KubitDocs · Legislation

NCSC Cyber Essentials and Cyber Essentials Plus — Requirements for IT infrastructure v3.3 (from 27 April 2026)

Provisions the documents cite: the scheme, the five technical controls and the Requirements for IT infrastructure document

What it requires

The government-backed certification scheme run by the National Cyber Security Centre with IASME as its delivery partner. Cyber Essentials is a self-assessment verified by an independent assessor; Cyber Essentials Plus adds independent technical testing for higher assurance. Both assess five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The current requirements document is Cyber Essentials Requirements for IT infrastructure v3.3, applying from 27 April 2026 (v3.2 applied from 28 April 2025). Certificate validity was not stated on the pages read.

The instrument itself: https://www.ncsc.gov.uk/cyberessentials/resources. The summary above is our plain-English reading, not the text of the instrument — always work from the source.

How this entry is kept current

  • Citation status: cited from the primary source.
  • Watched by: NCSC resources page — check the requirements document version at each monthly horizon scan.
  • Source last checked by the automated scan: not yet — first scan pending.

Every source is re-checked monthly and the result is published in the scan log. A change that alters what a document should say raises a revision, and past buyers of that document are told.

The 1 document that cite it

Every KubitDocs document prints its statutory basis on the form itself, so the person signing can verify the citation rather than take our word for it.

Company policies