Compliance and security glossary
Understand the terms used in certification, cybersecurity and risk management. Search by name or abbreviation, then open a definition for further guidance.
106 terms available
14-Day Patching Rule
Apply qualifying vendor-approved security fixes within 14 days of vendor release. A high or critical vendor rating, CVSS v3 base score of at least 7, or a vulnerability with no vendor severity description can trigger the deadline. For example, a Tuesday update with an unclassified fix is due within 14 days even if a monthly window falls later; assess the whole bundle, release date and supported fix.
6-Hour Certification Guarantee
Fig Group’s service promise applies to a complete, compliant Cyber Essentials Basic self-assessment received before midday on a UK business day, subject to its published certification terms. For example, buying on Monday while still preparing evidence does not start the six-working-hour review clock; a qualifying submission does. This is a supplier guarantee, not an IASME scheme entitlement.
Account Lockout
Account lockout or throttling limits repeated failed attempts against an account. For an internet-facing password sign-in, five wrong attempts might trigger a delay or temporary block under the chosen control; other effective rate limiting can also protect it. Device-unlock rules and online account protection have different contexts. MFA adds protection but does not make weak password-guessing controls acceptable.
Administrative Account
An account able to change configuration, install software or manage users. Cyber Essentials requires separate privileged and everyday use, and MFA wherever available, including cloud authentication. For example, an administrator reads email with a daily account and uses a separate privileged account for tenant changes. Fig Group recommends phishing-resistant MFA for that account as additional recommended protection, not a universal scheme-specific factor.
Advanced Protection Program (APP)
Google’s Advanced Protection Program offers stronger account protection for higher-risk users, including passkeys or security keys and recovery controls. Fig Group recommends considering it for Google super administrators where appropriate. Cyber Essentials requires effective authentication under its own rules; subscribing to this Google programme is not a certification prerequisite.
Assessor
An individual trained and authorised for the relevant IASME scheme and level who reviews an applicant’s evidence. A Certification Body holds the organisational licence and issues certification; the assessor performs the review. Fig Group’s supported certification services use human assessor review, with software assisting evidence triage rather than deciding an outcome.
Asset Register
A documented inventory of every device, operating system, application, and cloud service in Cyber Essentials scope. The register underpins patch management, malware protection coverage, and evidence during assessor review.
Audit Trail
A traceable record of relevant events, such as “2026-09-29 09:00, admin@example.com changed the MFA policy”. It helps an organisation investigate who did what and when. Choose retention, completeness and tamper evidence to meet the applicable risk and obligations; one universal retention period is not implied. An audit trail is a record, distinct from the remote review performed during certification.
Auto-run
Automatic execution of software or media content when a device or file is opened or attached, including downloaded content and removable media where the platform supports it. Secure configuration should prevent untrusted content running without an intentional user action. Disabling USB AutoPlay alone is not the whole control, and blocking autorun does not forbid a user from deliberately opening an authorised application.
BitLocker
A Windows disk-encryption feature used to protect stored data. Check the supported edition, actual protection state and recovery-key arrangements. BitLocker can support broader security and contractual obligations, but Cyber Essentials does not universally mandate it or Intune. Disk encryption is separate from demonstrating the five certification controls.
Boundary Firewall
The firewall separating your internal network (or corporate VPN gateway) from the public internet. Under Cyber Essentials v3.3, the boundary firewall must have a non-default admin password, current firmware, and deny inbound traffic by default.
Break-Glass Account
A protected emergency administrative identity used when normal privileged access fails. This is a resilience pattern, not a universally required Cyber Essentials account type. Design independent authentication, monitoring and tested recovery; an exception from one Conditional Access policy must not become a blanket bypass of mandatory cloud MFA.
BYOD
Bring Your Own Device: personal devices used for work. Devices accessing organisational data or services are generally in Cyber Essentials scope, including endpoints accessing virtual desktops. The scheme has a specific exception for devices used only for native voice, native text or MFA applications. Ownership or the presence of MDM alone does not decide scope.
Certification Body
An organisation licensed by IASME to assess and certify applicants for the specific schemes and levels in its authorisation. Permission to deliver Cyber Essentials does not by itself establish Cyber Essentials Plus or DCC authorisation. Fig Group delivers certification through Fig Compliance Ltd; check each separate scheme licence on our licence evidence page.
