United Kingdom

Cyber Essentials Plus

28 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

28 controls 0 frameworks share controls with it United Kingdom verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

Cyber Essentials Plus Evidence & Implementation Kit

28 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
CE-PLUS.1Authenticated Vulnerability Scan of Sample Devices0
CE-PLUS.2External Vulnerability Scan of Internet IPs0
CE-PLUS.3Malware Protection Test - EICAR via Email0
CE-PLUS.4Malware Protection Test - Web Download0
CE-PLUS.5Removable Media Malware Test0
CE-PLUS.6Account Separation Verification0
CE-PLUS.7MFA Verification on Cloud Services0
CE-PLUS.8Sample Size and Representativeness0
CEP-AUD-01Annual Hands On Audit and Recertification0
CEP-CLD-01Cloud Services in Scope0
CEP-FW-01Boundary Firewall Configuration0
CEP-FW-02Host Based Firewall on Devices0
CEP-MA-01Anti-Malware Deployment and Operation0
CEP-MA-02Application Allow Listing or Sandboxing0
CEP-MA-03Email Attachment Test0
CEP-MA-04Web Browsing Malware Test0
CEP-MOB-01Mobile Device Management and Encryption0
CEP-PM-01High and Critical Vulnerability Patching0
CEP-PM-02Unsupported Software Removal0
CEP-PM-03Authenticated Vulnerability Scan of Sample Devices0
CEP-PM-04External Vulnerability Scan of Internet Facing Services0
CEP-SC-01Secure Configuration of Devices0
CEP-SC-02Auto-Run and Auto-Play Disabled0
CEP-SC-03Multi-Factor Authentication for Cloud Services0
CEP-SCP-01Scope Definition and Whole Organisation Boundary0
CEP-UA-01Separation of Administrator Accounts0
CEP-UA-02Account Provisioning and Deprovisioning0
CEP-UA-03Password Policy and Brute Force Protection0

Tell me when Cyber Essentials Plus files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Identity proofing records aligned to NIST SP 800-63A
  • MFA enforcement evidence per system
  • Authenticator management procedures
  • Device authentication configurations
  • Federation agreements
  • Authentication configuration
  • Media handling policy
  • Media inventory
  • Chain of custody records
  • Removable media controls

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for Cyber Essentials Plus, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition