IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

ECP vs Cyber Essentials (UK): CyFun vs the NCSC Baseline Scheme

Cyber Essentials is the UK government's baseline cybersecurity certification scheme — five technical controls, two levels (CE self-assessed and CE+ independently verified), mandatory for UK government contracts under PPN 014, and owned by NCSC with IASME as delivery partner. Easy Cyber Protection is a CyFun audit-readiness platform for Belgian MSPs. Both operate in the cybersecurity compliance space, but for fundamentally different regulatory regimes — the UK left the EU, and NIS2 does not apply there. CE is a respected, brand-strong baseline; CyFun is Belgium's legally-grounded NIS2 path.

At a glance

Cyber Essentials / CE+ (UK) Easy Cyber Protection / CyFun
Owning authority NCSC — National Cyber Security Centre (UK government); IASME Consortium is delivery partner since 2020 CCB — Centre pour la Cybersécurité Belgique (ECP implements CyFun)
Year established / last updated 2014 (UK government launch); last scheme update April 27, 2026 (Danzell v3.3 question set) CyFun 2025 (aligned with NIST CSF 2.0)
Legal status Voluntary for most organizations; mandatory for UK government contracts handling personal data (PPN 014) Operational — Belgium's CCB-issued NIS2 compliance path; audits running
Entity coverage Any organization; ~35,000 currently certified; 53,699 certificates issued Oct 2024 – Sep 2025; ~190,000 total to date Belgian entities registered under NIS2 (CCB portal)
Structure 5 technical controls: Firewalls, Secure configuration, Security update management, User access control, Malware protection — assessed at CE (self-assessment) or CE+ (independent technical audit) 4 tiers: Small, Basic, Important, Essential — each with YAML-implemented controls across all NIS2 domains
Certification / assessment CE: self-assessment questionnaire verified by IASME-authorized body; CE+: same controls + hands-on vulnerability scanning, phishing sim, config audit by certified assessor CAB audit by accredited body; ECP generates signed .ecpbundle.zip audit bundle
Compliance cost CE IASME fee: £330–£500 + VAT (by org size); CE total first-year: £1,500–£3,500 for SMEs; CE+ total: £1,500–£3,000 + VAT (assessor fee alone) MSP charges client €100–400/month via ECP platform — absorbed into MSP service fee
MSP / portfolio model No multi-tenant MSP portfolio track; each client needs its own certification; UK Cyber Resilience Bill will bring ~900 MSPs into direct regulatory scope Purpose-built for MSP portfolio delivery: partner dashboard, white-label, per-client management
NIS2 / EU relationship UK left the EU — NIS2 does not apply; the UK Cyber Security and Resilience Bill (entered Lords June 2026, Royal Assent expected late 2026) is the UK's NIS2-equivalent and will expand scope to MSPs CyFun is Belgium's official NIS2 implementation path; CCB-issued
Geography UK (England, Scotland, Wales, Northern Ireland); recognized in Australia, Canada for supply-chain requirements Belgium-first; Ireland co-adopting CyFun as of 2026

Sources: NCSC cyber.gov.uk, IASME iasme.co.uk, UK government PPN 014, SC Magazine UK certification statistics Oct 2024 – Sep 2025. Last verified 2026-07-27.

Where Cyber Essentials fits better

  • You supply services or products to UK government bodies — CE/CE+ is a mandatory pre-condition for contracts involving personal data under PPN 014
  • You serve UK commercial clients where CE is becoming expected by cyber insurance underwriters and larger enterprise buyers
  • You want a recognized baseline that protects against ~80% of common internet-based attacks, according to NCSC's own estimate
  • Your clients are very small organizations (micro/SME) that need an achievable, structured starting point and want the included cyber liability insurance for UK orgs with turnover under £20M
  • You need to align with UK-specific procurement and supply chain requirements (National Cyber Security Centre guidance, UK government frameworks)

Where ECP / CyFun fits better

  • Your clients are Belgian (or Irish) — CyFun is the CCB's official NIS2 compliance path, the one Belgian auditors and the CCB assess against
  • You are a Belgian MSP and want to package CyFun audit-readiness as a repeatable service across your client portfolio — not a per-org certification project
  • You need NL / FR / EN materials with Belgian regulatory context (CCB alignment, VLAIO kmo-portefeuille leverage for Flemish clients)
  • You want predictable MSP economics: one per-client fee by size (XS €25 / S €75 / M €250 / L €825 / XL €2,750 / XXL €9,075), no monthly base, billed annually upfront
  • Your clients need a CAB audit deliverable — ECP generates the signed .ecpbundle.zip that an accredited audit body accepts

The compliance cost comparison

This comparison is framework-vs-platform, not tool-vs-tool. Cyber Essentials is a UK government scheme — the cost is the certification work it requires. ECP is a platform that MSPs pay for and resell to clients. The numbers below illustrate what each path costs a typical Belgian SME via ECP versus a UK SME seeking Cyber Essentials Plus.

