ECP vs Cyber Essentials (UK): CyFun vs the NCSC Baseline Scheme
Cyber Essentials is the UK government's baseline cybersecurity certification scheme: five technical controls, two levels (CE self-assessed and CE+ independently verified), expected on UK central government contracts that handle personal information under PPN 014, and owned by NCSC with IASME as delivery partner. Easy Cyber Protection is a CyFun audit-readiness platform for Belgian MSPs. Both operate in the cybersecurity compliance space, but for fundamentally different regulatory regimes. The UK left the EU, and NIS2 does not apply there. CE is a respected, brand-strong baseline; CyFun is Belgium's legally-grounded NIS2 path.
At a glance
| Cyber Essentials / CE+ (UK) | Easy Cyber Protection / CyFun | |
|---|---|---|
| Owning authority | NCSC: National Cyber Security Centre (UK government); IASME Consortium is delivery partner since 2020 | CCB: Centre pour la Cybersécurité Belgique (ECP implements CyFun) |
| Year established / last updated | 2014 (UK government launch); last scheme update April 26, 2026 (Danzell v3.3 question set) | CyFun 2025 (aligned with NIST CSF 2.0) |
| Legal status | Voluntary for most organisations; PPN 014 puts contracts handling personal information in scope, but leaves the requirement to the buyer contract by contract and rules out a blanket approach | Operational: Belgium's CCB-issued NIS2 compliance path; audits running |
| Entity coverage | Any organization; ~35,000 currently certified; 53,699 certificates issued Oct 2024 – Sep 2025; ~190,000 total to date | Belgian entities registered under NIS2 (CCB portal) |
| Structure | 5 technical controls: Firewalls, Secure configuration, Security update management, User access control, Malware protection, assessed at CE (self-assessment) or CE+ (independent technical audit) | 4 tiers: Small, Basic, Important, Essential, each with YAML-implemented controls across all NIS2 domains |
| Certification / assessment | CE: self-assessment questionnaire verified by IASME-authorized body; CE+: same controls + hands-on vulnerability scanning, phishing sim, config audit by certified assessor | CAB audit by accredited body; ECP generates signed .ecpbundle.zip audit bundle |
| Compliance cost | CE IASME fee: £320–£600 + VAT (by org size); CE total first-year: £1,500–£3,500 for SMEs; CE+ total: £1,500–£3,000 + VAT (assessor fee alone) | MSP charges client €100–400/month via ECP platform, absorbed into MSP service fee |
| MSP / portfolio model | No multi-tenant MSP portfolio track; each client needs its own certification; UK Cyber Security and Resilience Bill is estimated to bring 900 to 1,100 MSPs into direct regulatory scope | Purpose-built for MSP portfolio delivery: partner dashboard, white-label, per-client management |
| NIS2 / EU relationship | UK left the EU, so NIS2 does not apply; the UK Cyber Security and Resilience Bill (HL Bill 32 brought from the Commons 17 June 2026, still before the Lords, Royal Assent expected late 2026) is the UK's NIS2-equivalent and will expand scope to MSPs | CyFun is Belgium's official NIS2 implementation path; CCB-issued |
| Geography | UK (England, Scotland, Wales, Northern Ireland); recognized in Australia, Canada for supply-chain requirements | Belgium-first; Ireland co-adopting CyFun as of 2026 |
Sources: NCSC cyber.gov.uk, IASME iasme.co.uk, UK government PPN 014, SC Magazine UK certification statistics Oct 2024 – Sep 2025. Last verified 2026-08-18.
Where Cyber Essentials fits better
- You supply services or products to UK government bodies, where PPN 014 points buyers to CE/CE+ for contracts handling personal information, though each buyer decides contract by contract
- You serve UK commercial clients where CE is becoming expected by cyber insurance underwriters and larger enterprise buyers
- You want a recognised baseline aimed at the most common internet-based attacks, which is how NCSC itself describes the scheme
- Your clients are very small organizations (micro/SME) that need an achievable, structured starting point and want the included cyber liability insurance for UK orgs with turnover under £20M
- You need to align with UK-specific procurement and supply chain requirements (National Cyber Security Centre guidance, UK government frameworks)
Where ECP / CyFun fits better
- Your clients are Belgian (or Irish). CyFun is the CCB's official NIS2 compliance path, the one Belgian auditors and the CCB assess against
- You are a Belgian MSP and want to package CyFun audit-readiness as a repeatable service across your client portfolio, not a per-org certification project
- You need NL / FR / EN materials with Belgian regulatory context (CCB alignment, VLAIO kmo-portefeuille leverage for Flemish clients)
- You want predictable MSP economics: one fee per client per month, by the client's size in employees (Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request; partner rates on request), no monthly base
- Your clients need a CAB audit deliverable. ECP generates the signed .ecpbundle.zip that an accredited audit body accepts
The compliance cost comparison
This comparison is framework-vs-platform, not tool-vs-tool. Cyber Essentials is a UK government scheme. The cost is the certification work it requires. ECP is a platform that MSPs pay for and resell to clients. The numbers below illustrate what each path costs a typical Belgian SME via ECP versus a UK SME seeking Cyber Essentials Plus.