CISA KEV
The US CISA Known Exploited Vulnerabilities catalogue records vulnerabilities with evidence of exploitation. Each entry carries its own due date for covered US federal agencies; other organisations can use KEV to prioritise risk. Cyber Essentials instead measures its qualifying 14-day update deadline from vendor release. Check the applicable obligation and fix rather than applying one universal KEV clock.
CMMC
The US defence Cybersecurity Maturity Model Certification programme, distinct from UK DCC and Cyber Essentials. CMMC 2.0 defines Levels 1, 2 and 3, replacing the legacy five-level model. The required assessment, current implementation phase and contract clause determine a supplier's obligations; verify the live official programme guidance rather than assuming every defence contract has the same requirement.
Compliance Automation
Technology can collect supported system evidence, remind owners, test selected configurations and flag changes. For example, a new device inventory export can refresh a patch-status record, which a control owner reviews before an assessment. People still decide scope, exceptions and certification outcomes; automation is not an autonomous compliance guarantee.
Conditional Access
An identity-provider policy that uses signals such as user, device and location to decide whether to allow access and require MFA. For example, a cloud administrator may need a trusted device and MFA before accessing a management portal. Review effective policies and session handling so location or risk exclusions do not bypass mandatory cloud MFA. Conditional Access is not a product universally required by the scheme, and a new MFA prompt on every request is not mandatory.
Control Framework
A structured set of security controls that an organisation implements to manage risk and meet regulatory requirements. Common control frameworks include ISO 27001 Annex A, NIST CSF, CIS Controls, and the Cyber Essentials five-category model.
CRP
An abbreviation for Cyber Risk Profile, the buyer-assigned level in the MOD Cyber Security Model. Current CSMv4 profiles are numbered 0 to 3. Obtain the assigned profile and Risk Assessment Reference from your customer, and use the full Cyber Risk Profile explanation when planning certification. Do not convert a legacy verbal risk band into a current level yourself.
CS&R
The UK Cyber Security and Resilience (Network and Information Systems) Bill proposes reforms to the NIS Regulations, including initial incident notification within 24 hours and a fuller report within 72 hours for relevant regulated entities and incidents. As reviewed on 27 September 2026, it remains a Bill in Parliament; proposals are not current enacted obligations. Confirm the final legislation, commencement and organisation-specific scope. Fig Group’s incident workflow can support preparation without establishing legal compliance.
CVE
A Common Vulnerabilities and Exposures identifier names a publicly recorded vulnerability; it is not itself a severity score or proof of active exploitation. An illustrative record such as CVE-YYYY-NNNN might have a CVSS score and separately appear in an exploited-vulnerability catalogue. Check the affected product, vendor fix and full Cyber Essentials update rule rather than assuming every CVE has the same deadline.
CVSS
The Common Vulnerability Scoring System describes technical severity. Scores can differ by version or assessor and do not by themselves show exploitation likelihood. CVSS answers “how severe?”, EPSS estimates exploitation probability, and CISA KEV records known exploitation. Cyber Essentials also considers vendor severity and unspecified-severity fixes; read the complete update rule.
Cyber Essentials
Cyber Essentials is a UK government-backed certification scheme, governed by the NCSC and operationally delivered by IASME, that validates an organisation has implemented five core cybersecurity controls: firewalls, secure configuration, user access control, malware protection, and security update management.
Cyber Essentials Plus
Cyber Essentials Plus independently tests the same five controls after a valid Cyber Essentials assessment for the matching scope. Testing includes specified internal and external checks, device configuration and authentication; it is more than an external scan. Fig Group Plus prices are £1,499.99–£4,499.99 + VAT by size, with the package and prerequisites on the Plus page.
Cyber Essentials v3.3
The April 2026 edition of the NCSC Requirements for IT Infrastructure, used with the Danzell question set for assessments opened from 27 April 2026. It clarifies cloud scope and passwordless authentication. MFA is required where available and for cloud authentication; it is not a universal fresh-prompt-on-every-sign-in rule. Check the version assigned to an existing assessment.
Cyber Risk Profile
The level assigned through the MOD Cyber Security Model risk assessment for a contract or activity. CSMv4 uses numeric Levels 0, 1, 2 and 3. These are not direct equivalents of the legacy Very Low, Low, Moderate and High labels. The buyer provides the required profile and Risk Assessment Reference; certification and contract-specific assurance remain distinct.
