Skip to content
Industry

Cyber Essentials for Critical Digital Infrastructure Providers in the UK

The Cyber Security and Resilience Bill proposes expanded regulatory coverage of data centres, cloud providers, and digital service providers. Here is what these organisations need to know about Cyber Essentials.

white and blue light on dark room

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

10 min read

Share

Section 01

Cyber Essentials for Critical Digital Infrastructure Providers in the UK

The Cyber Security and Resilience Bill proposes changes to the NIS framework. Distinguish the proposal, existing duties and future commencement; a Bill or factsheet does not by itself establish that every new duty is already in force.

For organisations that provide the digital backbone of the UK economy, this means new compliance obligations are coming. Cyber Essentials certification is the starting point.

Section 02

What the Cyber Security and Resilience Bill Changes

The original Network and Information Systems (NIS) Regulations 2018 covered a narrow set of essential services: energy, transport, water, health, and digital infrastructure (primarily DNS providers, internet exchange points, and top-level domain registries).

The Cyber Security and Resilience Bill significantly expands this scope. The government’s factsheets describe proposals to bring the following into regulatory scope:

Data centres - recognised as critical national infrastructure by the UK government in September 2024. The Bill proposes a separate statutory regime; critical-national-infrastructure designation does not itself establish that the proposed duties have commenced.

Managed service providers - the proposals would bring qualifying medium and large MSPs into regulation by the Information Commissioner. The government’s March 2025 policy statement estimated 900–1,100 additional MSPs; this is a proposal-stage estimate, not a current regulated-provider count. Check the final statutory definitions and commencement.

Digital service providers - online marketplaces, search engines, and cloud computing services already fell under NIS, but the Bill strengthens the requirements and enforcement mechanisms.

Supply chain dependencies - the Bill gives regulators power to designate critical suppliers to essential services, bringing them directly into scope even if they would not otherwise qualify.

The government’s data-centre factsheet assigns the proposed data-centre regime to Ofcom. The ICO has roles for relevant digital service providers and proposed managed-service-provider regulation. Check the current statutory scope and commencement rather than treating every proposal as an enacted duty.

Section 03

Why Cyber Essentials Matters for These Organisations

Many critical digital infrastructure providers will need to implement comprehensive security frameworks - ISO 27001, SOC 2, or sector-specific standards. But Cyber Essentials serves a specific and valuable role even for organisations pursuing those larger certifications:

It covers the fundamentals. The five controls address common cyber risks. Do not read a general attack-prevention estimate as a guaranteed reduction for an infrastructure provider or as evidence of sector-specific resilience.

It is fast to assess once prepared. Fig Group’s six-working-hour Basic assessment commitment applies to a complete, compliant submission before midday on a UK Business Day, subject to the certification terms. Preparation, remediation and other assurance programmes have separate timetables; do not use a generic ISO 27001 or SOC 2 duration as a project deadline.

It can support supply-chain requirements. Check the actual procurement conditions. PPN 014 concerns specified procurements by in-scope public bodies and can accept equivalent controls; neither government-supplier status nor data-centre status establishes a universal certification prerequisite.

It demonstrates baseline control assurance. A certificate can contribute evidence, but does not establish compliance with all NIS or proposed Bill duties, nor guarantee favourable regulatory treatment.

Section 04

The Specific Challenges for Infrastructure Providers

Critical digital infrastructure providers face particular challenges in achieving and maintaining Cyber Essentials:

Scope definition. A data centre operator or cloud provider has a large and complex IT estate. Defining what is "in scope" for Cyber Essentials requires careful thought. The scope should include all devices and services that handle or process data, including management interfaces, monitoring systems, and administrative access points.

Multi-tenant environments. Define the provider/customer responsibility split, management plane and workloads clearly. Do not exclude production infrastructure or hosted services simply because customers use them. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor.

Patch management at scale. Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update. Automated deployment can help; an operational delay is not a waiver of the deadline.

Remote and distributed operations. Many infrastructure providers operate across multiple sites with staff accessing management systems remotely. Every access point and every device used for management is in scope.

Section 05

The v3.3 Changes and Infrastructure Providers

Cyber Essentials v3.3, effective from 27 April 2026, introduces changes that are particularly relevant to infrastructure providers:

Enable MFA for every user account accessing in-scope cloud services, including administrator and third-party accounts. Implement MFA where available on non-cloud systems and apply the separate administrative-access and password controls; do not assume v3.3 mandates MFA on every local account regardless of availability. Document non-interactive service identities separately rather than treating them as human logins.

Device scope. Include employees’ home devices used for organisational data or management services under the BYOD rules. Apply the separate third-party ownership rule; do not describe every external user’s own endpoint as included.

Firmware and BIOS updates. v3.3 clarifies that firmware updates for network equipment and servers fall within the patch management requirements. This is particularly relevant for data centres with large inventories of physical hardware.

Section 06

Getting Certified

For critical digital infrastructure providers, we recommend the following approach:

1. Define your scope - Identify all systems, devices, and services that fall within the Cyber Essentials boundary. For infrastructure providers, this typically includes management networks, administrative workstations, monitoring systems, and corporate IT

2. Run the readiness check - Use Fig Group's free readiness tool to assess your current position against the five controls

3. Address gaps - Common gaps for infrastructure providers include MFA not enforced on all management interfaces, firmware updates overdue on network equipment, and overly broad admin access

4. Certify. Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment. Plus has a prepared-assessment target of 2–3 working days after valid matching Basic certification, subject to scheduling, access and remediation; successful assessment is required.

Section 07

Building Toward Broader Compliance

For many critical infrastructure providers, Cyber Essentials is the first step in a broader compliance programme. The controls map naturally to the foundational requirements of ISO 27001, SOC 2, and NIS2.

If your organisation is planning an ISO 27001 implementation, Cyber Essentials provides a verified starting point for the technical controls in Annex A. If you are pursuing SOC 2, the five Cyber Essentials control themes map to common criteria across multiple trust service categories.

Fig Group offers a compliance platform that maps your Cyber Essentials controls to these broader frameworks, giving you visibility of where you stand and what still needs to be done. The certification journey does not have to start from scratch each time.

Get certified today

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.