Cyber Essentials Plus: UK SME, 25 employees
- • IASME assessment fee: £400 + VAT (small org, 10–49 employees)
- • CE+ independent technical audit (vulnerability scan, phishing sim, config check): £1,500–£3,000 + VAT
- • Preparation and remediation work: 20–60 person-hours for first-time applicants
- • Annual recertification required, same cost each year
- • Cyber liability insurance included free for UK orgs with turnover < £20M (CE only)
- • Total estimated first-year cost for 25-person SME: £1,800–£3,500 (CE) or £2,500–£6,000 (CE+)
IASME fees are official 2026 rates. CE+ assessor fees are set by individual certification bodies and vary by system complexity. Total costs include remediation and internal time but exclude any ongoing consultant retainer. Source: IASME 2026 fee schedule; UK market pricing data from certification bodies.
ECP / CyFun: Belgian SME via MSP (20-client portfolio, Small avg)
- • One-time MSP onboarding: €400 (per partner, once)
- • Direct end-client price by employee count: Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request
- • A Small client (10–49 employees) costs €195 / month, €2,340 / year, no monthly base (at the monthly rate; longer terms are discounted)
- • Client's annual cost at Small: €2,340, vs £1,800–£6,000 CE/CE+ first-year cost
- • Partners buy below the published rate; the partner rate card is on request
Per-client fee by employee count: Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request. Partners buy below the published rate; the partner rate card is on request. No monthly base. One-time €400 MSP onboarding per partner. Every client gets the full feature set including AI and integrations from day one.
Framework coverage overlap
Cyber Essentials covers five technical security controls, a deliberately narrow, achievable baseline. CyFun is broader, covering the full NIS2 Article 21 domain set across four tiers. The five CE controls are present within CyFun (predominantly in Small and Basic tiers), so CyFun work builds CE readiness, but CE certification does not satisfy CyFun audit requirements.
| Control area | Cyber Essentials / CE+ (UK) | CyFun / ECP |
|---|---|---|
| Firewalls & network boundary | Control 1: Firewalls: boundary and host-based firewalls; rule review; CE+ includes live scanning | CyFun PR.AC + PR.PT controls; network segmentation evidence in ECP |
| Secure configuration | Control 2: Secure configuration: disable unnecessary software/ports, auto-lock, admin accounts; tightened in Danzell v3.3 | CyFun PR.IP controls in Basic and above; ECP hardening checklists |
| Security updates (patching) | Control 3: Security updates: Danzell mandates critical/high patches within 14 days (auto-fail if missed); unsupported software must be removed | CyFun PR.IP-12 / ID.RA; ECP patch register + integration with EDR/RMM |
| User access control | Control 4: User access control: least privilege, MFA for cloud services mandatory, an auto-fail since the November 2025 Requirements for Infrastructure update rather than a Danzell change | CyFun PR.AC controls; ECP access register + evidence collection |
| Malware protection | Control 5: Malware protection: up-to-date anti-malware or application allowlisting | CyFun PR.DS + DE.CM; ECP EDR integration (Sophos, Checkpoint) |
| Incident response | Not in scope: CE focuses on prevention, not response or recovery | CyFun DE.CM + RS controls; ECP incident log + CSIRT notification workflow |
| Supply chain / ecosystem | Not in scope: CE is per-organization, not supply chain | CyFun ID.SC; ECP vendor register template |
| Governance & risk | Not in scope: CE is technical controls only, no governance layer | CyFun GV + ID.RA; ECP wiki enforces policy ownership and evidence |
| NIS2 Article 21 compliance | Not applicable: UK left the EU; CE is not a NIS2 compliance path | Yes: CyFun is Belgium's implementation of Article 21; CCB-issued |
Sources: NCSC Cyber Essentials Technical Requirements (Danzell v3.3, April 2026); IASME iasme.co.uk; CCB CyFun 2025 documentation. Mapping is indicative. Actual gap analysis requires professional assessment.
Common questions
Does Cyber Essentials certification satisfy NIS2 in Belgium?
No. Cyber Essentials is a UK government scheme owned by NCSC. It is not part of the EU regulatory framework, and Belgium's NIS2 compliance path is CyFun, issued by the CCB. A Belgian entity audited by a Belgian CAB body is assessed against CyFun, not Cyber Essentials. The two frameworks overlap in some technical controls (patching, access control, malware protection) but are entirely separate legal regimes with different governance, certification bodies, and legal effects. Holding a CE certificate does not satisfy a CyFun audit, and vice versa.
Can ECP help UK clients comply with Cyber Essentials?
