A Practical Guide to UK Cyber Essentials Plus Accreditation with AWS Security Improvement Program
UK Cyber Essentials+ certification is a growing requirement for organisations supplying to the UK government. The good news is that as an AWS Enterprise customer, much of the groundwork is already within reach. The AWS Security Improvement Program (SIP) aligns closely with all five Cyber Essentials control themes, turning your AWS security posture improvement work into tangible accreditation progress. This article walks you through exactly how.
Overview
Cyber Essentials (CE) is a UK government-backed security accreditation that helps organisations demonstrate a strong baseline of cybersecurity practices. For suppliers handling personal data or delivering technical products and services under government contracts, achieving this certification is a key requirement and an opportunity to build trust with your customers and stakeholders.
For organisations running workloads on AWS, there is good news: you are not starting from scratch. AWS already provides a structured security framework called the AWS Security Improvement Program (SIP) which is a set of curated best practices across five security pillars that AWS uses to baseline and elevate the security posture of Enterprise customers. Many of the SIP controls map directly to what Cyber Essentials requires.
This post explains how to use the AWS SIP as a proactive security best practices framework to close your CE gaps before the formal accreditation exercise.
What you will learn:
- Understand the five technical control themes assessed during Cyber Essentials accreditation
- How AWS SIP maps to Cyber Essentials
- Which Cyber Essentials auto-fail conditions to prioritise
- How to use AWS SIP as a Cyber Essentials readiness tool
- Key AWS-specific compliance gaps to watch
What is Cyber Essentials?
Cyber Essentials is a UK government-backed scheme, managed by the National Cyber Security Centre (NCSC) and certified through bodies like IASME. It defines five technical control themes that every organisation must demonstrate:
- Firewalls
- Secure Configuration
- Security Update Management
- User Access Control
- Malware Protection
The 2026 edition of Cyber Essentials introduces an enhanced focus on cloud security. Notably, Multi-Factor Authentication (MFA) is now a mandatory requirement for all cloud service users and administrators, making it a critical control to have in place before your assessment.
Cyber Essentials vs Cyber Essentials Plus
Cyber Essentials is a self-assessment certification that verifies your organisation has these five foundational security controls in place. Cyber Essentials Plus builds on this by introducing an independent technical audit, where an accredited assessor validates those same controls through hands-on testing including vulnerability scans and checks across sampled devices and internet-facing systems.
What is the AWS Security Improvement Program (SIP)?
The AWS Security Improvement Program is a structured security best practices framework used by AWS Technical Account Managers and Security Specialists to evaluate an enterprise customer's AWS environment. Unlike traditional point-in-time assessments, SIP is designed to deliver sustainable security outcomes by focusing on people, process, and mechanisms, providing your organisation with the depth and continuity needed to maintain a strong security posture over time. It covers over 200+ best practices across five pillars:
- IAM— identity, access management, MFA, least privilege, credential hygiene
- Detection — logging, alerting, anomaly detection, tamper-resistant audit trails
- Infrastructure Protection — network security, patch management, hardened images, malware defense
- Data Protection — encryption, secrets management, data classification, access controls
- IR & Automation — incident response, automated remediation, ransomware resilience
The Mapping: CE Themes to SIP Pillars
The following sections provide the complete question-level mapping for each CE theme. Each table lists the mapped SIP control(s), the SIP pillar, and the nature of the mapping (Direct = primary control satisfying the CE requirement; Supports = compensating or depth control).
1. Firewalls → SIP Infrastructure Protection + IAM + Detection Pillars
CE requires boundary and software firewalls, documented rule management, and protected admin access. On AWS, security groups are the primary firewall mechanism. VPC NACLs provide a secondary layer. Admin access to AWS accounts must be protected by MFA or IP allowlisting.
2. Secure Configuration → SIP Infrastructure Protection + IAM Pillars
CE requires removal of unnecessary software and accounts, changing of all default credentials, authentication on external services, brute force protection, and device locking. On AWS, this maps primarily to hardened AMI management, IAM credential hygiene, and account lifecycle controls.
3. Security Update Management → SIP Infrastructure Protection + IR & Automation Pillars
Under Cyber Essentials, organisations must ensure all software remains supported, properly licensed, and patched within 14 days of a critical or high-severity vulnerability fix being released. Maintaining a consistent and well-documented patching cadence is therefore essential to meeting this requirement.
On AWS, this control naturally maps to automated patch management, minor version upgrade automation, and vulnerability assessment tooling.
Important — Amazon WorkSpaces Users: The default monthly maintenance window in Amazon WorkSpaces does not meet the Cyber Essentials 14-day patching requirement. See our guide on achieving CE compliance for Amazon WorkSpaces Personal using AWS Systems Manager.
4. User Access Control → IAM (dominant) + Detection
User Access Control is the largest CE theme with 17 questions covering account provisioning, unique credentials, off-boarding, least privilege, admin account separation, password quality, and MFA on all cloud services. The IAM SIP pillar provides the primary coverage, with Detection controls providing the monitoring layer.
5. Malware Protection → Infrastructure Protection + IR & Automation
CE requires all devices to be protected from malware via either anti-malware software or application allow-listing. Anti-malware must be kept up to date and must scan web pages for malicious content. On AWS, this maps to GuardDuty, Inspector, DNS-based threat blocking, and automated incident response.
The Auto-Fail Controls: Where to Focus First
The 2026 CE question set has several questions that result in an automatic fail regardless of other answers. Each maps to a specific SIP control:
A Practical Assessment Workflow
Here is how to use the SIP as a CE readiness tool:
- Run a SIP assessment with your AWS TAM to get a baseline status across all controls
- Filter for CE-relevant controls — the 54 controls mapped in this framework
- Prioritise the auto-fail controls — IAM-21, IP-10, IR-14 must be Complete before anything else
- Work through each CE theme using the mapped SIP controls as your prioritised remediation checklist
- Re-run the SIP assessment to validate closure before submitting for CE accreditation
Conclusion
The AWS Security Improvement Program (SIP) is a structured security engagement available to AWS Enterprise Support and Unified Operations customers. It provides a baseline assessment of your AWS security posture across more than 200+ best practices, spanning five security pillars: identity and access management, detection, secure configuration, data protection, and incident response.
While SIP and Cyber Essentials are distinct frameworks, there is meaningful overlap between them. AWS SIP best practices covering secure configuration, user access control, patch management, network security, and malware protection align closely with the five technical controls assessed under Cyber Essentials. Organisations that address their SIP findings will therefore make significant progress towards CE readiness at the same time.
To get started, speak to your AWS Technical Account Manager (TAM) about scheduling a SIP review with Cyber Essentials readiness as a defined objective.
- Language
- English
Relevant content
AWS OFFICIALUpdated a year ago