United Kingdom · 8 controls evidenced

    Continuous evidence for Cyber Essentials

    UK government-backed baseline — required for many UK contracts.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    See your Cyber Essentials readiness in 60 seconds. Free, no signup.

    Sample evidence
    acme-corp.com · Cyber Essentials
    Live
    Control 1 — Firewalls and internet gateways
    DNS hygiene & DNSSEC
    Control 2 — Secure configuration
    Secure HTTP response headers
    Control 3 — User access control
    Exposed files & admin panels
    Control 4 — Malware protection
    Reputation & threat intelligence
    Updated continuously+ 4 more controls
    Why it matters

    Cyber Essentials in 30 seconds

    Cyber Essentials is mandatory for any supplier bidding on UK central government contracts that handle personal information or sensitive data. Cyber Essentials Plus adds a hands-on technical audit. Many UK enterprises now require it of their suppliers as a procurement gate. The 5 control areas map almost entirely to externally-observable signals.

    Scope

    UK organisations selling to government, NHS, MoD, or to enterprises that mandate it in their supplier code of conduct.

    Clause-by-clause mapping

    How Security Monitor evidences Cyber Essentials

    Each row links a Cyber Essentials clause to the external check we perform and the evidence it produces. Mappings are reviewed by our compliance team and updated when standards change.

    Cyber Essentials clauseWhat it requiresHow we evidence it
    DNS-1
    Control 1 — Firewalls and internet gateways
    Boundary firewalls and internet gateways must be configured to allow only necessary services. Externally observable open ports and DNS exposure are key indicators.
    DNS hygiene & DNSSEC
    We resolve A, AAAA, MX, NS, CAA and DNSSEC records and flag anomalies, dangling records and missing controls.
    WEB-1
    Control 2 — Secure configuration
    Computers and network devices are properly configured to reduce vulnerabilities — including web-server response headers and removed default content.
    Secure HTTP response headers
    We test for HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and X-Content-Type-Options on the live site.
    EXP-1
    Control 3 — User access control
    User accounts (especially admin accounts) are assigned only to authorised individuals and access to admin interfaces is restricted — must not be publicly exposed.
    Exposed files & admin panels
    We probe for publicly accessible .env, .git, backups, admin panels and other sensitive paths that should never be reachable.
    REP-1
    Control 4 — Malware protection
    The organisation is protected against malware — including external reputation, blocklist hygiene and exposure of known-malicious indicators.
    Reputation & threat intelligence
    We cross-check the domain and its IPs against VirusTotal, Shodan, Spamhaus, URLhaus and Google Safe Browsing.
    TLS-1
    Control 5 — Security update management
    Software (including TLS libraries and web server software) is kept up to date with security patches; outdated TLS protocols indicate missed updates.
    Encrypted transport (TLS 1.2+)
    We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname.
    EMAIL-1
    Control 1 — Email & web boundary protections
    Email filtering and authentication (SPF, DKIM, DMARC) are part of the boundary protections expected for Cyber Essentials Plus.
    Email authentication (SPF / DKIM / DMARC)
    We resolve and validate SPF, DKIM and DMARC records, including DMARC enforcement policy and reporting addresses.
    BREACH-1
    Supplementary — Account exposure
    Cyber Essentials Plus reviewers check for credential leakage on the public internet as part of the technical assessment.
    Credential exposure monitoring
    We query Have I Been Pwned for breaches involving the monitored domain and surface affected accounts.
    SUB-1
    Scope — Internet-facing assets
    Maintain an accurate inventory of all internet-facing assets in scope for Cyber Essentials assessment.
    Third-party data flow map (subdomains & external services)
    We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses.
    Honest scope

    What we don’t cover for Cyber Essentials

    External monitoring is one part of compliance. These areas need other evidence — typically from your GRC platform, HR system, or internal logging:

    • Bring-your-own-device policy and mobile device management
    • User account provisioning and de-provisioning workflow
    • Malware protection on end-user devices (we test from the outside, not on endpoints)
    • Formal IASME assessment submission — we surface the technical evidence; an accredited certification body issues the certificate
    FAQ

    Cyber Essentials questions

    See your Cyber Essentials readiness now

    One scan. Every clause on this page evaluated against your live domain. Auditor-ready PDF in your inbox.

    https://

    170+ checks · 10 layers · Results in <60s · No signup

    ISO 27001Aligned
    SOC 2 Type IIControls
    GDPRCompliant
    AES-256Encryption