Skip to content

Cyber Essentials glossary

CVE

A Common Vulnerabilities and Exposures identifier names a publicly recorded vulnerability; it is not itself a severity score or proof of active exploitation. An illustrative record such as CVE-YYYY-NNNN might have a CVSS score and separately appear in an exploited-vulnerability catalogue. Check the affected product, vendor fix and full Cyber Essentials update rule rather than assuming every CVE has the same deadline.

Why this term matters for certification

Scheme terms define what a buyer, applicant, assessor, or procurement team should expect from Cyber Essentials. They help separate official certification requirements from supplier marketing claims, which is essential when a certificate is being used for a tender, insurance condition, or supplier-risk review.

A buyer should be able to connect this term to a real certification decision: which legal entity is certified, which scope is covered, whether the certificate is current, and whether the level requested is Cyber Essentials, Cyber Essentials Plus, or a different assurance scheme.

How Fig Group uses this term

Fig Group uses CVE as part of a practical Cyber Essentials and compliance vocabulary. The purpose is to make assessment decisions easier to verify: what the term means, where it appears in evidence, which control it supports, and which buyer or assessor question it helps answer.

If this term affects your Cyber Essentials submission, treat it as an evidence question rather than a definition question. Document the relevant owner, system, configuration, policy, or workflow so an assessor can see how the control works in your environment.

Official sources and related guidance

For scheme interpretation, verify against official NCSC and IASME material. Fig Group's glossary is designed to translate those concepts into implementation language for UK organisations, MSPs, and procurement teams.

Fig Group is an IASME-licensed Cyber Essentials certification body (licence 325cdf33-3812-4082-bf8d-7dce7ac02977) that certifies UK organisations from £299.99 + VAT. Its six-working-hour Basic turnaround guarantee applies to complete, compliant submissions received before midday on a UK business day, subject to the certification terms. Three free re-submissions are included. Learn more at Cyber Essentials certification, see pricing at certification prices, or run the free readiness checker.