Cyber Essentials Plus — UK SME, 25 employees

  • • IASME assessment fee: £400 + VAT (small org, 10–49 employees)
  • • CE+ independent technical audit (vulnerability scan, phishing sim, config check): £1,500–£3,000 + VAT
  • • Preparation and remediation work: 20–60 person-hours for first-time applicants
  • • Annual recertification required — same cost each year
  • • Cyber liability insurance included free for UK orgs with turnover < £20M (CE only)
  • • Total estimated first-year cost for 25-person SME: £1,800–£3,500 (CE) or £2,500–£6,000 (CE+)

IASME fees are official 2026 rates. CE+ assessor fees are set by individual certification bodies and vary by system complexity. Total costs include remediation and internal time but exclude any ongoing consultant retainer. Source: IASME 2026 fee schedule; UK market pricing data from certification bodies.

ECP / CyFun — Belgian SME via MSP (20-client portfolio, S-size avg)

  • • One-time MSP onboarding: €400 (per partner, once)
  • • Per-client (S-size, 100–999 entities): 20 × €75 = €1,500 / month
  • • Total recurring ECP platform cost to MSP: €1,500 / month (billed annually upfront)
  • • MSP charges SME client: €200 / month (suggested range €100–400)
  • • Client's annual cost: €2,400 — vs £1,800–£6,000 CE/CE+ first-year cost
  • • MSP revenue: 20 × €200 = €4,000 / month — gross margin ~€2,500 / month (~€30K / year)

Per-client fee by site size (XS €25 / S €75 / M €250 / L €825 / XL €2,750 / XXL €9,075). No monthly base; billed annually upfront. One-time €400 MSP onboarding per partner. Every client gets the full feature set including AI and integrations from day one.

Framework coverage overlap

Cyber Essentials covers five technical security controls — a deliberately narrow, achievable baseline. CyFun is broader, covering the full NIS2 Article 21 domain set across four tiers. The five CE controls are present within CyFun (predominantly in Small and Basic tiers), so CyFun work builds CE readiness — but CE certification does not satisfy CyFun audit requirements.

Control area Cyber Essentials / CE+ (UK) CyFun / ECP
Firewalls & network boundary Control 1 — Firewalls: boundary and host-based firewalls; rule review; CE+ includes live scanning CyFun PR.AC + PR.PT controls; network segmentation evidence in ECP
Secure configuration Control 2 — Secure configuration: disable unnecessary software/ports, auto-lock, admin accounts; tightened in Danzell v3.3 CyFun PR.IP controls in Basic and above; ECP hardening checklists
Security updates (patching) Control 3 — Security updates: Danzell mandates critical/high patches within 14 days (auto-fail if missed); unsupported software must be removed CyFun PR.IP-12 / ID.RA; ECP patch register + integration with EDR/RMM
User access control Control 4 — User access control: least privilege, MFA for cloud services now mandatory (auto-fail if not enabled in Danzell) CyFun PR.AC controls; ECP access register + evidence collection
Malware protection Control 5 — Malware protection: up-to-date anti-malware or application allowlisting CyFun PR.DS + DE.CM; ECP EDR integration (Sophos, Checkpoint)
Incident response Not in scope — CE focuses on prevention, not response or recovery CyFun DE.CM + RS controls; ECP incident log + CSIRT notification workflow
Supply chain / ecosystem Not in scope — CE is per-organization, not supply chain CyFun ID.SC; ECP vendor register template
Governance & risk Not in scope — CE is technical controls only, no governance layer CyFun GV + ID.RA; ECP wiki enforces policy ownership and evidence
NIS2 Article 21 compliance Not applicable — UK left the EU; CE is not a NIS2 compliance path Yes — CyFun is Belgium's implementation of Article 21; CCB-issued

Sources: NCSC Cyber Essentials Technical Requirements (Danzell v3.3, April 2026); IASME iasme.co.uk; CCB CyFun 2025 documentation. Mapping is indicative — actual gap analysis requires professional assessment.

Common questions

Does Cyber Essentials certification satisfy NIS2 in Belgium?

