Cyber Essentials

Build the foundations for cyber security certification

Cyber Essentials is the UK government's recognised baseline for defending against common cyber threats. J700 Group helps North West businesses understand the five required technical controls, assess current readiness, and prepare for certification as part of a practical, managed approach to cyber security.

Cyber security support
North West based
Est. 2015

About the Scheme

What is Cyber Essentials?

Cyber Essentials is the UK government's recognised baseline certification for cyber security. Developed by the National Cyber Security Centre (NCSC), it defines five technical control areas that address the most common attack vectors facing organisations today. Certification demonstrates that a business has the basic defences in place to prevent the majority of commodity cyber attacks.

The scheme has two levels. Cyber Essentials is a self-assessment, verified by an accredited certification body against your answers. Cyber Essentials Plus adds an independent technical audit that confirms those controls are genuinely in place and working. Both result in a time-limited certificate that must be renewed annually.

Many North West businesses pursue Cyber Essentials as a supply chain requirement, an insurance condition, or as an honest baseline measure of where their security posture stands. J700 Group helps you understand where you are, address any gaps, and approach the certification process with confidence.

Why businesses certify

  • Supply chain requirement

    Required by government procurement and increasingly expected by private sector customers.

  • Insurance eligibility

    Some cyber insurance policies require or offer better terms with Cyber Essentials in place.

  • Baseline assurance

    An independently recognised measure that the five foundational controls have been addressed.

  • Staff and stakeholder confidence

    Demonstrates to customers, partners and leadership that cyber security is taken seriously.

Technical Control Areas

The five required controls explained

Cyber Essentials tests five technical control areas. These are designed to address the most common attack techniques used against UK organisations. Here is what each area covers and what it means in practice.

  1. Firewalls

    Boundary protection and software firewalls

    Firewalls control the network traffic allowed in and out of your systems. Cyber Essentials requires a correctly configured boundary firewall and software firewalls on devices — particularly those that connect to untrusted networks. Default or unused rules must be removed, and only necessary services exposed. This applies to cloud-hosted environments as well as on-premise infrastructure.

  2. Secure Configuration

    Systems set up securely, not in default state

    Many attacks succeed because devices and software are left in their default factory configuration. Secure configuration means removing or disabling unnecessary services, accounts and features; changing default passwords; and ensuring only software that is needed for business purposes is installed and running. This control applies to all computers, network devices, and cloud services in scope.

  3. Security Update Management

    Software and OS patches applied promptly

    Unpatched software is one of the most consistently exploited vulnerabilities. Cyber Essentials requires that operating systems and applications receive security updates within a defined timeframe — typically 14 days for high-risk patches. Unsupported software that no longer receives updates must be removed or isolated from the network. J700's managed IT includes structured patch management as a core function.

    Related: Managed IT Support
  4. User Access Control

    Access limited to what each user needs

    Users should have the minimum access rights needed to perform their role — no more. This control covers standard vs. administrative account separation, removal of unnecessary accounts, and controls around who can install software. It also includes multi-factor authentication for internet-accessible services. Microsoft 365 identity and access management is directly relevant here.

    Related: Microsoft 365
  5. Malware Protection

    Anti-malware controls active on devices

    Malware protection requires either anti-malware software running on all in-scope devices, application allowlisting (only approved software can run), or sandboxing for untrusted code. Controls must be kept up to date and scanning must be enabled. This works alongside the other four controls — malware is less effective when systems are patched, configured correctly, and access is controlled.

    Related: Cyber Security

Assessment Readiness

Common gaps before Cyber Essentials assessment

  • Challenge

    Unpatched systems or unsupported software still in use

    How J700 helps

    J700's managed IT includes structured patch management to keep operating systems and applications current within the required timeframes.

  • Challenge

    Default credentials or overly permissive admin accounts

    How J700 helps

    Review of user access, account privileges, and admin account separation — with MFA configured for internet-accessible services.

  • Challenge

    Firewall rules that have accumulated without review

    How J700 helps

    Firewall audit to remove unnecessary rules, check boundary configuration, and ensure software firewalls are active on devices.

