Automate Cyber Essentials readiness with adaptive compliance
For companies doing business in the UK, Cyber Essentials is becoming a buyer requirement. See how rapidly growing teams close this gap between pilots and closed deals.

Prove you're protected from common threats
Unified by design. Built for the AI era.
Iru AI is designed from the ground up to connect a grid of agents behind the scenes—across identity, endpoint, and compliance. Powered by the Iru Context Model, it understands your users, apps, and devices to act safely, intelligently, and in context across your organization.
Cyber Essentials is the minimum standard of cyber security recommended by the UK government for organisations of all sizes. It's owned by the National Cyber Security Centre (NCSC), and built around five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection.
Support every control for Cyber Essentials with Iru
Automate evidence collection
Automatically pull evidence from collected sources via Iru Compliance Automation.Share compliance posture externally
Leverage a public-facing portal to share compliance posture via Iru Trust Center.Manage firewalls across devices
Enforce host firewall status, inbound blocking, and application network access rules across Mac and Windows via Iru Endpoint Management.Customize device security settings
Enforce secure settings for every device to reduce threat surface via Iru Endpoint Management.Control user access
Enforce multi-factor authentication, unique credentials per user, and separated admin accounts via Iru Workforce Identity.Protect against viruses and other malware
Detection and containment via Iru Endpoint Detection & Response, with Microsoft Defender policy managed on Windows via Iru Endpoint Management.Keep your software up to date
Promptly apply patches and updates across devices to close known weaknesses via Iru Vulnerability Management.Controls customized for your unique business
Most compliance tools use generic checklists. Iru generates controls specific to your organization, delivered in plain language.
- Iru AI generates tailored controls, based on your company context and audit details
- You can migrate existing controls over from other products, or upload your own custom control set
- Controls become actions the moment they are created, with suggested owners and due dates

Automate your evidence collection
Iru discovers and attaches artifacts to controls, reducing manual uploads. Devices and identity managed with Iru means that data is pulled natively.
- Evidence flows in continuously from supported devices, integrations and systems
- Iru AI helps to identity stale, missing or potentially irrelevant evidence for you to review
- You stay better prepared before fieldwork begins, with fewer fire drills before your Cyber Essentials engagement

Ensure continuous audit readiness
Iru's Adaptive Compliance capabilities watch for changes in your organization, and automatically suggest updates to your controls and actions.
- Iru AI regularly checks for changes to your sources, artifacts or company profile
- If a change is detected, a control update recommendation is surfaced for your to review, often within 24 hours
- No changes are made without your approval, and every change is logged for your auditors to review

