Does Cyber Essentials cover GDPR?
No - Cyber Essentials does not cover GDPR. Cyber Essentials is a technical cybersecurity baseline; GDPR is a data-protection regulation covering lawful basis, rights, transfers, and accountability. They overlap at the technical-security boundary but neither replaces the other.

Section 01
Does Cyber Essentials cover GDPR?
No - Cyber Essentials does not cover GDPR. Cyber Essentials is a technical cybersecurity baseline; the UK GDPR (and EU GDPR) is a data-protection regulation covering lawful basis for processing, data-subject rights, international transfers, and organisational accountability. They overlap at the technical-security boundary but neither replaces the other.
Section 02
Where they overlap
UK GDPR Article 32 requires "appropriate technical and organisational measures" to ensure security of processing. The five Cyber Essentials controls can help with baseline technical security. ICO guidance requires measures proportionate to the nature and risk of processing; other technical, physical and organisational measures may be needed.
The ICO lists Cyber Essentials as an example of basic technical controls to consider. A certificate may support an evidence discussion, but it does not establish Article 32 compliance for every processing activity.
Section 03
What GDPR requires that Cyber Essentials does not
- Lawful basis for processing. Cyber Essentials does not assess whether you have a valid lawful basis.
- Privacy notices, data-subject rights, and consent management. Out of scope.
- Records of Processing Activities (RoPA). Out of scope.
- Data Protection Impact Assessments. Out of scope.
- International data transfer mechanisms (SCCs, IDTA). Out of scope.
- Data Protection Officer designation. Out of scope.
- Personal-data breach assessment and notification. Where a breach is likely to risk individuals' rights and freedoms, the controller must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware. Other notification rules may apply; the certificate does not decide them.
Section 04
What Cyber Essentials requires that GDPR does not directly
- The specific 14-day patching rule for high/critical vulnerabilities.
- The specific firewall / boundary device configuration rules.
- The scheme's applicable MFA requirements for in-scope accounts and cloud services.
- The specific supported-OS rules.
UK GDPR calls for measures appropriate to the processing risk. Cyber Essentials provides one useful baseline; it is not a universal Article 32 threshold.
Section 05
The practical answer for UK SMEs
For most UK SMEs the sensible stack is:
1. Cyber Essentials - one technical baseline to consider in a risk-based Article 32 programme.
2. A published privacy notice, a documented lawful basis, a RoPA, a breach-response plan - organisational GDPR measures.
3. Optional higher tiers - IASME Cyber Assurance Level 2 or ISO 27001 where contractual or regulatory expectation requires a broader ISMS.
Cyber Essentials can support technical security, alongside controls chosen for the actual processing risk.
Section 06
Bottom line
Cyber Essentials does not cover GDPR. Assess your processing risks, use appropriate technical and organisational measures and keep the governance records your circumstances require. A CE certificate can contribute evidence without proving the whole programme.
Fig Group offers a conditional Basic six-working-hour guarantee after a complete, compliant submission under its terms, from £299.99 + VAT.
Start Cyber Essentials from £299.99 + VAT | Cyber Essentials vs ISO 27001 | Free readiness check
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
What are the five Cyber Essentials controls?
The five Cyber Essentials controls are: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations.
Read articleIndustry
CJSM, Common Platform, and Criminal Chambers: The Digital Security Baseline for 2026
CJSM is a transport-level network, not end-to-end encrypted email. Common Platform is the HMCTS case system. Neither is a substitute for the baseline cybersecurity controls that CE asks for. This guide covers how to think about these systems alongside Cyber Essentials in a UK criminal chambers context.
Read articleGuides
Cyber Essentials Belfast: a practical certification guide
Belfast technology suppliers can use Cyber Essentials to demonstrate a national technical baseline while keeping product security and customer-specific assurance separate. Expertise in cybersecurity does not remove the need to verify how the company’s own accounts, devices and business services are managed.
Read article