Not natively. ECP implements CyFun (Belgium's CCB framework). The underlying technical controls overlap (CE's five areas are present within CyFun Small and Basic), so ECP work builds readiness for the technical substance of CE. But ECP does not generate NCSC/IASME-formatted evidence, does not connect to IASME-authorized certification bodies, and does not produce the documentation format UK assessors require. A UK client using ECP as a compliance tool would get strong technical hygiene but would need a separate CE/CE+ assessment process for formal certification.
What is the UK Cyber Security and Resilience Bill and does it affect Belgian MSPs?
The UK Cyber Security and Resilience Bill was introduced to Parliament in November 2025 and reached the House of Lords as HL Bill 32 on 17 June 2026, where it still sat on 14 August 2026. It is the UK's domestic NIS2-equivalent, expanding the scope of the original UK NIS Regulations to include Managed Service Providers (the government policy statement estimates 900 to 1,100 UK MSPs) and data centre providers, with enhanced security duties and incident reporting requirements. Royal Assent is expected late 2026 with phased implementation to 2028. This Bill affects UK-based MSPs, not Belgian ones. Belgian MSPs are subject to EU NIS2 and CCB/CyFun, not the UK Bill.
Is Cyber Essentials widely recognised outside the UK?
CE has significant brand recognition in the UK market and is referenced in the procurement policies of some UK-headquartered multinationals. It is recognized in supply-chain contexts in Australia and Canada, where some organizations cite it alongside ISO 27001 as an accepted baseline. Within the EU, CE is not a recognized compliance path under NIS2. EU member states each have national frameworks (CyFun in Belgium, ReCyF in France, ENS in Spain, IT-Grundschutz in Germany) that are the assessed paths. If a Belgian company wins a UK government contract, CE may be required in addition to, not instead of, CyFun.
Deliver CyFun audit-readiness to your Belgian clients
If you are a Belgian MSP, CyFun, not Cyber Essentials, is the compliance path your clients need. ECP packages it as a monthly MSP service: guided workflows, evidence collection, white-label reports, and a signed audit bundle your CAB auditor accepts.
Related
Fact check
| Claim | Source | Accessed |
|---|---|---|
| Cyber Essentials launched 2014 by UK government; NCSC owns the scheme; IASME is delivery partner since 2020 | NCSC / Wikipedia: Cyber Essentials scheme history | 2026-07-27 |
| Five technical controls: Firewalls, Secure configuration, Security update management, User access control, Malware protection | NCSC Cyber Essentials Technical Requirements | 2026-08-18 |
| Danzell (v3.3) applies to assessment accounts created after 26 April 2026; accounts opened before that keep six months on the previous requirements. It designates two security-update questions as auto-fail (critical/high patches within 14 days). The MFA auto-fail predates it, from the November 2025 Requirements for Infrastructure update | IASME: Important Update: Changes to Cyber Essentials for April 2026 | 2026-08-18 |
| 53,699 certificates issued Oct 2024 – Sep 2025 (40,626 CE + 13,073 CE+); ~190,000 total to date; ~35,000 currently certified UK orgs | SC Magazine UK: Cyber Essentials Adoption Increases in 2025 | 2026-07-27 |
| PPN 014, in force 24 February 2025 and replacing PPN 09/14 and 09/23, puts contracts handling personal information in scope. It does not make certification automatic: "In-scope organisations must not take a blanket approach. Not all contracts will require suppliers to be certified under a Cyber Essentials Scheme." | UK Government Procurement Policy Note 014 | 2026-08-18 |
| IASME assessment fees: £320 + VAT (micro 0–9 emp), £440 + VAT (small 10–49), £500 + VAT (medium 50–249), £600 + VAT (large 250+) | IASME Cyber Essentials FAQ (IASME runs the scheme) | 2026-08-18 |
| CE total first-year cost for SMEs: £1,500–£3,500; CE+ total assessor fee: £1,500–£3,000 + VAT | Multiple UK certification body pricing guides (CT, Cypro, CyberOne) | 2026-07-27 |
| Cyber Security and Resilience (Network and Information Systems) Bill: HL Bill 32 brought from the Commons 17 June 2026, still before the Lords at 14 August 2026, Royal Assent not yet given. The government policy statement estimates 900 to 1,100 MSPs brought into scope | UK Parliament Bill 4035 + DSIT policy statement | 2026-08-18 |
| NCSC describes Cyber Essentials as designed to prevent the most common internet-based attacks. We previously cited an "~80% of attacks" figure to NCSC; that number is not on their Cyber Essentials pages, so it has been removed | NCSC Cyber Essentials overview | 2026-08-18 |
| ECP pricing: per-client by employee count (Micro (1–9) €95, Small (10–49) €195, Medium (50–249) €395, Large (250–999) €750, 1,000+ on request), no monthly base, one-time €400 MSP onboarding; partner rates on request | ECP ADR-0050 per-client-by-employee-count pricing + ADR-0036 onboarding fee | 2026-07-27 |
| CyFun is Belgium's official NIS2 compliance path, CCB-issued | CCB Centre pour la Cybersécurité Belgique | 2026-07-27 |