  • Challenge

    Microsoft 365 not configured to meet the access control requirements

    How J700 helps

    J700's Microsoft 365 support addresses identity, conditional access, MFA and account security as part of preparation.

  • Challenge

    Uncertainty about what is in scope for the assessment

    How J700 helps

    J700 works through the scope with you — which devices, services and cloud accounts are included — so there are no surprises at assessment time.

How J700 Helps

What J700 does to support Cyber Essentials

  • Readiness review

    Assess your current position against each of the five technical controls before formal assessment.

  • Gap identification

    Identify where your systems, configuration, or processes do not yet meet the control requirements.

  • Patch management

    Structured OS and application patching via managed IT — within the Cyber Essentials update timelines.

  • Firewall review

    Review boundary and software firewall configuration to remove unnecessary rules and check coverage.

  • Access control and MFA

    Review user accounts, admin privilege separation, and MFA configuration for internet-accessible services.

  • Microsoft 365 configuration

    Secure configuration of Microsoft 365 accounts, conditional access, and identity controls relevant to the scheme.

  • Malware protection review

    Confirm anti-malware controls are active, up to date, and appropriately configured on in-scope devices.

  • Ongoing managed IT

    After working towards certification, J700's managed IT maintains the controls on an ongoing basis — supporting annual renewal.

Assessment Preparation

How preparation typically works

  1. Initial conversation

    Discuss your current setup, what has driven the decision to pursue Cyber Essentials, and any known gaps or concerns. No preparation is needed before this call.

  2. Readiness review

    J700 reviews your current position against the five technical control areas — identifying what is already in place and where remediation is needed before assessment.

  3. Remediation and configuration

    Address the identified gaps. This may include patch management, firewall review, access control changes, and Microsoft 365 configuration work.

  4. Assessment submission

    Complete the self-assessment questionnaire with the controls in place. J700 supports this process through to submission with the certification body.

  5. Ongoing maintenance

    After submission, J700's managed IT maintains the required controls as part of day-to-day IT management, supporting your annual renewal cycle.

Microsoft 365

Microsoft 365 and Cyber Essentials

If your organisation uses Microsoft 365, many of the Cyber Essentials technical controls apply directly to how it is configured. User access control, multi-factor authentication, secure configuration of accounts and applications, and software update management for Microsoft 365 apps are all tested as part of the assessment.

J700's Microsoft 365 support addresses these configuration requirements as part of your Cyber Essentials preparation — and as ongoing managed IT — so there is no separation between day-to-day Microsoft 365 management and maintaining your certification controls.

Microsoft 365 services from J700

Microsoft 365 controls relevant to Cyber Essentials

  • Multi-factor authentication enabled for all user accounts
  • Administrative accounts separated from standard user accounts
  • Legacy authentication protocols disabled
  • Conditional access policies configured appropriately
  • Microsoft 365 applications kept on a supported and updated version
  • Unused accounts and licences reviewed and removed
  • Mailbox access and delegation rights audited
  • External sharing settings reviewed and restricted as appropriate

Managed IT Support

Cyber Essentials within managed IT

Working towards Cyber Essentials is a point-in-time process, and maintaining the controls requires them to remain in place throughout the year and to be renewed annually. J700's managed IT service keeps patch management, device configuration, and access controls current as a normal part of day-to-day IT management — which makes ongoing Cyber Essentials compliance significantly easier than managing it separately.

J700 also connects Cyber Essentials work to backup and business continuity, cyber security awareness, and broader security posture improvements — so the certification process is part of a joined-up approach rather than a standalone exercise.

What managed IT covers for Cyber Essentials

  • Structured patch management within Cyber Essentials update timelines
  • Device configuration management and baseline security settings
  • User account and access rights reviews
  • Software inventory and removal of unsupported applications
  • Anti-malware deployment and monitoring
  • Firewall rule review and ongoing management
  • Annual Cyber Essentials renewal support
  • Backup and business continuity planning alongside the certification process

Your local IT team

Cyber Essentials support from a North West IT team

J700 Group is a managed IT and cyber security provider based in Lancashire and Greater Manchester. Cyber Essentials support is part of our broader cyber security and managed IT service — not a one-off exercise. We work with you to understand your environment, identify gaps, and maintain controls on an ongoing basis.

