Cyber Essentials
Build the foundations for cyber security certification
Cyber Essentials is the UK government's recognised baseline for defending against common cyber threats. J700 Group helps North West businesses understand the five required technical controls, assess current readiness, and prepare for certification as part of a practical, managed approach to cyber security.
About the Scheme
What is Cyber Essentials?
Cyber Essentials is the UK government's recognised baseline certification for cyber security. Developed by the National Cyber Security Centre (NCSC), it defines five technical control areas that address the most common attack vectors facing organisations today. Certification demonstrates that a business has the basic defences in place to prevent the majority of commodity cyber attacks.
The scheme has two levels. Cyber Essentials is a self-assessment, verified by an accredited certification body against your answers. Cyber Essentials Plus adds an independent technical audit that confirms those controls are genuinely in place and working. Both result in a time-limited certificate that must be renewed annually.
Many North West businesses pursue Cyber Essentials as a supply chain requirement, an insurance condition, or as an honest baseline measure of where their security posture stands. J700 Group helps you understand where you are, address any gaps, and approach the certification process with confidence.
Why businesses certify
Supply chain requirement
Required by government procurement and increasingly expected by private sector customers.
Insurance eligibility
Some cyber insurance policies require or offer better terms with Cyber Essentials in place.
Baseline assurance
An independently recognised measure that the five foundational controls have been addressed.
Staff and stakeholder confidence
Demonstrates to customers, partners and leadership that cyber security is taken seriously.
Technical Control Areas
The five required controls explained
Cyber Essentials tests five technical control areas. These are designed to address the most common attack techniques used against UK organisations. Here is what each area covers and what it means in practice.
Firewalls
Boundary protection and software firewalls
Firewalls control the network traffic allowed in and out of your systems. Cyber Essentials requires a correctly configured boundary firewall and software firewalls on devices — particularly those that connect to untrusted networks. Default or unused rules must be removed, and only necessary services exposed. This applies to cloud-hosted environments as well as on-premise infrastructure.
Secure Configuration
Systems set up securely, not in default state
Many attacks succeed because devices and software are left in their default factory configuration. Secure configuration means removing or disabling unnecessary services, accounts and features; changing default passwords; and ensuring only software that is needed for business purposes is installed and running. This control applies to all computers, network devices, and cloud services in scope.
Security Update Management
Software and OS patches applied promptly
Unpatched software is one of the most consistently exploited vulnerabilities. Cyber Essentials requires that operating systems and applications receive security updates within a defined timeframe — typically 14 days for high-risk patches. Unsupported software that no longer receives updates must be removed or isolated from the network. J700's managed IT includes structured patch management as a core function.
Related: Managed IT SupportUser Access Control
Access limited to what each user needs
Users should have the minimum access rights needed to perform their role — no more. This control covers standard vs. administrative account separation, removal of unnecessary accounts, and controls around who can install software. It also includes multi-factor authentication for internet-accessible services. Microsoft 365 identity and access management is directly relevant here.
Related: Microsoft 365Malware Protection
Anti-malware controls active on devices
Malware protection requires either anti-malware software running on all in-scope devices, application allowlisting (only approved software can run), or sandboxing for untrusted code. Controls must be kept up to date and scanning must be enabled. This works alongside the other four controls — malware is less effective when systems are patched, configured correctly, and access is controlled.
Related: Cyber Security
Assessment Readiness
Common gaps before Cyber Essentials assessment
- Challenge
Unpatched systems or unsupported software still in use
How J700 helpsJ700's managed IT includes structured patch management to keep operating systems and applications current within the required timeframes.
- Challenge
Default credentials or overly permissive admin accounts
How J700 helpsReview of user access, account privileges, and admin account separation — with MFA configured for internet-accessible services.
- Challenge
Firewall rules that have accumulated without review
How J700 helpsFirewall audit to remove unnecessary rules, check boundary configuration, and ensure software firewalls are active on devices.
- Challenge
Microsoft 365 not configured to meet the access control requirements
How J700 helpsJ700's Microsoft 365 support addresses identity, conditional access, MFA and account security as part of preparation.
- Challenge
Uncertainty about what is in scope for the assessment
How J700 helpsJ700 works through the scope with you — which devices, services and cloud accounts are included — so there are no surprises at assessment time.
How J700 Helps
What J700 does to support Cyber Essentials
Readiness review
Assess your current position against each of the five technical controls before formal assessment.
Gap identification
Identify where your systems, configuration, or processes do not yet meet the control requirements.
Patch management
Structured OS and application patching via managed IT — within the Cyber Essentials update timelines.
Firewall review
Review boundary and software firewall configuration to remove unnecessary rules and check coverage.
Access control and MFA
Review user accounts, admin privilege separation, and MFA configuration for internet-accessible services.
Microsoft 365 configuration
Secure configuration of Microsoft 365 accounts, conditional access, and identity controls relevant to the scheme.
Malware protection review
Confirm anti-malware controls are active, up to date, and appropriately configured on in-scope devices.
Ongoing managed IT
After working towards certification, J700's managed IT maintains the controls on an ongoing basis — supporting annual renewal.
Assessment Preparation
How preparation typically works
Initial conversation
Discuss your current setup, what has driven the decision to pursue Cyber Essentials, and any known gaps or concerns. No preparation is needed before this call.
Readiness review
J700 reviews your current position against the five technical control areas — identifying what is already in place and where remediation is needed before assessment.
Remediation and configuration
Address the identified gaps. This may include patch management, firewall review, access control changes, and Microsoft 365 configuration work.
Assessment submission
Complete the self-assessment questionnaire with the controls in place. J700 supports this process through to submission with the certification body.
