Security credentials carry more weight in supplier conversations than they used to. Box UK has renewed its Cyber Essentials Plus certification for 2026, after passing the independent technical audit carried out by Pure Cyber, an NCSC-approved certification body.
What is Cyber Essentials Plus?
Cyber Essentials Plus is the UK government-backed scheme that confirms an organisation has the technical controls in place to defend against the most common cyber attacks. The basic Cyber Essentials is a self-assessment; the Plus version is the same control set but verified by an independent technical audit — someone external comes in and tests the controls. Certifications are valid for 12 months and are issued by IASME-accredited assessors under the NCSC scheme. Many UK public sector contracts require suppliers to hold it, and it’s increasingly referenced in private sector procurement frameworks too.
For many of the clients we work with — in the public sector, financial services, and anywhere with sensitive or regulated data — the credential has become part of the procurement baseline. Three or four years ago it was a differentiator; now it’s increasingly an entry requirement.
“We treat security as a baseline, not a feature. The audit looks at our internet-facing infrastructure, user privileges, endpoint protection, email and web filtering, and how we manage devices — and we’d rather have an independent assessor stress-test those controls every year than take our own word for it.”
Paul Evans, Chief Executive Officer, Box UK
What the 2026 audit covered
The 2026 assessment was carried out by Pure Cyber and covered:
External internet-facing infrastructure, with authenticated vulnerability scans of representative endpoints
User privileges and access controls
Email attachments, web browser downloads, and macro protection
Mobile device management across phones and tablets
If you’re scoping work where Cyber Essentials Plus matters, get in touch.
Alistair has been working in IT for the past decade both in the UK and Europe, supporting internal & external clients in various roles. Operating within a fast-paced environment, Alistair is experienced in numerous technologies such as Amazon Web Services, Windows Servers, Switching, Firewalls, Desktops, and everything in between.