Definition · External Attack Surface Management
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme owned by the National Cyber Security Centre (NCSC) and delivered by the IASME Consortium, which licenses the certification bodies that issue certificates. It is deliberately a baseline: it asks whether an organisation has a set of fundamental technical controls in place, rather than assessing a full management system in the way ISO 27001 does.
The five control themes
- Firewalls — boundary controls that restrict what is reachable from the internet
- Secure configuration — removing default settings, unused accounts and unnecessary services
- Security update management — applying vendor updates to supported software within defined timescales
- User access control — account provisioning, privilege separation and multi-factor authentication
- Malware protection — anti-malware or equivalent controls on in-scope devices
How certification works
The organisation completes a self-assessment questionnaire covering its declared scope, and the answers are confirmed by a senior representative. A certification body reviews the submission and issues the certificate if the answers meet the scheme requirements. Certification is point-in-time and renewed annually; the question set is revised periodically, so a control that passed one year may be asked about differently the next.
Where external exposure comes in
Three of the five themes have symptoms that are visible from the internet. Firewall and boundary answers can be checked against what port scanning actually finds. Secure configuration shows up as exposed admin panels, default credentials and weak TLS settings. Security update management shows up as known CVEs on internet-facing services. User access control and malware protection are internal matters and need separate evidence.
Because the self-assessment is an honest declaration rather than a scan, discovering assets you had forgotten — the shadow IT and stale subdomains that scoping tends to miss — matters as much as fixing findings.
Related concepts
Cyber Essentials Plus adds independent technical verification of the same controls. SurfaceLoop’s Cyber Essentials page sets out which themes external scanning can and cannot evidence. See also security misconfiguration, patch management and attack surface reduction.