ECP vs Cyber Essentials (UK): CyFun vs the NCSC Baseline Scheme
Cyber Essentials is the UK government's baseline cybersecurity certification scheme — five technical controls, two levels (CE self-assessed and CE+ independently verified), mandatory for UK government contracts under PPN 014, and owned by NCSC with IASME as delivery partner. Easy Cyber Protection is a CyFun audit-readiness platform for Belgian MSPs. Both operate in the cybersecurity compliance space, but for fundamentally different regulatory regimes — the UK left the EU, and NIS2 does not apply there. CE is a respected, brand-strong baseline; CyFun is Belgium's legally-grounded NIS2 path.
At a glance
| Cyber Essentials / CE+ (UK) | Easy Cyber Protection / CyFun | |
|---|---|---|
| Owning authority | NCSC — National Cyber Security Centre (UK government); IASME Consortium is delivery partner since 2020 | CCB — Centre pour la Cybersécurité Belgique (ECP implements CyFun) |
| Year established / last updated | 2014 (UK government launch); last scheme update April 27, 2026 (Danzell v3.3 question set) | CyFun 2025 (aligned with NIST CSF 2.0) |
| Legal status | Voluntary for most organizations; mandatory for UK government contracts handling personal data (PPN 014) | Operational — Belgium's CCB-issued NIS2 compliance path; audits running |
| Entity coverage | Any organization; ~35,000 currently certified; 53,699 certificates issued Oct 2024 – Sep 2025; ~190,000 total to date | Belgian entities registered under NIS2 (CCB portal) |
| Structure | 5 technical controls: Firewalls, Secure configuration, Security update management, User access control, Malware protection — assessed at CE (self-assessment) or CE+ (independent technical audit) | 4 tiers: Small, Basic, Important, Essential — each with YAML-implemented controls across all NIS2 domains |
| Certification / assessment | CE: self-assessment questionnaire verified by IASME-authorized body; CE+: same controls + hands-on vulnerability scanning, phishing sim, config audit by certified assessor | CAB audit by accredited body; ECP generates signed .ecpbundle.zip audit bundle |
| Compliance cost | CE IASME fee: £330–£500 + VAT (by org size); CE total first-year: £1,500–£3,500 for SMEs; CE+ total: £1,500–£3,000 + VAT (assessor fee alone) | MSP charges client €100–400/month via ECP platform — absorbed into MSP service fee |
| MSP / portfolio model | No multi-tenant MSP portfolio track; each client needs its own certification; UK Cyber Resilience Bill will bring ~900 MSPs into direct regulatory scope | Purpose-built for MSP portfolio delivery: partner dashboard, white-label, per-client management |
| NIS2 / EU relationship | UK left the EU — NIS2 does not apply; the UK Cyber Security and Resilience Bill (entered Lords June 2026, Royal Assent expected late 2026) is the UK's NIS2-equivalent and will expand scope to MSPs | CyFun is Belgium's official NIS2 implementation path; CCB-issued |
| Geography | UK (England, Scotland, Wales, Northern Ireland); recognized in Australia, Canada for supply-chain requirements | Belgium-first; Ireland co-adopting CyFun as of 2026 |
Sources: NCSC cyber.gov.uk, IASME iasme.co.uk, UK government PPN 014, SC Magazine UK certification statistics Oct 2024 – Sep 2025. Last verified 2026-07-27.
Where Cyber Essentials fits better
- You supply services or products to UK government bodies — CE/CE+ is a mandatory pre-condition for contracts involving personal data under PPN 014
- You serve UK commercial clients where CE is becoming expected by cyber insurance underwriters and larger enterprise buyers
- You want a recognized baseline that protects against ~80% of common internet-based attacks, according to NCSC's own estimate
- Your clients are very small organizations (micro/SME) that need an achievable, structured starting point and want the included cyber liability insurance for UK orgs with turnover under £20M
- You need to align with UK-specific procurement and supply chain requirements (National Cyber Security Centre guidance, UK government frameworks)
Where ECP / CyFun fits better
- Your clients are Belgian (or Irish) — CyFun is the CCB's official NIS2 compliance path, the one Belgian auditors and the CCB assess against
- You are a Belgian MSP and want to package CyFun audit-readiness as a repeatable service across your client portfolio — not a per-org certification project
- You need NL / FR / EN materials with Belgian regulatory context (CCB alignment, VLAIO kmo-portefeuille leverage for Flemish clients)
- You want predictable MSP economics: one per-client fee by size (XS €25 / S €75 / M €250 / L €825 / XL €2,750 / XXL €9,075), no monthly base, billed annually upfront
- Your clients need a CAB audit deliverable — ECP generates the signed .ecpbundle.zip that an accredited audit body accepts
The compliance cost comparison
This comparison is framework-vs-platform, not tool-vs-tool. Cyber Essentials is a UK government scheme — the cost is the certification work it requires. ECP is a platform that MSPs pay for and resell to clients. The numbers below illustrate what each path costs a typical Belgian SME via ECP versus a UK SME seeking Cyber Essentials Plus.