Turn Cyber Essentials evidence collection into an always-on workflow
Iru replaces fragmented tools with one AI-powered platform, so IT, security and compliance teams spend less time chasing down evidence and more time improving the business
Let your team focus on what matters
Iru replaces fragmented tools with one AI-powered platform, so IT & security spend less time chasing tickets and more time improving the business.
Frequently asked
questions
Get answers to commonly asked questions
Who developed and maintains the Cyber Essentials framework?
Cyber Essentials is a UK government-backed, industry-supported scheme overseen by the National Cyber Security Centre (NCSC)
What does Cyber Essentials evaluate?
Cyber Essentials evaluates five technical controls designed to prevent the most common internet-based cyber threats: firewalls, secure configuration, security update management, user access control, and malware protection
What does a Cyber Essentials engagement look like?
Cyber Essentials is a verified self-assessment. You choose one of two routes: self-led, where you complete the assessment yourself, or supported, where you pay for support from a Cyber Advisor or Certification Body. Either way, your answers must be signed off by a board member or equivalent, then marked by an assessor.
Cyber Advisors are cyber security professionals who've passed an independent assessment covering their knowledge of the five technical controls, their competence at hands-on support, and their ability to work with smaller organisations to implement these controls. They are not involved with certification.
Cyber Essentials Plus builds on the same five technical controls, but adds independent technical testing to verify the controls are actually in place. The Cyber Essentials Plus audit must be completed within three months of the Cyber Essentials certification, or you will be forced to re-do the self-assessment.
Testing covers a representative sample of end user devices, your internally hosted servers, and your cloud services — IaaS, PaaS, and SaaS alike. Assessors run an external vulnerability scan, an authenticated patch scan, malware protection tests, multi-factor authentication checks on every cloud service, and account separation checks.
What does a Cyber Essentials engagement produce?
The output of a Cyber Essentials engagement is a Cyber Essentials certificate, which names the scope it covers — whole organisation or a defined sub-set. These are typically shared with customers and prospects, and are publicly findable via the Cyber Essentials Delivery Partner IASME's website.
UK organisations with turnover under £20m that certify their whole organisation also receive free Cyber Liability Insurance arranged by IAS.
UK or Crown organizations with annual turnover under £20m that certify their entire organization can opt in to Cyber Liability Insurance included with Cyber Essentials, providing up to £25,000 of cover and 24-hour incident-response support.
What are the potential outcomes of a Cyber Essentials engagement?
Most Assessors aim to return your results within three working days. There are three possible outcomes.
-
Pass. You are certified for 12 months.
-
Fail with a free resubmission. You get a report with the Assessor's comments on every non-compliant answer, then 2 working days to fix simple issues, update your answers, and resubmit at no extra charge.
-
Fail outright. If you are still non-compliant after that window, you reapply and pay the assessment fee again.
One automatic fail to know about in advance: using unsupported software anywhere in scope will fail the assessment, regardless of how everything else scores. Otherwise you need to be compliant on nearly every question.
If the Assessor cannot mark a question because you haven't given enough detail, they'll return it asking for more — which adds a few days.
Is Cyber Essentials required by law?
No. Cyber Essentials is not a legal requirement for UK businesses. It is a procurement requirement, which is a different thing.
Under the Cabinet Office Procurement Policy Note governing the scheme, central government departments, their executive agencies, non-departmental public bodies, and NHS bodies must require Cyber Essentials or Cyber Essentials Plus for contracts carrying higher cyber risk — typically those handling citizen or staff personal data, or systems processing data at OFFICIAL. Local authorities aren't formally in scope, though an increasing number apply it anyway. It's also required across the Ministry of Defence supply chain for suppliers handling defence information.
Buyers can accept equivalent controls demonstrated by an independent third party, at their discretion, so lacking the certificate doesn't automatically disqualify you — it just makes you prove it the slow way, at the point of bidding. And where certification is required, it must be renewed annually for the duration of the contract.
Commercially, many enterprise buyers in the UK now treat it as a baseline filter in vendor questionnaires.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Both look at the exact same five controls, but they differ significantly in how your compliance is verified. Note: you must pass the Standard certification before you can attempt Cyber Essentials Plus.
- Cyber Essentials is verified by self-assessment questionnaires signed off by a senior executive. Cyber Essentials Plus is a hands-on, independent technical audit.
- Cyber Essentials is a desktop review by an accredited Assessor, while Cyber Essentials Plus adds an independent technical audit, including vulnerability scanning and sample-based testing, to verify that the Cyber Essentials controls are implemented and operating effectively.
How long is a Cyber Essentials certificate valid for?
Cyber Essentials is an annually renewable certification, so each certificate — Cyber Essentials and Cyber Essentials Plus alike — lasts 12 months. Lapse, and you're removed from IASME's public list of certified organisations.
Recertification is a genuine annual review: you re-enter all your answers each year, and the question set changes between versions.
The Cabinet Office explicitly notes that a Cyber Essentials certificate "provides assurance of compliance only at the time of testing" — organisations that stop patching or drift on secure configuration "may become non-compliant in substantially less than one year."
Can Iru certify us, or issue a Cyber Essentials badge?
No platform can issue a Cyber Essentials certificate. Your assessment has to be marked by an Assessor — either through IASME directly on the self-led route, or through an IASME-licensed Certification Body on the supported route. And a board member or equivalent has to personally sign the declaration that your answers are true.
What Iru does is everything up to that point. The platform continuously collects evidence across your devices, identities, and cloud services, maps it to the five technical controls, and flags gaps while you can still fix them — rather than during your two working days to resubmit. For Cyber Essentials Plus, that same evidence is what your assessor samples against.
If you'd like to work with one of the Certification Bodies we partner with, please reach out to your rep.