4. User access control and certification
The certification process
Getting certified starts with defining your scope, typically your whole organisation's IT, though it can be narrowed to a specific network or subset in some cases, as long as the scope is clearly documented and justified.
The steps
1. Complete the self-assessment questionnaire covering all five controls, honestly and in detail. 2. A qualified assessor from an IASME-accredited certification body reviews your answers. 3. If you meet the requirements, a certificate is issued, valid for twelve months. 4. You re-certify annually to keep the certificate current, since the threat landscape and your own IT environment both keep changing.
Once certified, you can use the Cyber Essentials badge in your marketing and tender responses, which is often the whole point commercially, but the real value is in actually having the five controls in place, not just the certificate itself.
Check your understanding
A short, optional 5-question quiz on this section. It doesn't block your progress, it's just a quick self-check.
Try the section quiz →› Course contents
What Cyber Essentials is
Firewalls and secure configuration
Security updates and malware protection
User access control and certification
Putting it into practice