Schemes
What each scheme asks of unsupported software
Seven schemes, each placed only when you tick it. With nothing ticked the lines show their support state and no clause.
- Cyber EssentialsPlaced when you say you hold or are going for Cyber Essentials. Choose Cyber Essentials Plus and the Plus requirements attach too. Segregation is a scope decision you make: the pages say what the requirement asks and never that a device is out of scope.
- Cyber Essentials PlusPlaced when you choose Cyber Essentials Plus. It keeps the Cyber Essentials requirements and adds the assessor-run checks.
- Essential EightPlaced when you say Essential Eight applies to you, at the maturity level you target (1, 2 or 3). Which clause attaches turns on the class of the product: operating systems, the priority application classes, or other applications.
- CIS Controls v8Placed when you tick CIS Controls v8.
- PCI DSS 4.0Placed when you say PCI DSS applies. Appendix A3 (designated entities) attaches only when you tick that you are one.
- NIST SP 800-53Placed when you say NIST SP 800-53 is your control set.
- ISO/IEC 27001Placed when you tick ISO/IEC 27001 as in scope. It is a management system standard you choose to hold, not a law.