NCSC · IASME-delivered · CE & CE Plus
FRAMEWORKCyber Essentials is deliberately small five technical controls across every internet-connected device. Uproot proves all five from your real fleet, so CE Plus holds up.
Self-assessment ready in days
CE Plus evidence assembled automatically
acme-uk · Cyber Essentials Plus
198 devices in scope · IASME
95%
pass-ready
The five controls
198 devices
Firewalls
boundary + host
100%
Secure configuration
hardened baseline
96%
User access control
least privilege + MFA
98%
Malware protection
EDR enrolled
97%
Update management · 14-day SLA
7 devices patching
88%
Unsupported OS
0 devices
Cert body
CyberSmart
Critical patch SLA
14 days
Patch SLA breach caught
7 laptops fell outside the 14-day critical-update window. Owners paged before the CE Plus audit.
Technical controls
5Firewalls, secure configuration, user access control, malware protection, and update management.
Two levels
CE / CE+Cyber Essentials is a verified self-assessment. CE Plus adds a hands-on independent technical audit.
Renewal
AnnualCertification lasts twelve months. Many UK contracts require a current certificate to bid.
Authority
NCSCBacked by the National Cyber Security Centre, delivered through IASME and its certification bodies.
In scope
AlldevicesEvery internet-connected device servers, laptops, mobiles, and cloud services unless properly segmented.
Cyber Essentials covers the basics that stop the overwhelming majority of common attacks. The hard part isn't understanding the five controls it's proving they hold on everydevice, every day. That's exactly what Uproot does.
Firewalls
Boundary and host firewalls on every device, default-deny inbound. Cloud security groups count.
Secure configuration
Devices hardened from defaults unused accounts removed, default passwords changed, auto-run off.
User access control
Named accounts, least privilege, controlled admin rights, and MFA on cloud.
Malware protection
Anti-malware or allow-listing, current and enforced not merely installed.
Update management
Supported software with high/critical updates applied within 14 days; end-of-life software removed.
The 14-day patch SLA is simple to state and brutal to maintain across a fleet. Here's how Uproot turns it into live, device-level evidence.
All software must be supported, licensed, and patched: high and critical security updates applied within 14 days of release, and unsupported software removed. The single most common reason organizations fail a CE Plus assessment.
"When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort."
CONTROL 5 · UPDATE MANAGEMENT
High/critical updates within 14 days
Last evidenced 09:14:02 UTC · 198 devices · sha256 verified
The requirement
What Control 5 asks for
Your real fleet
What we read from your systems
Uproot pulls live device state from your MDM and EDR every laptop, server, and mobile in scope.
Evidence collected
Per-device, against the 14-day clock
Each device's OS version, pending criticals, and days-since-release are pulled, hashed, and measured against the SLA. End-of-life OSes are flagged automatically.
For the assessor
CE Plus, device-by-device
Your CE Plus assessor opens Control 5 and sees a live per-device patch report exactly the sampling they'd otherwise do by hand, already done.
SLA · 14 days · Owner · IT · Past SLA · 7
Cyber Essentials is fast by design. The work is making sure the self-assessment is true and that CE Plus finds nothing you didn't already know.
Day 0
Define scope
Confirm the boundary which devices, users, and cloud services are in scope. Uproot inventories them from MDM, EDR, and cloud.
Day 1–5
Prove the five
Firewalls, configuration, access, malware, and updates evidenced per device. Gaps issued as tickets to owners.
Day 6–10
Self-assessment
The verified questionnaire is answered from live evidence, not guesswork. Submit for Cyber Essentials.
Day 11–20
CE Plus audit
The assessor samples devices hands-on. Because the fleet state is already live, there's nothing to scramble for.
A self-assessment answered from memory and optimism, not from the actual fleet
One unpatched laptop nobody knew about, found live during the CE Plus audit
An end-of-life OS still in scope, quietly failing the whole certification
Re-doing the whole exercise next year from scratch, with the same blind spots
The questionnaire answered from live, per-device evidence you can stand behind
Patch-SLA breaches and EOL software surfaced as tickets before the assessor arrives
The whole fleet’s posture in one continuously-updated view
Next year’s renewal is already evidenced recertification without the redo
A map of where Uproot pulls Cyber Essentials evidence fleet management, endpoint protection, identity, and cloud.
Firewalls & config
Jamf · host firewall
on
Intune · config baseline
enforced
AWS · security groups
default-deny
FileVault / BitLocker
100%
User access
Okta · MFA on cloud
312
Local admin rights
controlled
Named accounts
enforced
Leaver offboarding
7d
Malware
CrowdStrike · enrolled
97%
Signatures current
live
Gatekeeper / SmartScreen
on
App allow-listing
servers
Updates
OS version coverage
198
Critical patch SLA
≤14d
Auto-update enforced
on
End-of-life OS
0
Cyber Essentials is owned by the NCSC and delivered through IASME and its licensed certification bodies. Uproot is body-agnostic whoever certifies you gets a read-only portal with the five controls already evidenced.
NCSC
scheme owner
IASME
accreditation
CyberSmart
ce cert body
Cyber Tec
ce cert body
URM
ce cert body
Evalian
ce cert body
Securious
ce cert body
Indelible Data
ce cert body
Babble
ce cert body
CESO
ce cert body
Cyber Smart UK
ce cert body
+ many
iasme-licensed
Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus adds an independent, hands-on technical audit of a sample of your devices. CE Plus carries more weight and is where weak patching gets caught.
Many UK government and public-sector contracts require a current Cyber Essentials (or CE Plus) certificate to bid, particularly where personal or sensitive data is handled. Plenty of private buyers ask for it too.
Every internet-connected device used by your organization servers, laptops, desktops, mobiles, and the cloud services you administer unless properly segmented out. Uproot inventories the fleet so scope is based on reality.
Update management. The 14-day critical-patch SLA is easy to state and hard to hold across a real fleet. It's the most common CE Plus failure and exactly what Uproot monitors continuously.
Twelve months. You recertify annually. Because Uproot keeps the five controls continuously evidenced, renewal is a re-submission rather than a fresh project.
Yes. Cloud services you configure are in scope, and the controls apply MFA on cloud admin, secure configuration of security groups, and so on. Uproot reads these from your cloud accounts directly.
Inventory your fleet in minutes, prove all five controls per device, and keep the 14-day patch clock honest. The self-assessment writes itself and CE Plus finds nothing new.