  • We work with your actual systems

    J700 reviews the specific devices, applications, and cloud services you use — not a generic template — so the readiness review reflects your real environment.

  • Preparation is part of managed IT

    Cyber Essentials controls connect directly to J700's managed IT service. Patch management, access control, and configuration work happen as part of normal operations.

  • We support ongoing compliance

    After working through the assessment process, J700 maintains the required controls and supports your annual renewal — not just the initial submission.

  • Local team, genuine accountability

    With offices in Rossendale and Bury, J700 is a local North West team with direct accountability for the work we do.

About J700 Group

  • UK-based team in Lancashire and Greater Manchester

  • Managed IT and cyber security delivered as one coordinated service

  • Supporting North West businesses since 2015

  • Cyber Essentials support connected to Microsoft 365, backup, and ongoing IT management

2015

Established

2

Offices

Common Questions

Cyber Essentials questions answered

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme that helps organisations demonstrate they have the basic technical controls in place to defend against common cyber threats. It covers five control areas: firewalls, secure configuration, security update management, user access control, and malware protection.

What is Cyber Essentials Plus?

Cyber Essentials Plus is the higher tier of the scheme. It includes an independent technical audit that verifies the controls are in place and working correctly, not just self-attested. It is typically required for higher-risk supply chain relationships and certain government contracts.

How long does Cyber Essentials preparation typically take?

The timeline varies. Organisations with well-configured systems and good update management may move through the self-assessment quickly. Those with gaps in their current controls will need time to remediate before submitting. J700 works with you to assess where you are and prioritise what to address first.

Is Cyber Essentials mandatory?

Cyber Essentials is mandatory for suppliers bidding for certain UK central government contracts, particularly those involving handling personal data or providing cyber security services. Many private sector supply chains also require it. Beyond formal requirements, it is widely used as a baseline security standard for small and medium businesses.

Does J700 Group support Cyber Essentials Plus?

J700 can help you prepare for both Cyber Essentials and Cyber Essentials Plus. The technical controls required are the same — Cyber Essentials Plus adds independent verification. J700's managed IT and cyber security services help ensure those controls are in place and correctly configured before you go through assessment.

How does Cyber Essentials relate to Microsoft 365?

Many of the five Cyber Essentials technical controls apply directly to Microsoft 365. User access control and MFA, secure configuration of accounts and applications, and update management for Microsoft 365 apps are all relevant. J700's Microsoft 365 support connects directly to your Cyber Essentials preparation.

Do I need Cyber Essentials to use a managed IT service?

No. Cyber Essentials certification is not a prerequisite for managed IT support. However, working with J700 on managed IT makes it easier to build and maintain the controls Cyber Essentials requires as part of your day-to-day IT management.

How does Cyber Essentials relate to backup and business continuity?

Backup and business continuity are not directly tested controls under Cyber Essentials, but they are an important part of your broader security posture. J700's backup and business continuity services complement Cyber Essentials by ensuring that if an incident does occur, your data can be recovered.

Can J700 Group help if I have already failed a Cyber Essentials assessment?

Yes. J700 can review the specific failures from your assessment, help you understand the root cause, and work through the remediation steps needed before you resubmit.

Ready to work towards Cyber Essentials certification?

Talk to J700 Group about where your organisation stands against the five technical controls and agree the practical next step — whether that is a readiness review, remediation work, or assessment preparation.

Privacy controls

Choose optional analytics and marketing categories independently. Marketing technologies are not active in this development configuration.

Necessary

Always active

Required for core website functionality and security. These cannot be disabled.

Analytics

Allows J700 to understand how visitors use the website and improve content and services. Optional and disabled until consent.

Marketing

Reserved for approved marketing technologies. None are active in this development configuration.

Read our Privacy & Cookie Policy.