Your 2026 Cyber Essentials Checklist: Before You Apply

Key Takeaways Working for Pera Prometheus, who are a Cyber Essentials (CE) and Cyber Essentials Plus (CE+) certifying body, and through my experience working with organisations of all sizes, I can confidently say that CE failures are rarely caused by poor security. More often, they are caused by gaps the applicant didn’t know were there; […]

How to align your DCC Level with MOD contract expectations

Key Takeaways Defence suppliers must be aware that although the DCC (beyond Level 0 after 31 December 2026) is currently optional, this is very likely to change in the near future, with every indication being that MOD will expect increasing numbers of organisations to achieve DCC.  As much as organisations can choose any DCC level […]

Cyber Essentials: The Foundation of DCC Level 0

Key Takeaways Do You Need Cyber Essentials Before DCC Level 0? Suppliers working towards Defence Cyber Certification (DCC) often ask the same question: do you need Cyber Essentials before achieving DCC Level 0? The answer is yes, it’s a mandatory requirement. Some organisations assume DCC replaces Cyber Essentials or that the two are separate options […]

MOD Requirement to Suppliers: “Achieve DCC Level 0 by 31 December 2026”

Key Takeaways The Ministry of Defence (MOD) has asked all of its industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, which includes Cyber Essentials for the business-critical systems in scope. If you supply to the defence sector, or if you want to, that deadline now sits in your calendar. […]

Inside a Cyber Essentials Plus Audit: What Really Happens

Key Takeaways Plenty of organisations pass the Cyber Essentials self-assessment and then feel uneasy about the next step. Cyber Essentials Plus adds an independent audit to the assessment process and for those business’ who have  not  experienced a CE+ assessment before, it can seem to be a confusing and difficult target to achieve. The reality […]

CMMC Phase 2 Suspended: What It Means for Your Supply Chain

Key Takeaways Introduction The US has hit pause on the part of CMMC that most worried organisations in the supply chain. On 13 July 2026 it suspended Phase 2, the stage that would have forced mandatory independent assessment from 10 November 2026. A pause is not the same as the end, so it would be […]

The Cyber Security and Resilience Bill: Who It Impacts

Key Takeaways The rules that govern cyber security in the UK are about to cover far more organisations than they do today. Until now, legal duties fell only on operators of essential services, in sectors such as energy, transport, water, health and digital infrastructure, and on a small group of digital providers, namely online marketplaces, […]

Defence Cyber Certification: Certify Before You Bid 

Key Takeaways With the demise of the UK MOD accreditation process, the ability to demonstrate a business conformed to MOD assurance requirements, was lost.  This has had significant ramifications for UK businesses, resulting in an increase in due diligence activities to provide evidence of compliance with MOD requirements for every contract or collaboration activity a […]

Cloud Is In Scope: What Cyber Essentials Requires From You

Cyber Essentials Cloud Scope

Amy Osborne, Head of Audit Services Key Takeaways Some organisations approach Cyber Essentials assuming that because their data sits in Microsoft 365 or another cloud platform that information security is largely someone else’s responsibility; however, that assumption can cause assessments to fail. Your cloud provider secures the infrastructure it runs but your organisation is responsible […]

Cyber Essentials Scoping: The Decision That Determines Whether You Pass or Fail

Cyber Essentials Scoping: The Decision That Determines Whether You Pass or Fail

Key Takeaways Introduction Most organisations focus on the five technical controls when preparing for Cyber Essentials. Fewer give the same attention to scoping and that is where assessments are quietly lost before a single question has been answered. The scope defines exactly which systems, devices, and services are being assessed. Too broad, without the right […]