UprootSecurity
Book a demo

NCSC · IASME-delivered · CE & CE Plus

FRAMEWORK

Five controls.Proven, not promised.

Cyber Essentials is deliberately small five technical controls across every internet-connected device. Uproot proves all five from your real fleet, so CE Plus holds up.

Start Cyber EssentialsTalk to a CE lead

Self-assessment ready in days

·

CE Plus evidence assembled automatically

app.uproot.security · /framework/cyber-essentials
CE+NCSC

acme-uk · Cyber Essentials Plus

198 devices in scope · IASME

95%

pass-ready

189 compliant7 patching2 flagged

The five controls

198 devices

FW

Firewalls

boundary + host

100%

CFG

Secure configuration

hardened baseline

96%

ACC

User access control

least privilege + MFA

98%

MAL

Malware protection

EDR enrolled

97%

UPD

Update management · 14-day SLA

7 devices patching

88%

Unsupported OS

0 devices

Cert body

CyberSmart

Critical patch SLA

14 days

Patch SLA breach caught

7 laptops fell outside the 14-day critical-update window. Owners paged before the CE Plus audit.

Technical controls

5

Firewalls, secure configuration, user access control, malware protection, and update management.

Two levels

CE / CE+

Cyber Essentials is a verified self-assessment. CE Plus adds a hands-on independent technical audit.

Renewal

Annual

Certification lasts twelve months. Many UK contracts require a current certificate to bid.

Authority

NCSC

Backed by the National Cyber Security Centre, delivered through IASME and its certification bodies.

In scope

Alldevices

Every internet-connected device servers, laptops, mobiles, and cloud services unless properly segmented.

The five controls

Small on purpose. Uproot makes all five provable across the fleet.

Cyber Essentials covers the basics that stop the overwhelming majority of common attacks. The hard part isn't understanding the five controls it's proving they hold on everydevice, every day. That's exactly what Uproot does.

Control 1
FW

Firewalls

Boundary and host firewalls on every device, default-deny inbound. Cloud security groups count.

Boundary firewalls · host firewalls · default-deny · no open admin to internet
Coverageall devices
CFG

Secure configuration

Devices hardened from defaults unused accounts removed, default passwords changed, auto-run off.

No default creds · remove unused services · disk encryption
Coverageall devices
ACC

User access control

Named accounts, least privilege, controlled admin rights, and MFA on cloud.

Least privilege · separate admin accounts · MFA on cloud
Coverageall accounts
MAL

Malware protection

Anti-malware or allow-listing, current and enforced not merely installed.

EDR enrolled · signatures current · allow-listing
Coverageall devices
UPD

Update management

Supported software with high/critical updates applied within 14 days; end-of-life software removed.

14-day critical SLA · auto-update on · no end-of-life OS
SLA14 days
One control, end to end

CE Plus fails most often on one thing: an unpatched laptop. Update management is where Uproot keeps you honest.

The 14-day patch SLA is simple to state and brutal to maintain across a fleet. Here's how Uproot turns it into live, device-level evidence.

Control 5 Security update management

All software must be supported, licensed, and patched: high and critical security updates applied within 14 days of release, and unsupported software removed. The single most common reason organizations fail a CE Plus assessment.

"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."

— Yogesh Narayan, CTO

CONTROL 5 · UPDATE MANAGEMENT

High/critical updates within 14 days

Last evidenced 09:14:02 UTC · 198 devices · sha256 verified

7 patching
01

The requirement

What Control 5 asks for

“Security updates for all software on in-scope devices must be applied within 14 days of release where the update fixes a vulnerability rated high or critical, and unsupported software must be removed.”
02

Your real fleet

What we read from your systems

Uproot pulls live device state from your MDM and EDR every laptop, server, and mobile in scope.

jamf ·os.versionintune ·patch.statecrowdstrike ·sensor.statusaws ·ssm.patch
03

Evidence collected

Per-device, against the 14-day clock

Each device's OS version, pending criticals, and days-since-release are pulled, hashed, and measured against the SLA. End-of-life OSes are flagged automatically.

191 / 198 ·within SLA7 ·patching nowEOL OS ·0auto-update ·enforced
04

For the assessor

CE Plus, device-by-device

Your CE Plus assessor opens Control 5 and sees a live per-device patch report exactly the sampling they'd otherwise do by hand, already done.

SLA · 14 days  ·  Owner · IT  ·  Past SLA · 7

SOC 2 CC7.1ISO A.8.8CIS 7.3
Path to certification

From fleet visibility to a CE Plus pass.