Data Sovereignty
Data sovereignty concerns the laws and authorities that can affect data; data residency concerns physical storage location. A UK region alone does not determine every legal obligation or international transfer: access, backups, telemetry and subprocessors also matter. Confirm the actual service and contractual data flow before asserting UK-only processing; UK GDPR does not universally require UK hosting.
DCC
Defence Cyber Certification provides independent assurance against the MOD Cyber Security Model. Its four levels align with the current numeric profiles, rather than replacing the contract process. A certificate does not remove the requirement to complete the contract-specific Supplier Assurance Questionnaire. Fig Group offers assessment at Levels 0 and 1; confirm the required level with your buyer.
DCC Level 0
The entry level of Defence Cyber Certification, corresponding to current numeric Level 0 requirements. It assesses the applicable controls and requires a separate, current Cyber Essentials certificate. Confirm organisational scope and the current scheme criteria before applying; do not infer this level from the old Very Low label. Fig Group offers Level 0 assessment.
DCC Level 1
Defence Cyber Certification against current numeric Level 1 requirements, with broader assurance than Level 0. Confirm the applicable Cyber Essentials prerequisite, scope and evidence with the certification body. It is not simply a renaming of the legacy Low risk band. Fig Group offers Level 1 assessment; contract-specific SAQ responsibilities continue.
DCC Level 2
A higher level of Defence Cyber Certification against current numeric Level 2 requirements. Use the official level criteria for prerequisites, assessment and organisational scope rather than treating it as a Cyber Essentials Plus audit or equating it to the legacy Moderate band. Fig Group does not deliver Level 2 assessment and refers this work to an appropriately authorised provider.
DCC Level 3
Defence Cyber Certification against the highest numeric level in the current four-level scheme. Confirm prerequisites and assessment scope through official guidance and the buyer requirement. It is not an automatic conversion from the legacy High band or a substitute for information-handling obligations. Fig Group does not deliver Level 3 assessment and refers this work to an appropriately authorised provider.
DCPP
The Defence Cyber Protection Partnership brought government and industry together on supply-chain cyber protection. It is distinct from the MOD Cyber Security Model, its controls standard and IASME-delivered Defence Cyber Certification. For a current contract, obtain the assigned numeric Cyber Risk Profile and Risk Assessment Reference from the buyer rather than treating an older partnership reference as a certification instruction.
Def Stan 05-138
The defence supplier cyber-security controls standard. CSMv4 uses Issue 4 and numeric Cyber Risk Profiles 0 to 3. Earlier Issue 3 and verbal risk bands are historical references, not a direct conversion table for current levels. Ask the buying authority to clarify the version, assigned profile and evidence required for the contract.
DEFCON 658
The MOD contractual condition supporting Cyber Security Model obligations, including supplier assurance and flow down to subcontractors. Follow the version and requirements in the actual contract. DCC provides independent evidence but does not currently replace the full contract-specific Supplier Assurance Questionnaire submitted through the Supplier Cyber Protection Service.
DORA
The Digital Operational Resilience Act - EU regulation applying to financial sector entities and their ICT providers. DORA requires ICT risk management, incident reporting, operational resilience testing, and oversight of third-party ICT providers. In effect from January 2025.
EDR (Endpoint Detection and Response)
Security software that continuously monitors endpoints for suspicious behaviour, investigates threats, and responds automatically. Examples: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne. Exceeds Cyber Essentials minimum.
EPSS
Exploit Prediction Scoring System - a probabilistic score from 0 to 1 that estimates the likelihood a given CVE will be exploited in the wild in the next 30 days. Fig Group's vulnerability management workflow prioritises by EPSS and CISA KEV.
Evidence Collection
Gathering dated policies, logs, configuration exports and other records that demonstrate how a control operates. An integration may collect a device state, but a person still checks its scope, freshness and relevance before an assessor relies on it. Fig Group’s platform can help collect supported evidence; connector counts alone do not prove that every security control is verified.
FIDO2
Standards for public-key authentication, including WebAuthn and supported authenticators. FIDO2 authentication with user verification can satisfy Cyber Essentials MFA requirements. Phishing-resistant authentication is recommended hardening for privileged access; the scheme does not universally prescribe a particular FIDO2 device or product.
