WebinarShufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle25th Sep | 02:00 PM UTCREGISTER NOW Shufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle25th Sep | 02:00 PM UTCREGISTER NOW How AMLR Extends KYC Across the LifecycleRegister Gavel on AMLR rule bookAMLR applies 10 July 2027. See your stack against every obligationBook a Demo AMLR applies 10 July 2027. See your stack against every obligationBook A Demo AMLR applies 10 July 2027 — see your stackBook Demo Globe with pKYC, Onboarding, Screening and Transactions labelsShufti’s Glocal PlatformGlobal Coverage. Local Depth. Full Compliance Lifecycle.Explore More Global Coverage. Local Depth. Full Compliance Lifecycle.Explore More Glocal Platform — Global Coverage. Local Depth.Explore Shufti x ACFEWebinarAI has changed fraud. Now we need to change how we fight it.Microphone icon for Shufti and ACFE fraud webinar5th October, 2026Register Now Shufti x ACFEAI has changed fraud. Now we need to change how we fight it.5th October, 2026Register Now AI has changed fraud — change how we fight itRegister INNOVATION DROPSUMMER
EDITION
20
26
Qualified Electronic Signature
WATCH NOW
INNOVATION DROP - Qualified Electronic SignatureWatch Now Innovation Drop — Qualified Electronic SignatureWatch
INNOVATION DROPSUMMER
EDITION
20
26
Transaction Trust Monitoring
WATCH NOW
INNOVATION DROP - Transaction Trust MonitoringWatch Now Innovation Drop — Transaction Trust MonitoringWatch
INNOVATION DROPSUMMER
EDITION
20
26
Travel Rule Compliance
WATCH NOW
INNOVATION DROP - Travel Rule ComplianceWatch Now Innovation Drop — Travel Rule ComplianceWatch
Gavel on AMLR rule bookAMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027 — Find the GapsConsult Bank card and cashBank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification — Secure PayoutsSee How Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance — Verified Location, Verified IdentityBook Demo Journey Builder dot gridConfigure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Configure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Journey Builder — Configure Verification FlowsSee How Shufti MCP toggle with ChatGPT and ClaudeShufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP — Verification Tools Inside Claude or ChatGPTExplore

us

136.69.224.248

CYBER ESSENTIALS / CYBER ESSENTIALS PLUS

Certified Across Both Cyber Essentials Tiers

Shufti holds Cyber Essentials and Cyber Essentials Plus, including independent technical testing against the UK government-backed cybersecurity scheme. This gives procurement and security teams clear assurance when assessing Shufti’s controls.

Cyber Essentials certification badge

Certification Overview

What Cyber Essentials Covers

Cyber Essentials (Self-Assessed)

Five control categories documented and attested by the organisation: boundary firewalls and internet gateways, secure configuration of devices and software, user access controls, malware protection, and patch management. Confirms the baseline controls are in place and documented. Shufti holds this tier.

Cyber Essentials Plus (Independently Tested)

The same five control categories, tested hands-on by an IASME Consortium-accredited certifying body: external vulnerability scans of public-facing systems, internal network testing, and device configuration review against the live production environment. If gaps were found, the certification would not be issued. Shufti holds Plus, your procurement team does not need to take our word for it.

Why It Matters

Cyber Essentials Plus is the government-recognised baseline that reduces the scope of your vendor security questionnaire on the five covered control domains. It is mandatory for UK central government contracts involving personal data. If you are procuring Shufti under a UK government framework, or require your supply chain to hold Cyber Essentials Plus, we meet that requirement at the independently tested tier.

Holding both tiers demonstrates continuity

We did not simply acquire Plus without the documented baseline that underpins it. The five control domains are evidenced at both self-assessed and independently tested levels, giving your InfoSec team a complete picture.

NCSC-backed UK government scheme

Mandatory for central government contracts involving personal data. Both tiers held, with Plus independently verified by an accredited assessor.

Certification Assurance

Independently Verified Compliance Standards

Standard

Cyber Essentials and Cyber Essentials Plus, both current under the NCSC-backed scheme.

Assessed By

IASME Consortium-accredited certifying body, with Plus-tier hands-on testing by an accredited assessor.

Scope

IASME Consortium-accredited certifying body, with Plus-tier hands-on testing by an accredited assessor.

Documentation

Certificates available on request, usable for UK procurement submissions and renewed annually.

How Shufti Maintains It

Shufti Cyber Essentials Plus assessment is conducted annually by an IASME Consortium-accredited certifying body. The assessment tests the live production environment, not a prepared test build. Between cycles, we maintain the same patch management cadence, access control procedures, and firewall configurations that the assessment validated.

Both certificates are available on request and can be included directly in UK procurement submissions. Certificate numbers are verifiable on the IASME certificate checker.