Cyber Essentials is fast by design. The work is making sure the self-assessment is true and that CE Plus finds nothing you didn't already know.

Day 0

Define scope

Confirm the boundary which devices, users, and cloud services are in scope. Uproot inventories them from MDM, EDR, and cloud.

Day 1–5

Prove the five

Firewalls, configuration, access, malware, and updates evidenced per device. Gaps issued as tickets to owners.

Day 6–10

Self-assessment

The verified questionnaire is answered from live evidence, not guesswork. Submit for Cyber Essentials.

4

Day 11–20

CE Plus audit

The assessor samples devices hands-on. Because the fleet state is already live, there's nothing to scramble for.

The questionnaire-guess way
  • ×

    A self-assessment answered from memory and optimism, not from the actual fleet

  • ×

    One unpatched laptop nobody knew about, found live during the CE Plus audit

  • ×

    An end-of-life OS still in scope, quietly failing the whole certification

  • ×

    Re-doing the whole exercise next year from scratch, with the same blind spots

With Uproot
  • The questionnaire answered from live, per-device evidence you can stand behind

  • Patch-SLA breaches and EOL software surfaced as tickets before the assessor arrives

  • The whole fleet’s posture in one continuously-updated view

  • Next year’s renewal is already evidenced recertification without the redo

Evidence map

Where the five controls actually live. Uproot reads them there.

A map of where Uproot pulls Cyber Essentials evidence fleet management, endpoint protection, identity, and cloud.

FW

Firewalls & config

  • Jamf · host firewall

    on

  • Intune · config baseline

    enforced

  • AWS · security groups

    default-deny

  • FileVault / BitLocker

    100%

ACC

User access

  • Okta · MFA on cloud

    312

  • Local admin rights

    controlled

  • Named accounts

    enforced

  • Leaver offboarding

    7d

MAL

Malware

  • CrowdStrike · enrolled

    97%

  • Signatures current

    live

  • Gatekeeper / SmartScreen

    on

  • App allow-listing

    servers

UPD

Updates

  • OS version coverage

    198

  • Critical patch SLA

    ≤14d

  • Auto-update enforced

    on

  • End-of-life OS

    0

Scheme & certification bodies

Bring your IASME-licensed certifier. Uproot has the evidence ready.

Cyber Essentials is owned by the NCSC and delivered through IASME and its licensed certification bodies. Uproot is body-agnostic whoever certifies you gets a read-only portal with the five controls already evidenced.

NCSC

scheme owner

IASME

accreditation

CyberSmart

ce cert body

Cyber Tec

ce cert body

URM

ce cert body

Evalian

ce cert body

Securious

ce cert body

Indelible Data

ce cert body

Babble

ce cert body

CESO

ce cert body

Cyber Smart UK

ce cert body

+ many

iasme-licensed

Cyber Essentials, plainly

Questions we get every week. Answered the way an engineer would.

What's the difference between CE and CE Plus?+

Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus adds an independent, hands-on technical audit of a sample of your devices. CE Plus carries more weight and is where weak patching gets caught.

Why do I need it?+

Many UK government and public-sector contracts require a current Cyber Essentials (or CE Plus) certificate to bid, particularly where personal or sensitive data is handled. Plenty of private buyers ask for it too.

What's in scope?+

Every internet-connected device used by your organization servers, laptops, desktops, mobiles, and the cloud services you administer unless properly segmented out. Uproot inventories the fleet so scope is based on reality.

What's the hardest control to keep?+

Update management. The 14-day critical-patch SLA is easy to state and hard to hold across a real fleet. It's the most common CE Plus failure and exactly what Uproot monitors continuously.

How long does certification last?+

Twelve months. You recertify annually. Because Uproot keeps the five controls continuously evidenced, renewal is a re-submission rather than a fresh project.

Does cloud count?+

Yes. Cloud services you configure are in scope, and the controls apply MFA on cloud admin, secure configuration of security groups, and so on. Uproot reads these from your cloud accounts directly.

Five controls. Zero surprises.

Inventory your fleet in minutes, prove all five controls per device, and keep the 14-day patch clock honest. The self-assessment writes itself and CE Plus finds nothing new.

Start Cyber EssentialsTalk to a CE lead
$uproot init --framework cyber-essentials
inventorying fleet198
checking five controls per deviceok
189 compliant · 7 patching · 2 flagged95%
self-assessment ready in 2m 14slive