FileVault
The macOS feature that protects access to data using disk encryption. Hardware-backed storage encryption does not by itself establish that FileVault protection is enabled for the user configuration. Verify activation and recovery arrangements. Encryption is valuable security practice and may be required by other obligations, but it is not a universal requirement of the five Cyber Essentials controls.
Firewalls and Internet Gateways
One of the five Cyber Essentials controls. Manage boundary firewall and internet-gateway rules, allowing only necessary inbound traffic, with secure administration. Devices used away from an office boundary, such as roaming laptops, also need an appropriate software or host firewall. A compliant office appliance alone does not cover every in-scope endpoint.
GDPR
The EU General Data Protection Regulation and the separate UK GDPR govern personal-data processing within their respective territorial scopes. Applicability is not determined by a person's residence alone. Controllers assess breach-notification duties against the applicable risk threshold; under UK GDPR, report a qualifying breach without undue delay and, where feasible, within 72 hours of awareness. Processors notify their controller without undue delay.
Governance-First
An approach to security and compliance that starts with governance structures (policies, risk registers, accountability frameworks) before implementing technical controls. Ensures security investments align with business objectives and regulatory requirements.
GRC
Governance, Risk and Compliance connects decisions, risk records, controls, evidence, incidents and reviews so accountable people can see what is working. Platforms differ in scope and price; compare the same functions, organisation size, support and licence terms before choosing one. Fig Group provides GRC capabilities through its platform.
Home Worker Device
A device used for organisational data or services while working remotely. Employee-owned work devices are generally in scope, subject to the scheme exceptions. A worker- or ISP-supplied home router is outside assessment scope; an organisation-supplied router is included. Apply the required firewall controls to the actual remote-working arrangement.
IaaS
Infrastructure as a Service - virtualised compute, storage, and networking delivered on demand. Examples: AWS EC2, Azure VMs, Google Compute Engine. In Cyber Essentials scope if you run organisational data on it; the cloud provider handles the infrastructure, you handle OS, data, and identity.
IASME
The Information Assurance for Small and Medium Enterprises consortium is the NCSC-appointed delivery partner for Cyber Essentials. IASME licenses UK Certification Bodies, including Fig Compliance Ltd, to assess organisations. Each scheme licence is independently verifiable through Blockmark.
IASME Cyber Assurance
IASME Cyber Assurance is an independently assessed security standard with Level 1 and Level 2. It can help an organisation demonstrate broader security practices beyond Cyber Essentials, but it is not interchangeable with ISO 27001 certification: buyers must check their specified standard and assurance level. Jay Hopkins at Fig Group holds IASME Cyber Assurance assessor accreditation.
IL2
Impact Level 2, a historical information-impact designation. It is not a current DCC level and cannot by itself determine a modern classification or certification requirement. Read the current security requirements and buyer-assigned Cyber Risk Profile in the contract; ask the authority to clarify any retained legacy terminology.
IL3
Impact Level 3, a historical information-impact designation. It should not be presented as a direct equivalent of OFFICIAL-SENSITIVE or a particular DCC tier. Contract-specific handling requirements and the current buyer-assigned Cyber Risk Profile determine the required assurance. Obtain clarification where older labels remain in procurement documents.
IL4
Impact Level 4, a historical information-impact designation. It does not automatically translate to SECRET or a particular DCC tier. Establish the current classification, handling controls and numeric Cyber Risk Profile with the buyer. Fig Group delivers DCC Levels 0 and 1 and refers requirements outside that assessment scope to an appropriately authorised provider.
In Scope
Devices, users, networks, and services that access organisational data are "in scope" for Cyber Essentials. All five Cyber Essentials technical controls (firewall, secure configuration, user access control, malware protection, security update management) apply to in-scope assets.
Incident Response
The structured process of detecting, containing, eradicating, and recovering from security incidents. An effective IR programme includes pre-defined playbooks, clear roles and responsibilities, communication templates, and post-incident review.
Internet-Facing Device
Any device or service with an interface exposed to the public internet - web servers, VPN gateways, mail relays, public APIs. Cyber Essentials Plus external vulnerability scans focus on internet-facing devices.
