If you have ever filled in a supplier security questionnaire — or sent one — you will have seen the question: "Do you hold Cyber Essentials?" It is fast becoming the baseline for doing business in the UK, and for good reason.

Cyber Essentials, in plain English

Cyber Essentials is the UK government-backed certification scheme that checks an organisation has the fundamental protections in place: boundary firewalls, secure configuration, access control, malware protection and patching. It is the security equivalent of a gas safety certificate — not a promise of invulnerability, but evidence that the basics are genuinely done.

There are two levels, and the difference matters:

  • Cyber Essentials — a rigorous self-assessment, verified by a certification body.
  • Cyber Essentials Plus — the same controls, but independently audited: an assessor actually tests the systems rather than taking the organisation's word for it.

Why it matters when choosing a software partner

Your development partner sees your ideas, often your data, and sometimes your production systems. Their security posture becomes part of yours. When a supplier holds Cyber Essentials Plus, you inherit the assurance that an independent assessor has tested the controls protecting the machines your project passes through — and many public-sector and enterprise contracts now require it outright.

What the five controls mean for your project

The controls sound abstract until you translate them into what actually happens to your project while it is being built. Your requirements, designs, credentials and source code spend months on your partner's machines and in their accounts, so each control maps directly onto something you care about:

  • Firewalls and secure configuration mean the laptops and servers your code passes through are not sitting on the internet with the factory defaults still switched on.
  • Access control means only named people who need your project can reach it, and that access is removed when it is no longer needed, not left lingering for years.
  • Malware protection and patching mean the machines handling your intellectual property are kept up to date, closing known holes before anyone can use them against you.

In other words, certification is not really about the supplier's office network in the abstract; it is about the environment your ideas and data will live in for the duration of the engagement. That is true whether you are commissioning a new build or handing an existing system to an external team through software development outsourcing, where the partner's environment effectively becomes an extension of your own.

One practical detail worth knowing: Cyber Essentials certification is renewed annually, so ask to see a current certificate rather than a claim from years past. The question belongs early in the conversation, not at contract stage; asking on day one costs nothing and tells you a great deal about how seriously a supplier takes the basics. We have set out the wider set of questions worth putting to any supplier in our guide to vetting a software development partner.

What we hold

Assemblysoft holds Cyber Essentials at company level, achieved on 28 July 2026 for the whole organisation, and Cyber Essentials Plus, with the audited assessment carried out on 4 August 2026 by our certification body, Layer 7. Certificate numbers and the full detail — including how our Microsoft Azure hosting layer adds its own independently certified standards (ISO/IEC 27001, ISO/IEC 27017/27018, SOC 1/2/3 among them) — are on our Certifications, Standards & Regulatory Monitoring page.

Certification is the floor, not the ceiling

A certificate tells you the fundamentals are audited. It does not, by itself, tell you how a partner reviews code, manages suppliers or responds to incidents — which is why we publish those statements too, in one place: the Trust & Compliance Centre covers secure development, information security and access control and incident response in plain English.

If security assurance is the thing standing between you and starting a project, it is a conversation we genuinely enjoy having.

If you are weighing up a software partner and want the paperwork as well as the promises, our Trust & Compliance Centre has the statements ready to read — and we are happy to walk you through any of it. Start a conversation.