Cyber Essentials Plus — UK SME, 25 employees
- • IASME assessment fee: £400 + VAT (small org, 10–49 employees)
- • CE+ independent technical audit (vulnerability scan, phishing sim, config check): £1,500–£3,000 + VAT
- • Preparation and remediation work: 20–60 person-hours for first-time applicants
- • Annual recertification required — same cost each year
- • Cyber liability insurance included free for UK orgs with turnover < £20M (CE only)
- • Total estimated first-year cost for 25-person SME: £1,800–£3,500 (CE) or £2,500–£6,000 (CE+)
IASME fees are official 2026 rates. CE+ assessor fees are set by individual certification bodies and vary by system complexity. Total costs include remediation and internal time but exclude any ongoing consultant retainer. Source: IASME 2026 fee schedule; UK market pricing data from certification bodies.
ECP / CyFun — Belgian SME via MSP (20-client portfolio, S-size avg)
- • One-time MSP onboarding: €400 (per partner, once)
- • Per-client (S-size, 100–999 entities): 20 × €75 = €1,500 / month
- • Total recurring ECP platform cost to MSP: €1,500 / month (billed annually upfront)
- • MSP charges SME client: €200 / month (suggested range €100–400)
- • Client's annual cost: €2,400 — vs £1,800–£6,000 CE/CE+ first-year cost
- • MSP revenue: 20 × €200 = €4,000 / month — gross margin ~€2,500 / month (~€30K / year)
Per-client fee by site size (XS €25 / S €75 / M €250 / L €825 / XL €2,750 / XXL €9,075). No monthly base; billed annually upfront. One-time €400 MSP onboarding per partner. Every client gets the full feature set including AI and integrations from day one.
Framework coverage overlap
Cyber Essentials covers five technical security controls — a deliberately narrow, achievable baseline. CyFun is broader, covering the full NIS2 Article 21 domain set across four tiers. The five CE controls are present within CyFun (predominantly in Small and Basic tiers), so CyFun work builds CE readiness — but CE certification does not satisfy CyFun audit requirements.
| Control area | Cyber Essentials / CE+ (UK) | CyFun / ECP |
|---|---|---|
| Firewalls & network boundary | Control 1 — Firewalls: boundary and host-based firewalls; rule review; CE+ includes live scanning | CyFun PR.AC + PR.PT controls; network segmentation evidence in ECP |
| Secure configuration | Control 2 — Secure configuration: disable unnecessary software/ports, auto-lock, admin accounts; tightened in Danzell v3.3 | CyFun PR.IP controls in Basic and above; ECP hardening checklists |
| Security updates (patching) | Control 3 — Security updates: Danzell mandates critical/high patches within 14 days (auto-fail if missed); unsupported software must be removed | CyFun PR.IP-12 / ID.RA; ECP patch register + integration with EDR/RMM |
| User access control | Control 4 — User access control: least privilege, MFA for cloud services now mandatory (auto-fail if not enabled in Danzell) | CyFun PR.AC controls; ECP access register + evidence collection |
| Malware protection | Control 5 — Malware protection: up-to-date anti-malware or application allowlisting | CyFun PR.DS + DE.CM; ECP EDR integration (Sophos, Checkpoint) |
| Incident response | Not in scope — CE focuses on prevention, not response or recovery | CyFun DE.CM + RS controls; ECP incident log + CSIRT notification workflow |
| Supply chain / ecosystem | Not in scope — CE is per-organization, not supply chain | CyFun ID.SC; ECP vendor register template |
| Governance & risk | Not in scope — CE is technical controls only, no governance layer | CyFun GV + ID.RA; ECP wiki enforces policy ownership and evidence |
| NIS2 Article 21 compliance | Not applicable — UK left the EU; CE is not a NIS2 compliance path | Yes — CyFun is Belgium's implementation of Article 21; CCB-issued |
Sources: NCSC Cyber Essentials Technical Requirements (Danzell v3.3, April 2026); IASME iasme.co.uk; CCB CyFun 2025 documentation. Mapping is indicative — actual gap analysis requires professional assessment.
Common questions
Does Cyber Essentials certification satisfy NIS2 in Belgium?
No. Cyber Essentials is a UK government scheme owned by NCSC — it is not part of the EU regulatory framework, and Belgium's NIS2 compliance path is CyFun, issued by the CCB. A Belgian entity audited by a Belgian CAB body is assessed against CyFun, not Cyber Essentials. The two frameworks overlap in some technical controls (patching, access control, malware protection) but are entirely separate legal regimes with different governance, certification bodies, and legal effects. Holding a CE certificate does not satisfy a CyFun audit, and vice versa.
