Recent Breaches
Breaches
View All →
Cyber Essentials

Exceed UK Baseline Certification with Physical Isolation Evidence

Cyber Essentials establishes baseline security requirements for UK organisations. Firevault Control provides physical measures that demonstrably exceed baseline requirements, providing stronger evidence for Cyber Essentials Plus certification and supply chain assurance.

Back to Control
Control

Cyber Essentials

Cyber Essentials certification demonstrates baseline security hygiene. Physical enforcement demonstrates that those baselines are continuously maintained and cannot be accidentally undermined.

5/5

Technical controls with physical enforcement

100%

Boundary firewall requirements exceeded

CE+

Cyber Essentials Plus evidence strengthened

Full

Continuous certification evidence

The Certification Gap

Baseline certification is necessary but not sufficient.

Baseline vs Reality

Cyber Essentials certifies baseline controls at a point in time. Between assessments, control effectiveness can degrade through configuration drift and human error.

Boundary Device Limitations

Cyber Essentials requires boundary firewalls, but firewalls can be misconfigured, bypassed, or compromised, undermining the boundary they are meant to protect.

Supply Chain Requirements

Government and enterprise contracts increasingly require Cyber Essentials Plus. Stronger evidence differentiates organisations competing for these contracts.

The Scenario

Scenario: Supply Chain Tender with Physical Evidence

A government department evaluates three suppliers for a sensitive contract. All three hold Cyber Essentials Plus certification. However, the department's security assessment reveals that two suppliers rely entirely on software-based boundary controls that have experienced configuration incidents in the past year. The third supplier presents physical boundary enforcement evidence from Firevault Control, showing continuous, unbroken boundary protection with tamper-proof logs. The department selects the supplier with physical enforcement, noting that physical boundaries provide a higher assurance level for the sensitivity of the contract.

"All our competitors had Cyber Essentials Plus. What differentiated us was the ability to show physical boundary enforcement with continuous evidence. For the government buyer, physical controls meant genuine assurance, not just a certificate."

Cyber Essentials mapping

Where Cyber Essentials controls meet Control modules.

Cyber Essentials and Cyber Essentials Plus prescribe five technical control themes. Firevault Control hardens those themes with physical enforcement where logical configuration alone would not hold.

Reference: NCSC Cyber Essentials Requirements for IT Infrastructure v3.2 (April 2025).

SEC 01

Firewalls and boundary protection

  • CE 1

    Boundary firewalls

    The boundary is physical, not a configurable rule. Severed by default.

    FirebreakIsolate
SEC 02

Secure configuration

  • CE 2

    Secure configuration

    Configurations and golden images sit in tamper-evident offline storage.

    ArchiveValidate
SEC 03

User access control

  • CE 3

    User access control

    Reach is named, scoped and time-bound, with revocation at the boundary.

    LockUnlinkRelay
SEC 04

Malware protection

  • CE 4

    Malware protection

    Removable media and inbound paths are governed Transfer events with validation.

    TransferValidate
SEC 05

Security update management

  • CE 5

    Security update management

    Updates apply through named, time-bound Relay sessions with multi-party approval.

    RelayExecute

Modules & symbols

FirebreakPhysical sever
IsolateZone boundary
ArchiveDisconnected copy
ValidateIntegrity check
LockNamed access
UnlinkRemove trust
RelayTime-bound path
TransferControlled move
ExecuteApproved action
Direct mapModule satisfies clause

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Physical Boundary Protection

Physical network boundaries exceed Cyber Essentials boundary firewall requirements, providing demonstrable protection that cannot be misconfigured.

Governed Access Control

Multi-party authorisation provides access control evidence that exceeds baseline requirements and demonstrates active governance.

Continuous Evidence

Automated logging generates continuous compliance evidence, strengthening your position for Cyber Essentials Plus assessment and renewals.

Secure Configuration Support

Physical zone separation ensures secure configuration requirements are maintained regardless of individual system configuration states.

Assessment-Ready Logs

Tamper-proof logs provide complete audit trails ready for Cyber Essentials Plus technical verification.

Clean Recovery Capability

Verified control-plane baselines ensure clean system restoration, supporting malware protection requirements with guaranteed uncompromised recovery.

Demo to Live

Adoption Guide

Step 1

Baseline Assessment

Review your current Cyber Essentials controls and identify where physical enforcement provides the greatest assurance improvement.

Step 2

Physical Boundary Design

Design physical boundary enforcement for your network perimeter and internal zone boundaries aligned to your Cyber Essentials scope.

Step 3

Pre-Assessment Deployment

Deploy Control before your next Cyber Essentials Plus assessment to generate continuous evidence and validate physical boundary effectiveness.

Step 4

Full Boundary Enforcement

Organisation-wide physical boundary enforcement with continuous evidence generation and verified control-plane baseline restoration.

Step 1

Baseline Assessment

Review your current Cyber Essentials controls and identify where physical enforcement provides the greatest assurance improvement.

Step 2

Physical Boundary Design

Design physical boundary enforcement for your network perimeter and internal zone boundaries aligned to your Cyber Essentials scope.

Step 3

Pre-Assessment Deployment

Deploy Control before your next Cyber Essentials Plus assessment to generate continuous evidence and validate physical boundary effectiveness.

Step 4

Full Boundary Enforcement

Organisation-wide physical boundary enforcement with continuous evidence generation and verified control-plane baseline restoration.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Cyber Essentials

    How Firevault Control supports Cyber Essentials certification requirements.

    © 2026 Firevault Limited. Disconnect to Protect®