Status: working towards Cyber Essentials. Viewee is not claiming certification.
What the certification requires
Cyber Essentials is the UK Government-recommended minimum cyber-security standard. The NCSC scheme covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Certification uses a verified self-assessment of the organisation's in-scope IT.
Evidence and controls we need
Defined assessment scope covering cloud services, endpoints, networking, user accounts and internet-facing systems.
Asset, software and cloud-service inventory with owners and supported versions.
Firewall and cloud security-group rules, including default-deny rationale and review records.
Secure configuration baselines, removal of unused accounts/services and controlled admin access.
Patch policy and evidence that high-risk fixes are applied within the scheme's required window.
Joiner, mover and leaver process; least privilege; separate admin accounts; MFA where required.
Malware protection and application allow-listing or equivalent controls for in-scope devices.
Completed current IASME question set with evidence retained for each answer.
Current gap status
Direction exists for managed identity/MFA, separate environments, security scans, UK/EU processing, infrastructure as code and telemetry.
No complete in-scope asset inventory, device baseline, firewall evidence, patch evidence or access-review pack is recorded yet.
Cloud and hosting vendors are not selected, so final scope and inherited controls are still open.
No Cyber Essentials assessment has been completed.
Next steps
Name an owner and define the certification scope.
Build the asset/software/cloud inventory and map each item to the five controls.
Choose vendors only after security, residency, processor, backup and restore checks.
Close control gaps and collect screenshots, exports, policies and review logs.
Run a dry self-assessment using the current IASME question set, remediate gaps, then apply through an accredited certification body.
Official sources
Deeper review additions - 16 September 2026
Scope details to close
- End-user devices cannot be left out. Include both founders' work laptops and any BYOD that accesses Viewee data or cloud services.
- Include every cloud service used for the business, including Google Workspace, source control, hosting, monitoring, outreach tooling and supplier/support accounts owned by Viewee.
- For each cloud control performed by a provider, retain the contract, security statement or trust-centre evidence that commits the provider to it.
Control details to evidence
- Firewall rules must default-block unauthenticated inbound connections. Every allowed inbound rule needs approval, a documented business need and removal when no longer needed.
- Device unlock must resist brute-force attacks; configure throttling or locking after no more than 10 failed attempts where possible, with unlock PIN/password length of at least six characters.
- All in-scope software must be licensed and supported. Enable automatic updates where possible and install critical/high, CVSS v3 7+, or unclassified security fixes within 14 days.
- Cloud authentication must always use MFA where available. Use separate admin-only accounts and disable accounts or elevated access when no longer required.
- Where passwords remain, use MFA, or 12+ characters, or 8+ characters with a common-password deny-list; do not impose routine expiry and provide secure password storage.
- Record active malware protection for every device using configured anti-malware, application allow-listing or an applicable sandboxed app-store model.
Working source
The detailed tracker is in "Cyber Essentials - Requirements" in the Legal folder. It uses the NCSC Requirements for IT Infrastructure v3.3 (April 2026) and the current IASME self-assessment source. Viewee remains working towards certification.
