Cyber Essentials Pack

Let us help you pass Cyber Essentials the first time

Cyber Essentials is as much a documentation exercise as a technical one, and that is where most first attempts stall. We give you every policy, register, and piece of evidence the IASME self-assessment asks for, written and ready to adapt, with a mapping that ties each document to the question it answers.

$200 One-time purchase · Every future update included Free sample · real documents · no email required Instant download · Editable Word, Excel & PowerPoint · Single-organization license
Cyber EssentialsNCSC Five ControlsIASME
Policies for all five technical controls
Working registers and evidence, not blank templates
A question-by-question mapping to the self-assessment

Cyber Essentials is a self-assessment. Passing it is a documentation exercise.

The questionnaire is short. The catch is that every "yes" has to be true and you have to be able to show it: a documented firewall standard, a secure-configuration baseline, evidence that updates get applied inside the deadline, accounts that follow least privilege. Most organizations stall not on the controls but on writing down the controls they already half-run.

This pack is that written layer. You answer the IASME self-assessment from a documented position instead of improvising, and you can show your working when a customer or insurer asks.

The five technical controls

What the assessment checks, and the documents in the pack that cover each one.

1
Firewalls and network security
A Firewall and Network Security Policy with a Firewall Rule Review Form to evidence boundary and host firewall configuration over time.
2
Secure configuration
A Secure Configuration Standard for hardened builds across laptops, servers, and mobile, with defaults changed and unnecessary services removed.
3
Security update management
A Patch and Vulnerability Management Policy and Vulnerability Management Procedure with defined timeframes and the records that show updates land on time.
4
User access control
User Access Control and Authentication and Password policies with a joiners, movers, and leavers process, covering least privilege, MFA, and admin separation.
5
Malware protection
A Malware Protection Policy that maps endpoint protection settings directly to what the question set asks you to confirm.

The governance behind the answers

A credible "yes" assumes a program around those controls. The pack carries the policies, registers, and plans that program needs.

Information Security Policy
The apex policy the whole set hangs from, with a Roles and Responsibilities document so ownership is explicit.
Access, devices, and remote work
Acceptable Use, Mobile Device and BYOD, and Home and Remote Working policies, the surface a quick self-assessment glosses over.
Assets and data
An Asset Management Policy with a working Asset Inventory, Data Classification and Handling, and a Retention Schedule.
Incident response and continuity
Incident Response Policy and Plan, a Disaster Recovery Plan, and a Business Continuity Policy, written before you need them.
Suppliers and people
A Supplier Security Policy with a ready questionnaire, plus HR Security and Security Awareness and Training.
Risk and registers
A scored Risk Register, with Privileged Access, System Owners, and Legal and Regulatory Obligations registers.

From documents to a submission you can defend

The pack is built to move you through the assessment in order, then keep you certified.

Step 1 · Map

The Self-Assessment Question Mapping ties each document to the IASME question it answers.

Step 2 · Check

The Readiness Checklist walks the current question set so you find gaps before the assessor does.

Step 3 · Prove

The Implementation Guide and Evidence Pack help you apply each control and assemble what you submit.

Step 4 · Maintain

A Maintenance Calendar and Compliance Matrix make next year's recertification a review, not a rebuild.

What this looks like in practice

A customer contract requires Cyber Essentials

You complete the self-assessment from documented controls and answer the procurement questionnaire the same week, instead of stalling for a fortnight.

An insurer asks how you manage security

You point to the risk register, access controls, and patching records that already exist, rather than writing them under deadline.

You are re-certifying next year

You reopen the same pack, check the maintenance calendar, and refresh the evidence, instead of starting over.

Walk into the self-assessment already able to answer it.

Editable Word and Excel · Worked examples, not placeholders · Buy once, and we send you every future update

What you are actually getting

Every policy is content you can adopt and edit, not a skeleton with "insert text here." The Excel registers and trackers open with sample rows, scoring, and the columns an assessor expects to see. You can read a complete answer before you adapt it to your own organization.

