How Cyber Essentials Maps to NCSC 10 Steps to Cyber Security
Published 3 June 2026
Why the two frameworks fit together
NCSC's 10 Steps is strategic – it tells you the ten areas every UK organisation should be thinking about, from risk management through to incident response. Cyber Essentials is operational – it specifies five technical controls you must implement and evidence to earn a certificate.
They're complementary. The 10 Steps gives leadership a complete view of what good looks like. Cyber Essentials gives you a measurable, certifiable subset that procurement teams and insurers actually ask for.
The mapping at a glance
NCSC Step 1 – Risk management
Not directly required by Cyber Essentials. Picked up in Cyber Assurance Level 1 and 2, where a risk register is mandatory. See our risk register guide.
NCSC Step 2 – Engagement and training
Lightly required by Cyber Essentials (you must be able to show users understand basic security responsibilities). Cyber Assurance treats it as a full theme.
NCSC Step 3 – Asset management
Implicit in Cyber Essentials – you need a current inventory of in-scope devices to answer the question set honestly. The strongest single overlap.
NCSC Step 4 – Architecture and configuration
Directly mapped to the Cyber Essentials "secure configuration" control. Default passwords changed, unused services removed, auto-lock enforced.
NCSC Step 5 – Vulnerability management
Directly mapped to Cyber Essentials "security update management" – the 14-day patching rule for high and critical vulnerabilities.
NCSC Step 6 – Identity and access management
Directly mapped to Cyber Essentials "user access control" – account inventory, leavers process, admin separation, and MFA on cloud accounts under the Danzell question set.
NCSC Step 7 – Data security
Partial. Cyber Essentials covers the device controls that protect data at rest on laptops; broader data classification and DLP sit in Cyber Assurance and ISO 27001.
NCSC Step 8 – Logging and monitoring
Not required for Cyber Essentials. A common gap among UK SMEs that achieve CE but haven't yet stood up logging.
NCSC Step 9 – Incident management
Not required for Cyber Essentials. Required for Cyber Assurance and ISO 27001. Worth having anyway – it's the difference between a bad day and a bad quarter.
NCSC Step 10 – Supply chain security
Indirectly supported – when you require Cyber Essentials of your suppliers (which large customers and the public sector increasingly do), you're operationalising this step.
What this means in practice
Cyber Essentials is the technical floor: five controls, strongly enforced. NCSC 10 Steps is the strategic ceiling: ten areas of capability. A small UK business can usually achieve full Cyber Essentials inside a month and use it as a stepping-stone to gradually build out the other 10 Steps. Larger organisations should treat the 10 Steps as the planning frame and Cyber Essentials Plus as the testable evidence.
Where to take it next
If you've achieved Cyber Essentials and want to demonstrate the wider 10 Steps coverage, Cyber Assurance is usually the next stop – its 14 themes cover most of what 10 Steps describes, without ISO 27001's overhead. For the technical baseline first, see our Cyber Essentials page.
