Cyber Essentials is changing – here’s how it affects you

As of today (24th January 2022), the NCSC and IASME have updated the pricing and scope for Cyber Essentials. In this blog, we’ll explain what the changes are and how this will affect organisations looking to achieve the certification.

But first – 

What is Cyber Essentials and will the changes affect me?

Cyber Essentials and Cyber Essentials Plus are great first steps towards making your systems more secure. The certifications are supported by the National Cyber Security Centre, recommended by the ICO and accredited through IASME.

Cyber Essentials is the first step towards making your systems more secure – especially if you’re at the start of your cyber security journey or have limited funds available. It consists of a simple online self-assessment that allows you to demonstrate you are taking the appropriate measures to protect your systems, data and networks.

Cyber Essentials Plus covers the same controls as Cyber Essentials, only with Plus, a third party (like us) verifies that the responses on the self-questionnaire are correct. This means it has considerably more credibility with third parties, which is why it’s increasingly required of any supplier to the Ministry of Defence, and encouraged for those working with government departments, local authorities and large organisations.

The revised version of the Cyber Essentials technical requirements are to be released on 24th of January. Any assessments to begin before then or that are already underway will continue to use the current standard, so will not be affected. Organisations using the current standard will have 6 months from then to complete the new assessment. 

So what are the changes? 

According to IASME, the governing body for Cyber Essentials: 

1) Home working devices are in scope, but most home routers are not

Anyone working from home for any amount of time is classified as a ‘home worker’. The devices that home workers use to access organisational information, whether they are owned by the organisation or the user, are in scope for Cyber Essentials.

Home routers that are provided by Internet Service Providers or by the home worker are now out of scope and the Cyber Essentials firewall controls are now transferred to the home worker’s device (computer, laptop, tablet and/or phone). However, a router supplied by the applicant company is in scope and must have the Cyber Essentials controls applied to it.

The use of a corporate (single tunnel) Virtual Private Network (VPN) transfers the boundary to the corporate firewall or virtual cloud firewall.

2) All cloud services are in scope

Cloud services are to be fully integrated into the scheme.

If an organisation’s data or services are hosted on cloud services, then the organisation is responsible for ensuring that all the Cyber Essentials controls are implemented. Definitions of cloud services have been added for Infrastructure as a Service, Platform as a Service and Software as a Service. Whether the cloud service provider or the user implements the control, depends on the type of cloud service.

3) Multi-factor authentication must be used for access to cloud services

As well as providing extra protection for passwords that are not protected by other technical controls, multi-factor authentication should always be used to provide additional protection to administrator accounts and accounts when connecting to cloud services.

The password element of the multi-factor authentication approach must have a password length of at least 8 characters with no maximum length restrictions.

Multi-factor Authentication requires the user to have two or more types of credentials before being able to access an account.  There are four types of additional factor that may be considered:

  • A managed enterprise device
  • An app on a trusted device
  • A physically separate token
  • A known or trusted account

4) Thin clients are in scope when they connect to organisational information or services

A thin client is a ‘dumb terminal’ that gives you access to a remote desktop. It doesn’t hold much data, but it can connect to the internet.

5) All servers including virtual servers on a sub-set or a whole organisation assessment are in scope

Servers are specific devices that provide organisational data or services to other devices as part of the business of the applicant.

6) All smartphones and tablets connecting to organisational data and services are confirmed in scope when connecting to a corporate network or mobile internet such as 4g and 5g

However, mobile or remote devices used only for voice calls, text messages or multi-factor authentication applications are out of scope.

7) Device locking

Biometrics or a minimum password or pin length of 6 characters must be used to unlock a device

8) Password-based and multi-factor authentication requirements

When using passwords, one of the following protections should be used to protect against brute-force password guessing:

  • Using multi-factor authentication
  • Throttling the rate of unsuccessful or guessed attempts
  • Locking accounts after no more than 10 unsuccessful attempts

Technical controls are used to manage the quality of passwords. This will include one of the following:

  • Using multi-factor authentication in conjunction with a password of at least 8 characters, with no maximum length restrictions
  • A minimum password length of at least 12 characters, with no maximum length restrictions
  • A minimum password length of at least 8 characters, with no maximum length restrictions and use automatic blocking of common passwords using a deny list
  • People are supported to choose unique passwords for their work accounts

New guidance has been created on how to form passwords. It is now recommended that three random words are used to create a password that is long, difficult to guess and unique.

There is an established process to change passwords promptly if the applicant knows or suspects the password or account has been compromised.

9) Account separation

Use separate accounts to perform administrative activities only (no emailing, web browsing or other standard user activities that may expose administrative privileges to avoidable risks)

10) The scope of an organisation must include end-user devices

Mobile devices (smartphones & tablets) are in scope whether they are company or user-owned.

11) All high and critical updates must be applied within 14 days and remove unsupported software

All software on in scope devices must be:

  • Licensed and supported
  • Removed from devices when it becomes un-supported or removed from scope by using a defined ‘sub-set’ that prevents all traffic to/from the internet.
  • Have automatic updates enabled where possible
  • Updated, including applying any manual configuration changes required to make the update effective, within 14 days of an update being released, where:
    • The update fixes vulnerabilities described by the vendor as ‘critical’ or ‘high risk’
    • The update addresses vulnerabilities with a CVSS v3 score of 7 or above
    • There are no details of the level of vulnerabilities the update fixes provide by the vendor

Pricing

The pricing of Cyber Essentials is adopting a new tiered structure, which will depend on the size of the organisation:

  • A micro organisation (0-9 employees) will be charged £300 + VAT.
  • A small organisation (10-49 employees) will be charged £400 + VAT.
  • A medium organisation (50-249 employees) will be charged £450 + VAT.
  • A large organisation (250+ employees) will be charged £500 + VAT.

What about Cyber Essentials Plus?

Two additional tests have now been added to the Cyber Essentials Plus Audit. This is a test to confirm MFA is required to access cloud services, and a test to confirm account separation between user and administration accounts.

There will be a grace period of one year to allow organisations to make the necessary changes for MFA cloud services, thin clients and security update management.

Any questions? 

If you have any questions about the upcoming changes to Cyber Essentials, or if you’d like to speak to our team about achieving the certification yourself, get in touch using the contact form below.