Enterprise GRC Platform
Tyndora for Cyber Essentials
Cyber Essentials is the UK government-backed cybersecurity certification standard. Required to bid on UK government contracts. Tyndora implements all 5 core security controls and automates annual certification.
Cyber Essentials Certification Framework
Cyber Essentials provides practical, actionable guidance on the 5 core technical controls that prevent the majority of cyber attacks. Government contracting requirement in UK and allied nations.
5 Core Controls
- Secure Configuration — Systems hardened and patched
- Access Control — User identity and privilege management
- Malware Prevention — Endpoint protection and monitoring
- Patch Management — Timely application of security patches
- Boundary Firewalls — Network perimeter protection
Certification Levels
Two levels: Cyber Essentials (self-assessment) and Cyber Essentials Plus (third-party assessment). Government contracting typically requires Plus level.
- ✓ Essentials: Self-assessment questionnaire
- ✓ Essentials Plus: Certified assessor validation (annual)
- ✓ Valid for: 12 months (annual renewal)
- ✓ Scope: UK and allied government contracting requirement
The 5 Technical Controls
The five control themes that prevent the majority of common internet-based attacks. Select any control to expand it and see representative requirements and what each one asks for.
Requirements shown are a faithful plain-language summary of the five Cyber Essentials technical controls (NCSC 'Requirements for IT Infrastructure') — not verbatim scheme text, and representative rather than exhaustive. Refer to the current official Cyber Essentials requirements for authoritative wording.
Cyber Essentials Implementation in Tyndora
From secure configuration to annual certification audit.
5 Controls Implementation
Cyber Essentials focuses on practical, high-impact controls. Each control has specific technical requirements that Tyndora implements and automates.
- Secure Configuration (OS hardening, application defaults)
- Access Control (unique user IDs, password policy, privilege)
- Malware Prevention (endpoint protection, anti-virus, anti-spyware)
- Patch Management (OS patches, application patches, firmware updates)
CYBER ESSENTIALS STATUS
Certification Level
Essentials Plus
5 Core Controls
3 / 5 in place, 2 in progress
Current Status
Preparing — not yet certified
Assessment Readiness
Targeting first self-assessment in Q3
CONTROL COMPLIANCE
Boundary Firewalls
✓ 100%
Malware Prevention
✓ 90%
Secure Configuration
75% — hardening in progress
Access Control
60% — MFA rollout underway
Patch Management
55% — SLA being established
Annual Certification & Renewals
Cyber Essentials Plus requires annual third-party assessment. Tyndora prepares evidence and coordinates annual certification renewals.
- Certification body selection and coordination
- Evidence collection for annual assessment
- Non-compliance tracking and remediation
- Certification certificate management and renewal
UK Government Contracting Requirements
UK government contracts often mandate Cyber Essentials Plus. Tyndora helps organizations maintain certification to meet government contracting eligibility.
Government Contracting Scope
- ✓ UK central government agencies
- ✓ NHS (National Health Service)
- ✓ Local authorities
- ✓ Critical infrastructure operators
Annual Renewal Process
- ✓ Q4: Assessment preparation and evidence gathering
- ✓ Q1: Third-party assessor visits
- ✓ Q2: Certification decision and award
- ✓ Valid for 12 months from award date
See Cyber Essentials Certification Ready
Book a discovery and we'll show you the 5 core controls implementation and annual certification preparation.
Book a discovery