Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

Cyber Essentials Plus (UK)

Cyber Essentials Plus (UK) certification establishes a high-assurance cybersecurity posture, validated through a mandatory independent technical audit as…

What Cyber Essentials Plus (UK) requires

Cyber Essentials Plus (UK) certification establishes a high-assurance cybersecurity posture, validated through a mandatory independent technical audit as specified in the NCSC Cyber Essentials Plus: Illustrative Test Specification v3.1. This framework, frequently a prerequisite for UK government contracts under Procurement Policy Note 09/14, demonstrates technical controls that align with the security of processing obligations found in the UK Data Protection Act 2018. Compliance mandates stringent operational discipline across all in-scope devices, where the device compliance scope includes bring-your-own-device assets accessing organizational data. Critical security updates must be applied within a strict 14-day maximum patch application window, and the operation of unsupported software is strictly prohibited. The technical audit verifies that internet-facing services do not possess vulnerabilities exceeding a maximum CVSS score of 6.9. Access controls are rigorously enforced; multifactor authentication is mandatory for all cloud services, all default passwords must be changed from vendor settings, and user passwords require a minimum length of 8 characters. Furthermore, the daily use of administrative accounts for standard activities is disallowed. Protective measures, guided by NCSC's Requirements for IT Infrastructure v3.1 and IASME Consortium rules, necessitate that malware protection signatures are updated within a 24-hour frequency, and certification requires successful completion of both an external vulnerability scan and an internal vulnerability scan.

Pillar: Cloud & SaaS · Authority: National Cyber Security Centre (NCSC) · Version: 1.1.1 · Last updated:

Primary source: https://www.ncsc.gov.uk/cyberessentials/overview

SHA-256 integrity: bd5d3f96d2ae60042e2e9b6b3e572183cb94dced6964700d4066a89ffae45c26

Primary Citations — 5 traced to source

  • NCSC Cyber Essentials: Requirements for IT Infrastructure v3.1 (April 2023)
  • NCSC Cyber Essentials Plus: Illustrative Test Specification v3.1 (April 2023)

+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.