Certification itself is carried out by an IASME-appointed certification body and is not included. This pack gets you ready to pass it the first time.

Who it's for

Organizations going for Cyber Essentials for the first time, anyone re-certifying who would rather not rebuild the evidence every year, and consultants or MSPs who need a consistent, editable baseline to deploy across clients. No prior certification experience is assumed. Every document is written to be read, edited, and used.

Going for the audited tier? The Cyber Essentials Plus Pack is this full set plus the runbooks and evidence for the hands-on assessment.

See inside

Real pages from the documents

A free sample from the Cyber Essentials Pack. No email required, open it and judge the quality for yourself.

Sample page from the Cyber Essentials PackSample page from the Cyber Essentials PackSample page from the Cyber Essentials Pack

Open the full sample

What is inside

Every document in the pack

60 documents, mapped to Cyber Essentials (five technical controls). Buy once, and every future update is included.

Start Here · 5 documents
Cyber Essentials Documentation Pack User GuideWord
Cyber Essentials Implementation GuideWord
Cyber Essentials Requirements SummaryWord
Cyber Essentials Scope DefinitionWord
Your RidgeGuard LicenceWord
Information Security Policy · 1 document
Information Security PolicyWord
Technical Control Policies · 13 documents
Authentication and Password PolicyWord
Cloud Security PolicyWord
Cryptography PolicyWord
Electronic Messaging PolicyWord
Firewall and Network Security PolicyWord
Logging and Monitoring PolicyWord
Malware Protection PolicyWord
Mobile Device and BYOD PolicyWord
Patch and Vulnerability Management PolicyWord
Secure Configuration StandardWord
User Access Control PolicyWord
User Access Management Process JMLWord
Vulnerability Management ProcedureWord
Organisational Policies · 15 documents
AI Security PolicyWord
Acceptable Use PolicyWord
Asset Management PolicyWord
Backup PolicyWord
Business Continuity PolicyWord
Change Management PolicyWord
Data Classification and Handling PolicyWord
Home and Remote Working PolicyWord
Human Resources Security PolicyWord
Incident Response PolicyWord
Information Security Roles and ResponsibilitiesWord
Physical and Environmental Security PolicyWord
Privacy and Personal Data Protection PolicyWord
Security Awareness and Training PolicyWord
Supplier Security PolicyWord
Registers and Plans · 8 documents
Asset InventoryExcel
Disaster Recovery PlanWord
Incident Response PlanWord
Legal and Regulatory Obligations RegisterExcel
Privileged Access RegisterExcel
Retention ScheduleExcel
Risk RegisterExcel
System Owners RegisterExcel
Implementation and Evidence · 9 documents
Certification Maintenance CalendarExcel
Compliance MatrixExcel
Control Implementation TrackerExcel
Cyber Essentials Evidence Compilation GuideWord
Cyber Essentials Readiness ChecklistExcel
Evidence PackExcel
Pack Version HistoryExcel
Project Plan and TimelineExcel
Self Assessment Question MappingExcel
Forms and Logs · 5 documents
Backup Testing LogExcel
Change LogExcel
Firewall Rule Review FormExcel
Supplier Security QuestionnaireExcel
Training Records and AcknowledgementExcel
Awareness Materials · 4 documents
Example Network DiagramPDF
Poster Spot a Phishing EmailPDF
Poster Strong Passwords and MFAPDF
Security Awareness TrainingPowerPoint

Want to see the quality behind the titles? Preview a sample document →

Document Customization

Need this customized to your organization?

Complete an intake form. We customize every document: industry context, regulatory mapping, calibrated parameters. Delivered in 7-10 business days.

Learn More →

Need the skills to operate the program? Our training platform builds the capability. Explore courses →

Ready to strengthen your security program?

Get started with professional, audit-ready documentation today.

Cyber Essentials Pack $200 Preview Buy Now