Ongoing maintenance
After submission, J700's managed IT maintains the required controls as part of day-to-day IT management, supporting your annual renewal cycle.
Speak to the team
Not sure where your Cyber Essentials gaps are?
Talk to J700 Group and we will review your current controls and discuss the practical next step.
Microsoft 365
Microsoft 365 and Cyber Essentials
If your organisation uses Microsoft 365, many of the Cyber Essentials technical controls apply directly to how it is configured. User access control, multi-factor authentication, secure configuration of accounts and applications, and software update management for Microsoft 365 apps are all tested as part of the assessment.
J700's Microsoft 365 support addresses these configuration requirements as part of your Cyber Essentials preparation — and as ongoing managed IT — so there is no separation between day-to-day Microsoft 365 management and maintaining your certification controls.
Microsoft 365 services from J700Microsoft 365 controls relevant to Cyber Essentials
- Multi-factor authentication enabled for all user accounts
- Administrative accounts separated from standard user accounts
- Legacy authentication protocols disabled
- Conditional access policies configured appropriately
- Microsoft 365 applications kept on a supported and updated version
- Unused accounts and licences reviewed and removed
- Mailbox access and delegation rights audited
- External sharing settings reviewed and restricted as appropriate
Managed IT Support
Cyber Essentials within managed IT
Working towards Cyber Essentials is a point-in-time process, and maintaining the controls requires them to remain in place throughout the year and to be renewed annually. J700's managed IT service keeps patch management, device configuration, and access controls current as a normal part of day-to-day IT management — which makes ongoing Cyber Essentials compliance significantly easier than managing it separately.
J700 also connects Cyber Essentials work to backup and business continuity, cyber security awareness, and broader security posture improvements — so the certification process is part of a joined-up approach rather than a standalone exercise.
What managed IT covers for Cyber Essentials
- Structured patch management within Cyber Essentials update timelines
- Device configuration management and baseline security settings
- User account and access rights reviews
- Software inventory and removal of unsupported applications
- Anti-malware deployment and monitoring
- Firewall rule review and ongoing management
- Annual Cyber Essentials renewal support
- Backup and business continuity planning alongside the certification process
Your local IT team
Cyber Essentials support from a North West IT team
J700 Group is a managed IT and cyber security provider based in Lancashire and Greater Manchester. Cyber Essentials support is part of our broader cyber security and managed IT service — not a one-off exercise. We work with you to understand your environment, identify gaps, and maintain controls on an ongoing basis.
We work with your actual systems
J700 reviews the specific devices, applications, and cloud services you use — not a generic template — so the readiness review reflects your real environment.
Preparation is part of managed IT
Cyber Essentials controls connect directly to J700's managed IT service. Patch management, access control, and configuration work happen as part of normal operations.
We support ongoing compliance
After working through the assessment process, J700 maintains the required controls and supports your annual renewal — not just the initial submission.
Local team, genuine accountability
With offices in Rossendale and Bury, J700 is a local North West team with direct accountability for the work we do.
About J700 Group
UK-based team in Lancashire and Greater Manchester
Managed IT and cyber security delivered as one coordinated service
Supporting North West businesses since 2015
Cyber Essentials support connected to Microsoft 365, backup, and ongoing IT management
2015
Established
2
Offices
Common Questions
Cyber Essentials questions answered
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme that helps organisations demonstrate they have the basic technical controls in place to defend against common cyber threats. It covers five control areas: firewalls, secure configuration, security update management, user access control, and malware protection.
What is Cyber Essentials Plus?
Cyber Essentials Plus is the higher tier of the scheme. It includes an independent technical audit that verifies the controls are in place and working correctly, not just self-attested. It is typically required for higher-risk supply chain relationships and certain government contracts.
How long does Cyber Essentials preparation typically take?
The timeline varies. Organisations with well-configured systems and good update management may move through the self-assessment quickly. Those with gaps in their current controls will need time to remediate before submitting. J700 works with you to assess where you are and prioritise what to address first.
Is Cyber Essentials mandatory?
Cyber Essentials is mandatory for suppliers bidding for certain UK central government contracts, particularly those involving handling personal data or providing cyber security services. Many private sector supply chains also require it. Beyond formal requirements, it is widely used as a baseline security standard for small and medium businesses.
Does J700 Group support Cyber Essentials Plus?
J700 can help you prepare for both Cyber Essentials and Cyber Essentials Plus. The technical controls required are the same — Cyber Essentials Plus adds independent verification. J700's managed IT and cyber security services help ensure those controls are in place and correctly configured before you go through assessment.
How does Cyber Essentials relate to Microsoft 365?
Many of the five Cyber Essentials technical controls apply directly to Microsoft 365. User access control and MFA, secure configuration of accounts and applications, and update management for Microsoft 365 apps are all relevant. J700's Microsoft 365 support connects directly to your Cyber Essentials preparation.
Do I need Cyber Essentials to use a managed IT service?
No. Cyber Essentials certification is not a prerequisite for managed IT support. However, working with J700 on managed IT makes it easier to build and maintain the controls Cyber Essentials requires as part of your day-to-day IT management.
How does Cyber Essentials relate to backup and business continuity?
Backup and business continuity are not directly tested controls under Cyber Essentials, but they are an important part of your broader security posture. J700's backup and business continuity services complement Cyber Essentials by ensuring that if an incident does occur, your data can be recovered.
Can J700 Group help if I have already failed a Cyber Essentials assessment?
Yes. J700 can review the specific failures from your assessment, help you understand the root cause, and work through the remediation steps needed before you resubmit.
Ready to work towards Cyber Essentials certification?
Talk to J700 Group about where your organisation stands against the five technical controls and agree the practical next step — whether that is a readiness review, remediation work, or assessment preparation.
