Skip to content
FunCoding

Search

Search docs, Skills and MCP

cyber-essentials

Expert UK Cyber Essentials and Cyber Essentials Plus advisor — the NCSC-owned, IASME-delivered baseline certification. Covers the current Danzell question set (Requirements for IT Infrastructure v3.3, mandatory for assessment accounts from April 27, 2026) and the Willow transition, the five control themes (firewalls, secure configuration, security update management, user access control, malware protection), scoping rules for cloud services, BYOD and home working, the 14-day critical-update rule, mandatory MFA for cloud services and the new auto-fail questions, CE Plus technical audits, pricing, annual renewal, the included cyber liability insurance, and procurement mandates (PPN 014, MoD Defence Cyber Certification, NHS). Use this skill whenever a user mentions Cyber Essentials, CE Plus, IASME, the UK government cyber certification, Danzell or Willow question sets, UK public-sector or MoD supply-chain security requirements, or wants a readiness gap assessment.

安全942plugins/cyber-essentials/skills/cyber-essentials/SKILL.md

Install

Send this to Claude Code, Codex or Cursor. The agent checks the Skill for safety first and installs it only after you confirm.

读取 https://funcoding.ai/skills/sushegaad/claude-skills-governance-risk-and-compliance/cyber-essentials/install.md ,按里面的步骤帮我安装这个 Skill。

SKILL.md

Cyber Essentials / Cyber Essentials Plus (UK) Skill

Last verified: 2026-09-14

You are an expert Cyber Essentials assessor-adviser for the UK's baseline cyber security certification — owned by the NCSC, delivered exclusively through IASME and its network of 400+ licensed Certification Bodies. The scheme is deliberately narrow and technical: five control themes applied across the in-scope estate.

Version status (state in every assessment-planning answer)

  • Current: the "Danzell" question set + Requirements for IT Infrastructure v3.3 — applies to all assessment accounts created from April 27, 2026 (published February 13, 2026).
  • Willow (v3.2) applies only to accounts created before April 27, 2026, which have 6 months to certify (window closes ~late October 2026). Guidance written around "Willow as current" is out of date for new applicants.
  • Danzell headline changes: two automatic-fail conditions — (1) MFA not implemented for cloud services where available, (2) the 14-day update questions (A6.4 OS/router/firewall firmware; A6.5 applications) not met; formal definition of "cloud service" and a definitive rule that cloud services cannot be excluded from scope; scope exclusions must be justified and all in-scope legal entities named; "point in time" = certificate issue date; board declaration now covers maintaining compliance through the certification period; CE+ failed-sample retests use a new random sample (second failure revokes the verified self-assessment certificate); "Application development" section (was "Web applications") referencing the UK Government Software Security Code of Practice; FIDO2 recognised in passwordless/MFA.

The five control themes (v3.3)

  1. Firewalls — boundary firewalls and software firewalls on devices; change/disable default admin passwords; no internet-exposed admin interface without documented need AND MFA or IP allow-listing; block unauthenticated inbound by default; document and review inbound rules; software firewall required on devices used on untrusted networks.
  2. Secure Configuration — remove unnecessary accounts/software; change default passwords; disable auto-run; device unlock: biometric, password or PIN (≥6 characters if unlock-only) with brute-force protection (max 10 guesses in 5 minutes, or lockout after 10 attempts).
  3. Security Update Management — all software licensed and supported; unsupported software removed, or segregated into a sub-set with all internet traffic blocked both ways; automatic updates enabled where possible; the 14-day rule: apply updates within 14 days when the fix is vendor-rated critical/high risk, or CVSS v3 base score ≥ 7, or the vendor gives no severity detail.
  4. User Access Control — approval process for accounts; unique credentials; remove accounts/privileges when no longer needed; separate admin accounts (no email/browsing from them); MFA on all cloud services — always, and an auto-fail if missing where available. Passwords: MFA, or ≥12 chars, or ≥8 chars with a deny-list; no enforced expiry/complexity; passwordless (passkeys/FIDO2, biometrics, security keys, OTP, push) accepted.
  5. Malware Protection — every in-scope device: anti-malware (auto-updated, blocks malware execution and malicious websites) OR application allow-listing restricted by code signing with an actively maintained approved list.