Intune
Microsoft device and application management software. It can help enforce configuration, collect device information and manage access policies. Cyber Essentials does not prescribe Intune or another MDM vendor. A compliant-device policy does not automatically exclude a personal device or VDI endpoint from scope; agree the actual assessment boundary with the assessor.
ISO 27001
The international standard for information security management systems (ISMS). ISO 27001 provides a systematic framework for managing sensitive information through risk assessment, control implementation, and continuous improvement. Heavier than Cyber Essentials; Cyber Essentials is a practical first step towards ISO 27001.
ISO 27017 / ISO 27018
Cloud-security and public-cloud privacy standards that complement ISO 27001. They can support assurance beyond Cyber Essentials. Cloud services used for organisational data or services remain in Cyber Essentials scope; separate ISO assurance does not exclude production hosting. Document the provider/customer control responsibilities.
Jamf
Enterprise MDM for Apple (macOS, iOS) devices. Jamf Pro and Jamf Now enforce device policies, passcode complexity, FileVault, and app installation. Common BYOD and corporate-device management tool for UK organisations certifying under Cyber Essentials v3.3.
Least Privilege
The principle of granting users only the permissions they need to perform their job. Under Cyber Essentials v3.3, users must not have admin rights unless necessary, and admin rights must be documented and reviewed periodically.
Legacy Authentication
Older authentication mechanisms, commonly basic authentication, that do not support modern authentication controls. POP, IMAP and SMTP are protocols and can support OAuth in suitable implementations; they are not inherently basic authentication. Identify and remove authentication paths that bypass required MFA instead of relying on a protocol name alone.
Malware Protection
A Cyber Essentials control preventing malicious or untrusted software from running. Version 3.3 provides an anti-malware option for Windows and macOS and an application allow-listing option for all platforms. Verify the chosen mechanism is active, maintained and configured to meet its requirements. EDR, a product name or a licence alone does not prove compliance.
MAV (Minimum Acceptable Version)
Under Cyber Essentials v3.3, the vendor-defined minimum version of software that is still supported and receiving security updates. Anything below MAV is "unsupported software" and fails Cyber Essentials unless removed or segregated.
MFA
Multi-factor authentication verifies identity using independent factors. Cyber Essentials v3.3 requires its use wherever available and for authentication to cloud services. Check actual enforcement across user, administrator and third-party access. Having registered an authenticator does not establish compliance, and reusing an authenticated session is not the same as bypassing MFA.
MSP
A Managed Service Provider - an organisation that manages IT infrastructure, security, and compliance services on behalf of its clients. MSPs typically serve multiple clients and require multi-tenant platforms. Fig Group's MSP programme supports white-label Cyber Essentials reselling.
MSSP
A Managed Security Service Provider specialises in delivering security-focused services including threat monitoring, incident response, vulnerability management, and compliance. MSSPs differ from general MSPs in their specific focus on security operations.
NCSC
The UK National Cyber Security Centre, part of GCHQ. The NCSC sets UK government cybersecurity policy, authors the Cyber Essentials scheme requirements, and maintains guidance on secure configuration, incident response, and supply chain security.
NIS2
The Network and Information Systems Directive 2 - EU directive strengthening cybersecurity for essential and important entities across 18 sectors. NIS2 mandates risk management, incident reporting, supply chain security, and management accountability.
Number Matching
An MFA push-notification feature that displays a number on the sign-in screen which the user must type into their authenticator app. Prevents MFA-fatigue attacks. Microsoft Authenticator requires number matching as default from February 2023.
Out of Scope
An asset or service outside the agreed certification boundary. Exclusions need a valid scheme basis, not simply a statement that no files are stored locally. Cloud services used for organisational data or services cannot be excluded. Agree any separately managed, network-segregated subset with the assessor; an access policy alone does not establish that boundary.
OWASP Top 10
OWASP’s 2025 list groups common web-application security risks, such as broken access control; it is not a catalogue of ten individual vulnerabilities or a fixed biennial release. It can inform application risk reviews and secure configuration, but it is not a direct Cyber Essentials certification requirement.
PaaS
Platform as a Service - managed runtime environments for deploying code without managing underlying OS. Examples: AWS Lambda, Azure App Service, Vercel. In Cyber Essentials scope when they process organisational data.
