Cyber security has become part of supplier due-diligence — a machining subcontractor holds your drawings and IP, and buyers want assurance that data is safe. Here is what Cyber Essentials Plus is, and why it matters.
What is Cyber Essentials Plus?
Cyber Essentials Plus is a UK government-backed cyber-security certification, run under the National Cyber Security Centre (NCSC) scheme. It confirms an organisation has the core technical controls — firewalls, secure configuration, access control, malware protection and patch management — in place to defend against the most common cyber attacks. Crucially, it is verified by independent hands-on testing, not just a questionnaire.
How is it different from Cyber Essentials?
Both cover the same five control areas, but the assurance level differs:
- Cyber Essentials — a self-assessment the organisation completes and submits.
- Cyber Essentials Plus — the same controls, plus an independent technical audit that actively tests they work.
The Plus tier is the one buyers trust when data protection genuinely matters.
Why does a machining subcontractor need it?
Because a subcontractor is trusted with customer drawings, specifications and intellectual property. Cyber Essentials Plus tells a buyer that data is handled securely — and in defence and aerospace supply chains it is increasingly a condition of doing business, captured in pre-qualification schemes such as JOSCAR.
Does Milltech hold Cyber Essentials Plus?
Yes. Milltech holds Cyber Essentials Plus, alongside ISO 9001:2015 (approved by LRQA) and JOSCAR registration — so your project data is protected to an independently tested standard, not just a self-declared one.