We’ve achieved Cyber Essentials Plus: what it means for your organisation

graphic with cyber essentials plus icon

This August, Geoxphere and Local Authority Tech CIC have been certified to Cyber Essentials Plus, the UK government’s audited standard for cyber security fundamentals. It covers our whole organisation: every company laptop and mobile device, and the cloud infrastructure we operate to deliver our services.

We were assessed under the latest question set (named Danzell) and version 3.3 of the Cyber Essentials requirements.

As we’re now trusted by thousands of public sector organisations, serve critical GOV.UK estate, and provide mapping systems to all tiers of government, we felt it was right to set ourselves a higher bar for the long-term.

If your organisation is looking at your own cyber security, a good place to start is the Government Cyber Action Plan.

What Cyber Essentials Plus is

Cyber Essentials is owned by the National Cyber Security Centre and delivered through IASME. It sets a baseline across five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection.

There are two tiers, and the difference matters:

  • Standard Cyber Essentials is a verified self-assessment. An organisation answers a structured question set and a certification body reviews the answers.
  • Cyber Essentials Plus adds an independent technical audit. An assessor tests our actual devices, configurations and patch levels rather than taking our word for it. Both tiers require annual recertification.

We hold the audited tier.

Why ‘scope’ of a certificate matters

When looking at companies that have Cyber Essentials, the real differentiator is the scope (essentially what’s included in the audit).

A certificate can legitimately cover a single office, one product line, or a subset of an organisation’s devices. Two suppliers can both wave a Cyber Essentials Plus certificate at you while one has certified their entire estate and the other has certified a single laptop.

Ours covers:

  • All company-issued laptops and mobile devices, and the accounts and cloud services our staff use to do their work
  • The cloud infrastructure we operate to run XMAP and Parish Online, including the systems that hold council data
  • Both legal entities: Geoxphere and Local Authority Tech CIC

So, we’ve not taken any shortcuts with this.

When you next assess any supplier, including us, ask to see the stated scope rather than just the certificate. It is a fair question and a good supplier will answer it plainly.

Having a strong supply chain

An organisation’s supply chain is also important to assess. Hosting for our Parish Online Websites runs on infrastructure operated by our specialist hosting partner rather than on our own. That infrastructure sits outside our Cyber Essentials Plus scope because it is not ours to certify. However, they are certified to ISO 27001, an information security management standard broader in scope than Cyber Essentials, and we hold a data processing agreement with them covering the services they provide.

Why we did Cyber Essentials Plus

Councils are custodians of resident data, and our commercial customers operate critical workflows on our software, and where we hold some of that data on your behalf, the assurance burden is shared. Local government has been a repeated target for ransomware and supply chain attacks, and suppliers are a well-documented route in.

Many of the councils we work with are town, parish and community councils and rarely have the capacity to run a detailed supplier security assessment, and shouldn’t have to. We would rather do the work, submit to an independent audit, and hand over the evidence.

The 2026 audit

The Cyber Essentials scheme is reviewed annually by the NCSC and IASME. In April 2026 there was a substantial revision, and it made certification much harder.

The changes introduced stricter marking on the practices that matter most, including multi-factor authentication and applying security updates promptly across the whole scope, with automatic failure for some of them. Scoping rules were tightened, the definition of a cloud service was revised, and the emphasis shifted towards demonstrating that controls are genuinely in place rather than merely documented.

On the audited tier, IASME had found cases of organisations applying updates selectively around the time of assessment, and the testing process was tightened in response, with more emphasis on representative sampling.

In short: a certificate issued under the current rules says more than one issued under the old ones.

What this means for you

  • It supports your data protection position. Under Article 28 of the UK GDPR, a council acting as controller must use processors who provide sufficient guarantees of appropriate technical and organisational measures. Independent certification is straightforward evidence of that, and it is easier to record than a supplier’s own assurances.
  • It saves you paperwork. If your internal audit, annual governance review or procurement process asks how you assure your suppliers, you can point at the certificate and its scope instead of issuing a questionnaire.
  • It feeds your risk register. If you maintain a data protection impact assessment covering our services, this is a documented control to reference.
  • It meets procurement requirements. Cyber Essentials is a common condition in public sector procurement, and the audited tier is increasingly asked for on contracts involving personal data.

We will always link to our latest certificate here; www.geoxphere.com/cyberessentialscertification

Limitations

There’s often confusion about Cyber Essentials, so to clarify:

  • It isn’t ISO 27001. Cyber Essentials Plus certifies a baseline of technical hygiene, audited properly. It is not a full information security management system.
  • It’s a point-in-time audit. It evidences the state of our systems when they were tested. However, it’s in our interest to keep up our standards as it’ll make recertification straightforward each year.
  • It covers us, not you. The certification says nothing about your organisation’s own devices and accounts. In practice, most incidents start with a compromised user account or an unpatched laptop, so it’s important to keep up your own security regime with turning on automatic updates, MFA and using password managers is a good start.

What’s next

The NCSC publishes free guidance and a Cyber Essentials readiness tool, and three things will get you a long way: turn on multi-factor authentication for email and any system holding resident data, let devices install security updates automatically, and make sure no one is sharing a login.

Small public sector bodies may not do Cyber Essentials themselves, but the Government Cyber Unit (the artist formerly known as Government Digital Service and CDDO) have Government Cyber Action Plan information to support you.

If you have questions about how we handle your data, or you need our certificate and scope statement for your own records, contact support@geoxphere.com or support@parish-online.co.uk.