Passkey
A public-key credential used for passwordless authentication. Passkeys may be device-bound or synchronised; they are not limited to Apple or Google accounts. Cyber Essentials v3.3 recognises FIDO2 authenticators with user verification as MFA. Check the actual authenticator and authentication flow rather than assuming every passwordless method meets the requirement.
Penetration Testing
An authorised attempt to identify and demonstrate exploitable weaknesses in a defined system or application. Its scope and methods differ from the Cyber Essentials Plus assessment specification. A penetration test does not replace the required Plus tests or its Cyber Essentials prerequisite; agree the right assurance exercise for the buyer requirement.
Policy Management
The lifecycle management of organisational security and compliance policies: drafting, reviewing, approving, distributing, tracking acknowledgement, and periodically updating. Effective policy management ensures staff understand their responsibilities and the organisation can demonstrate governance to auditors.
PPN 014
PPN 014 is the Cabinet Office policy for proportionate cyber-security assurance in relevant public procurement. It applies to specified central-government and NHS bodies and includes equivalent-control provisions. Check the contract and transitional rules rather than assuming every public supplier must hold a certificate. The former label PPN 014/21 is not the correct policy reference.
Re-Submission
An updated Cyber Essentials self-assessment submitted after assessor feedback. Fig Group includes three free re-submissions with its Cyber Essentials certification offer. Check the applicable terms and readiness requirements. Other providers set their own charges; do not assume a universal market fee. Formal Cyber Essentials Plus retesting follows separate scheme and engagement rules.
Remote Audit
The Cyber Essentials Plus audit format: the assessor reviews device samples, runs external scans, and tests malware protection via video call and screen share rather than in person. Fig Group Cyber Essentials Plus audits are remote by default.
Risk Register
A documented record of identified risks, their likelihood, potential impact, current controls, and treatment plans. A risk register is a living document that should be reviewed regularly and updated as new risks emerge or existing risks change.
SaaS
Software as a Service - full applications delivered over the internet. Examples: Microsoft 365, Google Workspace, Salesforce. Always in Cyber Essentials scope if it holds organisational data; the provider handles infrastructure, you handle identity and access configuration.
Scope Boundary
The agreed limit of a Cyber Essentials assessment, identifying the organisational unit, networks, locations, devices and services covered. A separately managed subset needs the prescribed network segregation and assessor agreement. An identity provider or Conditional Access rule can control authentication without creating the network boundary needed for a subset.
Scope Statement
A written declaration by the applicant, on the self-assessment form, of what devices, users, networks, and services are in and out of Cyber Essentials scope. The scope statement is the first thing an assessor reads and the first thing a feedback round tends to query.
Screen Lock
A device control that requires a user to unlock it before continuing access. Choose appropriate locking behaviour and protect unlocking credentials. Cyber Essentials v3.3 requires at least six characters for a device-only password or PIN, with full authentication requirements where the credential also authenticates. It does not prescribe a universal fifteen-minute inactivity timer or an MDM product.
Secure Configuration
One of the five Cyber Essentials controls. Remove unnecessary software and accounts, change insecure default credentials, disable unneeded services and autorun, and apply settings suited to the device. A default account can remain where needed if secured appropriately; the scheme does not automatically ban every pre-installed account. Extra vendor hardening may exceed the certification minimum.
Security Defaults
Microsoft Entra baseline identity protections, including MFA registration and controls against legacy authentication. The feature is not an automatic Cyber Essentials pass for organisations below a particular size. Review effective cloud authentication, service identities and session behaviour against the scheme requirements; registration and tenant size alone do not prove enforcement.
Security Update Management
One of the five Cyber Essentials control categories. Keep in-scope software licensed and supported, and apply qualifying fixes within 14 days of vendor release: vendor-rated high or critical vulnerabilities, CVSS v3 base scores of at least 7, or vulnerabilities without vendor severity details. A bundled update containing a qualifying fix inherits that deadline.
Segregation of Duties
Distributing incompatible responsibilities so one person cannot complete every stage of a sensitive transaction alone. Cyber Essentials separately requires administrators to use privileged accounts for administration and everyday accounts for routine work. That account separation does not itself require a second employee or constitute a universal dual-approval rule.
Self-Assessment Questionnaire (SAQ)
The core Cyber Essentials instrument: a structured questionnaire covering the five technical control categories. Completed by the organisation, submitted to an IASME-licensed certification body for review. Most organisations complete the SAQ in 1-3 hours given adequate preparation.