No. Cyber Essentials is a UK government scheme owned by NCSC — it is not part of the EU regulatory framework, and Belgium's NIS2 compliance path is CyFun, issued by the CCB. A Belgian entity audited by a Belgian CAB body is assessed against CyFun, not Cyber Essentials. The two frameworks overlap in some technical controls (patching, access control, malware protection) but are entirely separate legal regimes with different governance, certification bodies, and legal effects. Holding a CE certificate does not satisfy a CyFun audit, and vice versa.

Can ECP help UK clients comply with Cyber Essentials?

Not natively. ECP implements CyFun (Belgium's CCB framework). The underlying technical controls overlap — CE's five areas are present within CyFun Small and Basic — so ECP work builds readiness for the technical substance of CE. But ECP does not generate NCSC/IASME-formatted evidence, does not connect to IASME-authorized certification bodies, and does not produce the documentation format UK assessors require. A UK client using ECP as a compliance tool would get strong technical hygiene but would need a separate CE/CE+ assessment process for formal certification.

What is the UK Cyber Security and Resilience Bill and does it affect Belgian MSPs?

The UK Cyber Security and Resilience Bill was introduced to Parliament in November 2025 and entered the House of Lords on 25 June 2026. It is the UK's domestic NIS2-equivalent, expanding the scope of the original UK NIS Regulations to include Managed Service Providers (~900+ UK MSPs) and data centre providers, with enhanced security duties and incident reporting requirements. Royal Assent is expected late 2026 with phased implementation to 2028. This Bill affects UK-based MSPs, not Belgian ones. Belgian MSPs are subject to EU NIS2 and CCB/CyFun — not the UK Bill.

Is Cyber Essentials widely recognised outside the UK?

CE has significant brand recognition in the UK market and is referenced in the procurement policies of some UK-headquartered multinationals. It is recognized in supply-chain contexts in Australia and Canada, where some organizations cite it alongside ISO 27001 as an accepted baseline. Within the EU, CE is not a recognized compliance path under NIS2 — EU member states each have national frameworks (CyFun in Belgium, ReCyF in France, ENS in Spain, IT-Grundschutz in Germany) that are the assessed paths. If a Belgian company wins a UK government contract, CE may be required in addition to — not instead of — CyFun.

Deliver CyFun audit-readiness to your Belgian clients

If you are a Belgian MSP, CyFun — not Cyber Essentials — is the compliance path your clients need. ECP packages it as a monthly MSP service: guided workflows, evidence collection, white-label reports, and a signed audit bundle your CAB auditor accepts.

Related

Fact check

ClaimSourceAccessed
Cyber Essentials launched 2014 by UK government; NCSC owns the scheme; IASME is delivery partner since 2020 NCSC / Wikipedia — Cyber Essentials scheme history 2026-07-27
Five technical controls: Firewalls, Secure configuration, Security update management, User access control, Malware protection NCSC Cyber Essentials Technical Requirements 2026-07-27
Danzell (v3.3) question set mandatory from April 27, 2026; replaces Willow; introduces MFA auto-fail for cloud services and 14-day patching auto-fail IASME Danzell announcement + Cyphere analysis 2026-07-27
53,699 certificates issued Oct 2024 – Sep 2025 (40,626 CE + 13,073 CE+); ~190,000 total to date; ~35,000 currently certified UK orgs SC Magazine UK — Cyber Essentials Adoption Increases in 2025 2026-07-27
Mandatory for UK government contracts involving personal data under PPN 014 UK Government Procurement Policy Note 014 2026-07-27
IASME assessment fees 2026: £330 + VAT (micro 1–9 emp), £400 + VAT (small 10–49), £450 + VAT (medium 50–249), £500 + VAT (large 250+) ISMS.online Cyber Essentials cost guide 2026 2026-07-27
CE total first-year cost for SMEs: £1,500–£3,500; CE+ total assessor fee: £1,500–£3,000 + VAT Multiple UK certification body pricing guides (CT, Cypro, CyberOne) 2026-07-27
UK Cyber Security and Resilience Bill introduced November 2025; cleared Commons; entered Lords June 25, 2026; Royal Assent expected late 2026; brings ~900+ MSPs into scope Cloudswitched News — UK Cyber Security & Resilience Bill Clears Commons June 2026 2026-07-27
NCSC estimates CE protects against ~80% of common internet-based cyber attacks NCSC Cyber Essentials overview documentation 2026-07-27
ECP pricing: per-client by site size (XS €25 / S €75 / M €250 / L €825 / XL €2,750 / XXL €9,075), no monthly base, one-time €400 MSP onboarding, billed annually ECP ADR-0035 per-client-only pricing + ADR-0036 onboarding fee 2026-07-27
CyFun is Belgium's official NIS2 compliance path, CCB-issued CCB Centre pour la Cybersécurité Belgique 2026-07-27