Cyber Essentials Plus · AWS + Azure + Google Cloud
Published
Cyber Essentials certification lasts twelve months, so every certified organisation is always closing in on a renewal date. Many UK public sector contracts require it, usually alongside the NCSC Cloud Security Principles, insurers increasingly ask for it, and the Plus level adds an independent technical audit to the self-assessment. The detail that catches organisations out is scope: since the scheme was updated in January 2022, your cloud services are unambiguously in it.
Cloud is in scope, and you cannot declare it out
Under the current scheme rules, any cloud service your organisation uses is in scope: infrastructure platforms such as AWS, Azure and Google Cloud, but also every SaaS product your staff sign in to. You cannot carve the cloud out of the assessment, and responsibility for the controls does not transfer to the provider. Where the provider implements a control, you are responsible for checking it does; where it merely makes a control available, you are responsible for switching it on.
The rule with the sharpest teeth is multi-factor authentication. MFA must be enabled for administrator accounts on all cloud services, and for user accounts too where the service supports it. A single admin account without MFA on a forgotten SaaS subscription is a fail, and audits find exactly that with monotonous regularity.
The five controls, translated to cloud
Cyber Essentials assesses five technical control themes. On paper they were written for offices and laptops; each has a precise cloud meaning:
- Firewalls and boundary protection. In the cloud your boundary is security groups, network ACLs and exposed service endpoints. The assessor’s question becomes: what is reachable from the internet, and can you justify every port of it?
- Secure configuration. Default accounts, unnecessary services and open storage are the cloud equivalents of the unhardened workstation. Configuration baselines, enforced by policy rather than by memory, are what pass.
- Security update management. Compute you run, such as virtual machines and containers, must be patched within the scheme’s timescales: high and critical vulnerabilities within 14 days. Unsupported operating systems anywhere in scope are an automatic fail.
- User access control. Accounts are individual, access is least-privilege, admin rights are separated from daily-use accounts, and leavers are removed promptly. Cloud identity providers make this easy to do and easier to evidence, but only if the joiners-and-leavers process actually runs.
- Malware protection. Endpoints in scope need anti-malware or an allow-listing approach; for cloud workloads, the practical reading is hardened images and controls over what can execute.
What Plus adds
Cyber Essentials Plus takes the answers you gave in the self-assessment and tests them. An assessor scans your internet-facing services, tests a sample of devices, checks patch levels, and verifies that malware defences and MFA behave as claimed. It is not an adversarial penetration test, but it is precisely the kind of check that exposes the gap between what an estate was configured to do and what it does today.
That gap is the real risk to a renewal. Estates pass in April, drift all year, and rediscover the drift the week before the next assessment: an exposed port opened for a migration, a patching pipeline that quietly stopped, an admin account created during an incident with MFA deferred to later.
Passing it every year, without the scramble
The reliable way to hold Cyber Essentials Plus is to stop treating it as an annual event. The five controls are all continuously checkable: exposure, configuration, patch latency, access and MFA coverage can be monitored against the scheme’s requirements all year, with anything that slips fixed when it slips rather than found by an assessor. The same continuous discipline is what carries an estate through ISO 27001 surveillance audits, which ask for it at greater depth.
That is how Cloudreason’s cloud compliance service runs it: continuous monitoring of the estate against the control set, remediation done by our engineers, and the evidence ready before the assessor asks. If your renewal date is inside the next six months, start the conversation now, while there is still time to fix findings calmly.