Shared Responsibility
The cloud security division of labour: the cloud provider secures the infrastructure (physical, network, hypervisor), the customer secures their application, data, and identity configuration. Cyber Essentials v3.3 tests the customer side.
SIEM
Security Information and Event Management - systems that collect, aggregate, and analyse log data from across an organisation's IT environment to detect security threats and anomalies. SIEM platforms provide real-time alerting and forensic investigation capabilities.
Single Sign-On (SSO)
Centralised authentication where the user signs in once at the identity provider and accesses all integrated SaaS tools without separate passwords. Under Cyber Essentials v3.3, SSO is the cleanest way to enforce MFA across multiple SaaS applications.
SOC 2 Type II
An independent attestation report on a service organisation's controls over a defined period. Its scope is set by the described system and applicable trust services criteria. It can complement Cyber Essentials, but neither report has a universal product-only or corporate-only boundary. Check the actual report and certificate scopes before relying on either.
SPF / DKIM / DMARC
Email authentication mechanisms that help receiving systems assess sender authority, message signatures and domain alignment. They support protection against spoofing. Cyber Essentials Plus includes specified email-delivered malware testing; that is not the same as a universal SPF, DKIM and DMARC certification test. Label any additional email-security assessment separately.
Standard Account
A non-privileged user account used for day-to-day activities. Users with administrative duties must have both a standard account for email/web/line-of-business apps and a separate administrative account for privileged actions.
Sub-Set Exclusion
An agreed exclusion of a separately managed part of the organisation with the required network segregation. Document the business unit, location, technical boundary and reason with the assessor. A VDI session, MDM policy or user-group restriction does not automatically exclude an endpoint that accesses organisational data or services.
Supply Chain Risk
The potential for security incidents caused by vulnerabilities in an organisation's third-party vendors and service providers. NIS2 and DORA both include specific supply chain requirements; Fig Group's supplier risk monitoring capability automates third-party risk scoring.
Supported Software
Software currently receiving security updates from its vendor. Unsupported software (end-of-life OS, discontinued applications) must be removed or isolated from scope under Cyber Essentials v3.3.
Tamper Protection
A Microsoft Defender feature that helps prevent unauthorised changes to security settings. It is useful hardening; Cyber Essentials v3.3 does not name tamper protection as a separate universal requirement. Verify the active malware-protection mechanism against all applicable scheme requirements.
Third-Party Risk Management
The discipline of assessing and monitoring risks introduced by external vendors, suppliers, and service providers. TPRM programmes include vendor due diligence, risk scoring, contractual security requirements, and ongoing monitoring.
Unsupported Software
Software no longer receiving security updates from the vendor. Under Cyber Essentials v3.3, unsupported software in scope is an automatic fail; must be removed, replaced, or isolated before submission.
User Access Control
A Cyber Essentials control governing approved individual access, appropriate privileges, separate administrative use and removal of access no longer needed. Apply MFA wherever available and to cloud authentication. Review third-party accounts and actual authentication paths as well as staff accounts; do not equate a list of registered users with effective enforcement.
Vulnerability Scanning
The automated process of identifying known security weaknesses in systems, applications, and network infrastructure. Continuous scanning, as opposed to periodic scans, provides ongoing visibility into an organisation's attack surface.
Windows Hello for Business
Microsoft’s device-bound passwordless authentication using a biometric or PIN to unlock a credential. Verify the actual deployment and authentication path against Cyber Essentials requirements. Using Intune is neither a universal prerequisite nor proof that every cloud authentication path enforces the required MFA.
Zero Trust
A security architecture that removes inherent trust based on network location and authorises each resource request against a policy. For example, access to a finance application can use user identity, device health and least-privilege role before allowing a transaction. It guides design and monitoring; Cyber Essentials does not require an organisation to buy a “Zero Trust” product or obtain a separate Zero Trust certificate.
Zero-Day
A software vulnerability unknown to the vendor at the time of exploitation, or for which no patch is yet available. Under Cyber Essentials v3.3, zero-day exposure is addressed through compensating controls (EDR, network segregation) while a patch is awaited.
Explore the tools behind the terms
See how Fig brings asset visibility, risk management, security testing and compliance workflows together.