Can ECP help UK clients comply with Cyber Essentials?
Not natively. ECP implements CyFun (Belgium's CCB framework). The underlying technical controls overlap — CE's five areas are present within CyFun Small and Basic — so ECP work builds readiness for the technical substance of CE. But ECP does not generate NCSC/IASME-formatted evidence, does not connect to IASME-authorized certification bodies, and does not produce the documentation format UK assessors require. A UK client using ECP as a compliance tool would get strong technical hygiene but would need a separate CE/CE+ assessment process for formal certification.
What is the UK Cyber Security and Resilience Bill and does it affect Belgian MSPs?
The UK Cyber Security and Resilience Bill was introduced to Parliament in November 2025 and entered the House of Lords on 25 June 2026. It is the UK's domestic NIS2-equivalent, expanding the scope of the original UK NIS Regulations to include Managed Service Providers (~900+ UK MSPs) and data centre providers, with enhanced security duties and incident reporting requirements. Royal Assent is expected late 2026 with phased implementation to 2028. This Bill affects UK-based MSPs, not Belgian ones. Belgian MSPs are subject to EU NIS2 and CCB/CyFun — not the UK Bill.
Is Cyber Essentials widely recognised outside the UK?
CE has significant brand recognition in the UK market and is referenced in the procurement policies of some UK-headquartered multinationals. It is recognized in supply-chain contexts in Australia and Canada, where some organizations cite it alongside ISO 27001 as an accepted baseline. Within the EU, CE is not a recognized compliance path under NIS2 — EU member states each have national frameworks (CyFun in Belgium, ReCyF in France, ENS in Spain, IT-Grundschutz in Germany) that are the assessed paths. If a Belgian company wins a UK government contract, CE may be required in addition to — not instead of — CyFun.
Deliver CyFun audit-readiness to your Belgian clients
If you are a Belgian MSP, CyFun — not Cyber Essentials — is the compliance path your clients need. ECP packages it as a monthly MSP service: guided workflows, evidence collection, white-label reports, and a signed audit bundle your CAB auditor accepts.
Related
Fact check
| Claim | Source | Accessed |
|---|---|---|
| Cyber Essentials launched 2014 by UK government; NCSC owns the scheme; IASME is delivery partner since 2020 | NCSC / Wikipedia — Cyber Essentials scheme history | 2026-07-27 |
| Five technical controls: Firewalls, Secure configuration, Security update management, User access control, Malware protection | NCSC Cyber Essentials Technical Requirements | 2026-07-27 |
| Danzell (v3.3) question set mandatory from April 27, 2026; replaces Willow; introduces MFA auto-fail for cloud services and 14-day patching auto-fail | IASME Danzell announcement + Cyphere analysis | 2026-07-27 |
| 53,699 certificates issued Oct 2024 – Sep 2025 (40,626 CE + 13,073 CE+); ~190,000 total to date; ~35,000 currently certified UK orgs | SC Magazine UK — Cyber Essentials Adoption Increases in 2025 | 2026-07-27 |
| Mandatory for UK government contracts involving personal data under PPN 014 | UK Government Procurement Policy Note 014 | 2026-07-27 |
| IASME assessment fees 2026: £330 + VAT (micro 1–9 emp), £400 + VAT (small 10–49), £450 + VAT (medium 50–249), £500 + VAT (large 250+) | ISMS.online Cyber Essentials cost guide 2026 | 2026-07-27 |
| CE total first-year cost for SMEs: £1,500–£3,500; CE+ total assessor fee: £1,500–£3,000 + VAT | Multiple UK certification body pricing guides (CT, Cypro, CyberOne) | 2026-07-27 |
| UK Cyber Security and Resilience Bill introduced November 2025; cleared Commons; entered Lords June 25, 2026; Royal Assent expected late 2026; brings ~900+ MSPs into scope | Cloudswitched News — UK Cyber Security & Resilience Bill Clears Commons June 2026 | 2026-07-27 |
| NCSC estimates CE protects against ~80% of common internet-based cyber attacks | NCSC Cyber Essentials overview documentation | 2026-07-27 |
| ECP pricing: per-client by site size (XS €25 / S €75 / M €250 / L €825 / XL €2,750 / XXL €9,075), no monthly base, one-time €400 MSP onboarding, billed annually | ECP ADR-0035 per-client-only pricing + ADR-0036 onboarding fee | 2026-07-27 |
| CyFun is Belgium's official NIS2 compliance path, CCB-issued | CCB Centre pour la Cybersécurité Belgique | 2026-07-27 |