Skip to content
Cloudreason

Cyber Essentials Plus for cloud estates

Your certificate expires every twelve months. Your cloud estate is in scope for the next one.

Cyber Essentials Plus · AWS + Azure + Google Cloud

Published

Cyber Essentials certification lasts twelve months, so every certified organisation is always closing in on a renewal date. Many UK public sector contracts require it, usually alongside the NCSC Cloud Security Principles, insurers increasingly ask for it, and the Plus level adds an independent technical audit to the self-assessment. The detail that catches organisations out is scope: since the scheme was updated in January 2022, your cloud services are unambiguously in it.

Cloud is in scope, and you cannot declare it out

Under the current scheme rules, any cloud service your organisation uses is in scope: infrastructure platforms such as AWS, Azure and Google Cloud, but also every SaaS product your staff sign in to. You cannot carve the cloud out of the assessment, and responsibility for the controls does not transfer to the provider. Where the provider implements a control, you are responsible for checking it does; where it merely makes a control available, you are responsible for switching it on.

The rule with the sharpest teeth is multi-factor authentication. MFA must be enabled for administrator accounts on all cloud services, and for user accounts too where the service supports it. A single admin account without MFA on a forgotten SaaS subscription is a fail, and audits find exactly that with monotonous regularity.

The five controls, translated to cloud

Cyber Essentials assesses five technical control themes. On paper they were written for offices and laptops; each has a precise cloud meaning:

  • Firewalls and boundary protection. In the cloud your boundary is security groups, network ACLs and exposed service endpoints. The assessor’s question becomes: what is reachable from the internet, and can you justify every port of it?
  • Secure configuration. Default accounts, unnecessary services and open storage are the cloud equivalents of the unhardened workstation. Configuration baselines, enforced by policy rather than by memory, are what pass.
  • Security update management. Compute you run, such as virtual machines and containers, must be patched within the scheme’s timescales: high and critical vulnerabilities within 14 days. Unsupported operating systems anywhere in scope are an automatic fail.
  • User access control. Accounts are individual, access is least-privilege, admin rights are separated from daily-use accounts, and leavers are removed promptly. Cloud identity providers make this easy to do and easier to evidence, but only if the joiners-and-leavers process actually runs.
  • Malware protection. Endpoints in scope need anti-malware or an allow-listing approach; for cloud workloads, the practical reading is hardened images and controls over what can execute.

What Plus adds

Cyber Essentials Plus takes the answers you gave in the self-assessment and tests them. An assessor scans your internet-facing services, tests a sample of devices, checks patch levels, and verifies that malware defences and MFA behave as claimed. It is not an adversarial penetration test, but it is precisely the kind of check that exposes the gap between what an estate was configured to do and what it does today.

That gap is the real risk to a renewal. Estates pass in April, drift all year, and rediscover the drift the week before the next assessment: an exposed port opened for a migration, a patching pipeline that quietly stopped, an admin account created during an incident with MFA deferred to later.

Passing it every year, without the scramble

The reliable way to hold Cyber Essentials Plus is to stop treating it as an annual event. The five controls are all continuously checkable: exposure, configuration, patch latency, access and MFA coverage can be monitored against the scheme’s requirements all year, with anything that slips fixed when it slips rather than found by an assessor. The same continuous discipline is what carries an estate through ISO 27001 surveillance audits, which ask for it at greater depth.

That is how Cloudreason’s cloud compliance service runs it: continuous monitoring of the estate against the control set, remediation done by our engineers, and the evidence ready before the assessor asks. If your renewal date is inside the next six months, start the conversation now, while there is still time to fix findings calmly.

← Cloud Compliance at Cloudreason

Frequently asked questions

Are cloud services in scope for Cyber Essentials?

Yes. Since the scheme's January 2022 update, every cloud service your organisation uses is in scope, from AWS and Azure infrastructure to every SaaS product staff sign in to, and you cannot declare them out of the assessment.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment against the five control themes. Cyber Essentials Plus covers the same controls but adds an independent technical audit, including vulnerability scans and device testing, that verifies your answers reflect the estate as it actually runs.

How long does Cyber Essentials Plus certification last?

Twelve months. Every certified organisation is always within a year of its next assessment, which is why treating the five controls as continuously monitored rather than annually revisited is the reliable way to hold the certificate.

Is multi-factor authentication required for Cyber Essentials?

Yes. MFA must be enabled on administrator accounts for all cloud services, and on user accounts where the service supports it. A single unprotected admin account on a forgotten SaaS subscription is enough to fail.

Got an audit date?

Tell us the date and the framework, and we'll tell you honestly what stands between your estate and passing.