Cyber Essentials from the MSP side: what the scheme asks for, where estates come unstuck, and what the rule changes mean day to day. Written by the people who build Monitor.
Removing what isn't needed and changing what shipped insecure: SMBv1, remote desktop, UAC, autorun, screen lock and local lockout policy on Windows.
Why an MSP needs its own certificate, the weakness of the once-a-year model, and how selling the year rather than the day turns Cyber Essentials into recurring work.
For most Windows estates the built-in antivirus meets the malware protection control. What fails organisations is Defender switched off, out of date or overridden.
Windows 10 fails Cyber Essentials unless it is enrolled in Extended Security Updates. What ESU requires, where estates get caught out, and the options for each machine.
The UK government-backed scheme in plain terms: who runs it, the five controls, the two levels, and how an organisation gets certified.
What is in scope for Cyber Essentials, what can be excluded, and the scoping mistakes behind failed assessments: home workers, personal devices, cloud services and the machines nobody mentioned.
What a Cyber Essentials assessor looks at, what a Plus audit tests, and why a screenshot taken on assessment day answers a different question from a dated record.
Which updates the fourteen-day rule covers, when the clock starts, and why Windows often can't tell you an update's severity, with what that means for any tool measuring how far behind a machine is.
The three password options, protection against guessing, device unlock rules, and why MFA on cloud services is now an automatic-fail requirement.
The same five controls, but one is a self-assessment and the other an independent technical audit. What each involves, what each costs, and which one an organisation actually needs.
What Cyber Essentials requires: scope, the five technical controls and why each exists, the four automatic-fail questions, and what Cyber Essentials Plus adds on top.
A certificate lasts twelve months. How renewal works, why renewals fail on things that changed quietly during the year, and a six-week plan to renew without surprises.
A Cyber Essentials checklist built around the current question set: the automatic-fail requirements first, then what the questionnaire asks about scope and each of the five controls.
Cyber Essentials costs £320 to £600 + VAT by organisation size, and Plus usually adds £1,500 to £3,000. The fees, what they include, and the costs that never appear on a price list.
Missing MFA on a cloud service that offers it, and high-risk updates left past fourteen days, are now automatic failures rather than findings you can argue about. Most patching processes were built for the old rules.