CYBER ESSENTIALS / CYBER ESSENTIALS PLUS
Certified Across Both Cyber Essentials Tiers
Shufti holds Cyber Essentials and Cyber Essentials Plus, including independent technical testing against the UK government-backed cybersecurity scheme. This gives procurement and security teams clear assurance when assessing Shufti’s controls.
Certification Overview
What Cyber Essentials Covers
Cyber Essentials (Self-Assessed)
Five control categories documented and attested by the organisation: boundary firewalls and internet gateways, secure configuration of devices and software, user access controls, malware protection, and patch management. Confirms the baseline controls are in place and documented. Shufti holds this tier.
Cyber Essentials Plus (Independently Tested)
The same five control categories, tested hands-on by an IASME Consortium-accredited certifying body: external vulnerability scans of public-facing systems, internal network testing, and device configuration review against the live production environment. If gaps were found, the certification would not be issued. Shufti holds Plus, your procurement team does not need to take our word for it.
Why It Matters
Cyber Essentials Plus is the government-recognised baseline that reduces the scope of your vendor security questionnaire on the five covered control domains. It is mandatory for UK central government contracts involving personal data. If you are procuring Shufti under a UK government framework, or require your supply chain to hold Cyber Essentials Plus, we meet that requirement at the independently tested tier.
Holding both tiers demonstrates continuity
We did not simply acquire Plus without the documented baseline that underpins it. The five control domains are evidenced at both self-assessed and independently tested levels, giving your InfoSec team a complete picture.
NCSC-backed UK government scheme
Mandatory for central government contracts involving personal data. Both tiers held, with Plus independently verified by an accredited assessor.
Certification Assurance
Independently Verified Compliance Standards
Standard
Cyber Essentials and Cyber Essentials Plus, both current under the NCSC-backed scheme.
Assessed By
IASME Consortium-accredited certifying body, with Plus-tier hands-on testing by an accredited assessor.
Scope
IASME Consortium-accredited certifying body, with Plus-tier hands-on testing by an accredited assessor.
Documentation
Certificates available on request, usable for UK procurement submissions and renewed annually.
How Shufti Maintains It

Shufti Cyber Essentials Plus assessment is conducted annually by an IASME Consortium-accredited certifying body. The assessment tests the live production environment, not a prepared test build. Between cycles, we maintain the same patch management cadence, access control procedures, and firewall configurations that the assessment validated.

Both certificates are available on request and can be included directly in UK procurement submissions. Certificate numbers are verifiable on the IASME certificate checker.





