UK Cyber Essentials · Evidence & Implementation Kit
Pass Cyber Essentials the first time, without decoding the NCSC requirements yourself.
Every requirement across the five technical control themes, handed to you as an adopt-ready control, with the scope rules made clear, the evidence an assessor examines, and the finding they most often raise.
Assessment-ready in a weekend, not a month.
Here is the honest situation. Cyber Essentials is the certificate UK public-sector contracts and a growing number of buyers now require. It is pass or fail, so a single missed requirement fails the whole assessment. The controls sit across five themes, but the detail is where teams trip: the 14-day patch window, the multi-factor authentication rules for cloud and admin access, the password rules, the default-credential and admin-account requirements, and a scope that pulls in your cloud services, home workers and BYOD. Reading the NCSC requirements line by line and mapping them to evidence is the real job. A consultant charges several thousand pounds. Doing it yourself is a month of interpretation.
This Kit removes the build. It is every Cyber Essentials requirement, written as a control you personalize in a weekend, grounded in the current NCSC Requirements for IT Infrastructure v3.3.
What you get, the moment you buy
28
Requirements as adopt-ready controls. Every requirement across firewalls, secure configuration, security update management, user access control and malware protection, written so you personalize and apply it. The patch windows, multi-factor authentication rules and password rules are written in.
28
Evidence-they-examine checklists. For each requirement, exactly what an assessor examines, plus the finding they most often raise, so you close it before the self-assessment or the Plus audit.
1
Cyber Essentials Control Matrix, pre-built. Every requirement in a working spreadsheet, ready to record in-place status and evidence location.
1
Gap & Readiness Assessment. Score each requirement and the workbook tells you your readiness as a single percentage, and exactly what to fix next.
Grounded in the current NCSC Requirements for IT Infrastructure v3.3, with the cloud, home-worker and BYOD scope rules called out. Editable Word and Excel files.
The same evidence gets you Cyber Essentials Plus
Cyber Essentials is a self-assessment. Cyber Essentials Plus tests the same requirements with a hands-on technical audit. The evidence this Kit tells you to assemble is exactly what a Plus assessor verifies, so you can go straight for both.
What one control looks like
This is a Security update management requirement. All 28 are built to this depth.
CE-SU Apply critical and high-risk updates within 14 days SECURITY UPDATE MANAGEMENT
Adopt this control
[Organization] shall apply updates that are marked critical or high risk, or that address a vulnerability with a CVSS v3 base score of 7 or above, within 14 days of release across all in-scope devices and cloud services. Where the vendor gives no severity, the update shall still be treated as within scope and applied within 14 days.
Scope note
This applies to operating systems, applications and firmware on in-scope devices, and to software you manage in cloud services. Unsupported software must be removed or taken out of scope.
Evidence an assessor examines
- Patch management records showing updates applied within 14 days
- An inventory of in-scope software and its support status
- Configuration showing automatic updates enabled where available
- Records of unsupported software removed
Common finding they raise: unsupported operating systems or applications remain in scope, or the 14-day window cannot be evidenced across all devices.
Why this is not another checklist
- The evidence is the point. Generic checklists list the five themes. This tells you exactly what an assessor examines and the finding they raise, for every requirement. That is what passes the assessment.
- Current to v3.3. The patch windows, multi-factor authentication and password rules match the requirements in force now, not an old version.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. Cyber Essentials maps onto ISO 27001 and the Essential Eight, so this work feeds a broader security program.
Who buys this
UK businesses bidding for public-sector or enterprise contracts that require Cyber Essentials, managed service providers certifying their clients, and the IT and security leads who own the self-assessment. Whether it is your first certificate or an annual renewal, you save weeks and walk in with the controls and evidence ready.
By the end of the weekend you will have
✓ An adopt-ready control for all 28 requirements
✓ A completed Cyber Essentials control matrix
✓ The evidence an assessor examines
✓ Your scope boundary defined
✓ A readiness percentage and a fix list
✓ The common findings closed before assessment
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does this certify me? Certification is issued by an NCSC-approved certification body through IASME. The Kit gets you ready: the controls, the matrix, and the exact evidence they examine, for every requirement.
Does it cover Cyber Essentials Plus? Plus tests the same requirements with a hands-on audit, so the evidence in this Kit is what a Plus assessor verifies. It sets you up for both.
Is it current? Yes, grounded in NCSC Requirements for IT Infrastructure v3.3. Updates included.
What if it is not for me? A 30-day money-back guarantee.
Do not let one missed requirement fail the whole certificate.
A consultant is several thousand pounds and weeks. The Kit is instant, and it is guaranteed.
Add it to your cart and be assessment-ready this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com