Home/Blog/Insights
Insights

What Cyber Essentials Certification Actually Requires

Stack46 became Cyber Essentials certified before it took on a single piece of external client work. Here's what the five control areas and the IASME assessment actually involved.

Dinesh Koyyalamudi
Dinesh Koyyalamudi30 Aug 2026 6 min read
FourSix46® brand-color placeholder image — final photo to be addedFourSix46® brand-color placeholder image — final photo to be added
Share Article

Stack46, our software development agency, is Cyber Essentials certified. That's a real, checkable fact — Cyber Essentials is a UK Government-backed scheme, assessed via IASME — and we got certified before Stack46 had taken on a single piece of external client work. I want to explain what that actually involved, because "Cyber Essentials certified" is one of those phrases that gets used a lot on company websites without much explanation of what sits behind it.

What Cyber Essentials actually is

Cyber Essentials isn't a general security audit, and it isn't a penetration test. It's a UK Government-backed certification scheme that checks whether an organisation has a specific, defined set of basic technical controls in place. It exists because a large proportion of successful cyberattacks exploit gaps that are genuinely basic — not sophisticated zero-days, but things like an unpatched system, an open port that shouldn't be open, or a default password nobody changed. The scheme is assessed by an accredited certification body — in our case, via IASME — rather than self-declared, so there's an actual external check involved, not just a form you fill in about yourself.

The certification covers five control areas, and this is where the real work is:

Firewalls and internet gateways. You have to demonstrate that boundary firewalls are correctly configured — not just present, but actually restricting traffic the way they should, on every device and network boundary that's in scope.

Secure configuration. Devices and software have to be configured to reduce vulnerabilities — removing or disabling functionality you don't need, changing default settings and default credentials, and generally not leaving systems in the state they arrived in out of the box.

Access control. Who has access to what, and why. This means user accounts are only given the access they actually need, administrative privileges are controlled and limited, and accounts are properly managed over their lifecycle rather than accumulating access indefinitely.

Malware protection. Having actual, active protection against malware across the devices in scope — not a policy document that says you should, but a real, running control.

Patch management. Software and firmware kept up to date, with security patches applied within the scheme's required timeframes, and unsupported or unpatched software not left running in the environment.

What it actually felt like to go through

The part that surprised me most wasn't any single control — most of them, individually, sound like common sense. It was how unforgiving the assessment is about the gap between what you assume is configured correctly and what's actually configured correctly. It's easy to believe your systems are locked down because you set them up carefully once. Going through the assessment meant actually verifying each of the five areas, rather than trusting memory or intent. A few things that I'd assumed were fine turned out to need tightening once I looked properly — which is, I think, the entire point of the exercise. The certification isn't there to confirm what you already believe. It's there to catch the difference between believed and verified.

Verified beats assumed, every single time.

Note 46

Why before the first client, not after

Stack46 got certified before it had any external client work at all. That ordering was deliberate. It would have been easy to treat certification as something to sort out once a client asked for it, or once a contract required it — plenty of agencies operate that way, scrambling to get certified reactively when a prospective client's procurement process demands it. I didn't want Stack46's security posture to be a response to a client's requirement. I wanted it to already be true, so that the answer to "are you Cyber Essentials certified" was simply "yes," rather than "we're working on it."

Stack46 also holds employers' liability and cyber liability insurance, for the same underlying reason — I'd rather have the operational and legal groundwork in place before it's tested by a real client relationship than find out what's missing under pressure.

What this actually buys you

Cyber Essentials doesn't make you unhackable — nothing does, and the scheme doesn't claim otherwise. What it does is give you a genuinely verified baseline: firewalls configured correctly, systems set up securely rather than left on defaults, access properly controlled, active malware protection, and patches applied on time. Those five things, done properly and checked externally, close off the overwhelming majority of the basic ways companies actually get compromised. For a software agency handling other people's systems and code, that baseline isn't optional groundwork — it's the minimum standard I'd want any agency to have before I trusted them with a client project of my own, so it's the minimum I hold Stack46 to before we ask anyone to trust us with theirs.

Dinesh Koyyalamudi, known as 46DC, is a London-based founder. He is the Founder of FourSix46® Global Ltd, a United Kingdom registered parent company (Company No. 16712658) building ventures across technology, systems, digital infrastructure and logistics — including Stack46, Cinevenn, 46 Dogs and Route46. Originally from India, he moved to the United Kingdom in 2022 and registered FourSix46® Global Ltd in September 2025. He writes and builds in public at 46dc.com and is @the46dc across all social platforms.

FourSix46® Global Ltd is a company registered in England and Wales. Company No. 16712658. Registered office: 66 Paul Street, London EC2A 4NA.

Was this article helpful?
Dinesh Koyyalamudi
Written By

Dinesh Koyyalamudi

Founder, FourSix46® Global Ltd

Founder of FourSix46® — a UK-based parent brand building scalable ventures across technology, systems, and digital infrastructure. Building in public, one venture at a time.