IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
C31-R1 development candidate · acceptance pending

Cyber Essentials v3.3

Five technical control themes plus assessment scope, with distinct evidence review actions.

Professional and MSP preparation

Distinct descriptions, evidence actions, templates, scoped programs, evidence readiness and exports. Free retains ISO assessment scope and shared design.

Source and limits

v3.3 / April 2026. Preparation only; certification and Cyber Essentials Plus testing require the scheme assessment process. Local objective identifiers are ITAF-authored. Contains public sector information from the UK National Cyber Security Centre, licensed under the Open Government Licence v3.0: https://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/. Text reformatted; ITAF review identifiers, evidence actions and supporting mappings added. No NCSC endorsement.

Existing collectors supply supporting customer-side observations. Full Cyber Essentials scope, alternatives, time limits and cloud-provider assurance require independent review. No new collector or automatic certification is claimed.

Official source

C28 is the user-confirmed working baseline. C31-R1 installation and upgrade acceptance is pending. Website patch prepared, not deployed.