Cyber Essentials is a UK government-backed scheme, run with the NCSC and delivered by IASME through certification bodies, that verifies five technical controls. It is not a DFSA or FSRA requirement. It is a low-cost, well-recognised baseline, most useful if you belong to a UK group, serve UK clients or bid for UK work. ISO 27001 and the regulators’ rules cover much more.
Cyber Essentials is a scheme developed by the UK’s National Cyber Security Centre (NCSC) and delivered by IASME. It checks that you have five basic technical controls in place, which together are designed to protect against the most common internet-based attacks:
There are two levels. Cyber Essentials is a self-assessment that a certification body verifies. Cyber Essentials Plus adds hands-on technical testing by an assessor.
The requirements moved to version 3.3 and a new question set, Danzell, which replaces Willow, for new assessments from late April 2026. Organisations whose assessment account already existed have a six-month transition. The five controls are unchanged, but marking is stricter:
Neither the DFSA nor the FSRA requires Cyber Essentials, and it is a UK scheme. It becomes useful when you are part of a UK group, serve UK clients, or bid for UK public-sector or supply-chain work that asks for it. Cre8 IT has a UK office and supports UK businesses as well as UAE ones.
It also lines up well with the protective controls in the DFSA’s GEN 5.5 (authentication, patching, malware protection and access control), which makes it a practical first milestone. It does not cover governance, incident response or third-party oversight, which regulators also expect.
| Cyber Essentials | ISO 27001:2022 | DFSA GEN 5.5 and FSRA cyber rules | |
|---|---|---|---|
| What it is | UK government-backed baseline scheme | International standard for an information security management system | Regulatory rules for authorised firms |
| What it covers | Five technical controls | Governance, risk, people, suppliers and technology | Governance, technical controls, third parties, incidents and reporting |
| How you show it | Certificate (Essentials or Plus), renewed every 12 months | Certificate from an accredited body, audited each year | Evidence to the regulator on request, plus incident reporting |
| Mandatory for DIFC and ADGM firms? | No | No | Yes |
Certification itself is carried out by an accredited certification body. An MSP can prepare you and supply the technical evidence, and Cre8 IT helps clients scope, fix and evidence their controls, but no MSP can certify you.
Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