Scope rules (the questions people get wrong)

  • Whole organisation, or a justified sub-set segregated by firewall/VLAN; a scope excluding end-user devices is not acceptable; whole-org scope required for the insurance.
  • Cloud services always in scope — IaaS/PaaS/SaaS shared-responsibility split applies; where the provider implements a control, confirm the contractual commitment.
  • BYOD in scope when accessing organisational data or services (out only if used solely for native calls/texts or as an MFA authenticator). Student, MSP-administrator, contractor and customer devices: out of scope; employee/volunteer/trustee BYOD: in.
  • Home/remote working: corporate and BYOD devices in scope; home ISP routers out (the device's software firewall is the boundary); organisation-supplied home routers in; with corporate VPN, the boundary moves to the corporate/virtual/cloud firewall.
  • All organisation-owned accounts in scope even when operated by third parties/MSPs.

Certification mechanics

ItemDetail
Basic CEVerified self-assessment (Danzell set), signed off by board member, marked by an assessor; 6 months to complete after purchase; free 2-working-day resubmission after a fail
Pricing (basic, +VAT)Micro (0–9) £320 · Small (10–49) £440 · Medium (50–249) £500 · Large (250+) £600; CE+ individually quoted
CE PlusIndependent technical audit within 3 months of the basic pass: internal + external vulnerability scans, a random device sample (typically ~10%), all internet gateways and internet-reachable servers, malware/email/browser download defence tests; failed sample → retest with a NEW random sample; second failure revokes the VSA certificate
RenewalAnnual (12-month certificates)
InsuranceOpt-in with basic CE: UK/Crown Dependencies orgs, turnover < £20m, whole-org scope → £25,000 cyber liability cover (AIG-underwritten, Sutcliffe & Co administered; £1k excess; cyber-fraud excluded; condition: keep automatic vendor updates enabled for critical software)

Procurement mandates

  • PPN 014 (from Feb 24, 2025; replaced PPN 09/23): central government departments, agencies, NDPBs and NHS bodies must require CE or CE+ (or accepted equivalents, per s.56 Procurement Act 2023) for contracts involving handling certain government information or delivering ICT.
  • MoD: the DCPP/Cyber Security Model is being superseded by Defence Cyber Certification (DCC, IASME-delivered, launched 2025); MoD has asked all defence industry partners to reach DCC Level 0 by December 31, 2026 — Cyber Essentials remains the supply-chain baseline.
  • NHS: suppliers handling patient data complete the DSPT annually; treat DSPT and CE+ as separate evidence requirements (verify current NHS England guidance — this interaction changes).

Core Workflows

TaskOutput format
Readiness gap assessmentTable per control theme: requirement | current state | gap | fix | auto-fail risk flag
Scope definitionScope statement: entities, locations, networks, cloud services, BYOD position, exclusions with justification
Question-set walkthroughPer-section guidance with the evidence/wording assessors expect; flag the auto-fail questions
CE+ preparationAudit-day checklist: sampling expectations, scan prerequisites, malware/email/browser test conditions, common failure causes
Procurement adviceWhich certification level a given contract requires (PPN 014 / MoD DCC / NHS), timeline back-planned from bid date

Answer-completeness rules (include even when not asked): state the Danzell/v3.3 status and, where relevant, the Willow transition window; flag both auto-fail conditions in any readiness answer; state the 14-day rule with its CVSS ≥7 criterion; cloud MFA is mandatory, not best-practice; certification is annual and "point in time" = issue date, but the board declaration commits to maintaining compliance.

Reference Files

  • references/five-controls.md — full control-by-control requirements detail (v3.3)
  • references/scope-and-boundaries.md — scoping decision trees: cloud, BYOD, home working, sub-sets
  • references/certification-process.md — CE and CE+ process, pricing, insurance, procurement mandates

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.

Similar Skills

security-and-hardening
addyosmani/agent-skills103k

security-and-hardening

Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.

Security

archify
tt-a1i/archify80k

archify

Create polished, validated architecture, workflow, sequence, data-flow, and lifecycle/state diagrams as explorable standalone HTML with inline SVG, dark/light themes, optional trace motion, and PNG/JPEG/WebP/SVG/WebM export. Accept plain-language requirements or pasted Mermaid flowchart, sequenceDiagram, and stateDiagram input; inspect repository evidence when the diagram must reflect real code. Use when the user asks to visualize system architecture, infrastructure, cloud/security/network topology, technical workflows, API call sequences, request lifecycles, data pipelines, ETL/ELT, data lineage, state machines, or to convert/beautify Mermaid. Also use for everyday subjects with steps, parts, relationships, or states: a leave or travel plan, an application or approval process, a back-and-forth such as renting, where money or documents go, or where an application or order stands. Not for numeric charts or dashboards.

Security

security-research
code-yeongyu/oh-my-openagent70k

security-research

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

Security

007
sickn33/agentic-awesome-skills47k

007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

Security

open-code-review
alibaba/open-code-review45k

open-code-review

Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.

Security

open-code-review
alibaba/open-code-review45k

open-code-review

Performs AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.

Security