Aug 26, 2026

Company

Metafore is Cyber Essentials certified

Cyber Essentials certification mark with Metafore's five assessed security controls.

Metafore has been certified under Cyber Essentials, the UK government-backed scheme run by the National Cyber Security Centre. The certification, awarded this month following an external assessment by an IASME-licensed certification body, confirms that the technical controls protecting our systems and our customers' data meet the NCSC's baseline standard.

For a company that asks enterprises to run their operational workflows through cognitive agents, security has to be demonstrable rather than asserted. Certification gives our customers and partners something they can check for themselves, on a public register, maintained by the body that issued it.

Getting there was a focused piece of work. Over four weeks, teams across Metafore implemented the security processes, procedures, and controls the standard requires, then worked directly with our audit partner through the assessment itself — answering clarifications, producing evidence, and closing out every certification criterion. The credit belongs to the people who did that work, and to everyone whose responsiveness kept the assessment moving.

What Cyber Essentials covers

Cyber Essentials is the NCSC's answer to a practical question: what is the minimum set of technical controls that stops the great majority of commodity cyber attacks? The scheme has been running since 2014, is delivered in partnership with IASME, and has become a common requirement in UK public-sector procurement, including the Ministry of Defence supply chain.

The assessment examines five control areas. Firewalls must restrict inbound and outbound traffic at the network boundary and on individual devices. Secure configuration removes default passwords, unused accounts, and unnecessary software from every system in scope. Security update management requires that patches for high and critical vulnerabilities are applied within fourteen days of release. User access control limits administrative privileges to the people who need them, with multi-factor authentication where it matters. Malware protection ensures that every device in scope can detect and block malicious code before it runs.

None of these controls is exotic, and that is the point. The NCSC built the scheme around the observation that most successful attacks exploit basics left undone — an unpatched server, a default credential, an over-privileged account. An organization that holds the certification has shown an external assessor, in writing and under review, that the basics are done.

What this means for our customers

Metafore's platform sits close to the systems our customers care most about. Cognitive agents that sense, reason, and act across an enterprise necessarily touch customer records, transaction flows, and the knowledge fabric that connects them. Every conversation we have with a security or procurement team starts from the same place: show us how you protect what we give you.

Certification gives that conversation a verifiable starting point. Our certificate appears on the public register maintained by IASME on behalf of the NCSC, where anyone can confirm its scope, level, and current status — no request to us required. For customers in the UK public sector and for partners whose own contracts require certified suppliers, it also removes a procurement blocker outright.

We are equally clear about what the certification does and does not claim. Cyber Essentials is a baseline standard, and ours is the standard level of the scheme. It attests to the five technical control areas above and nothing broader, which is exactly how we present it. Security programs earn trust by being precise about their evidence, and we would rather state the boundary of ours plainly than let a badge imply more than it certifies.

What comes next

Cyber Essentials certification is valid for twelve months, and we will reassess annually to keep it current. The renewal cycle suits us well — the scheme's requirements evolve as attack techniques do, so each year's assessment checks our controls against the standard as it stands, and against an estate that keeps growing as the platform does.

The certification joins a security program that runs deeper than any single assessment, covering how we build, deploy, and operate the platform our customers rely on. We will share more of that work here as it matures.

You can verify our certificate on the NCSC register, and a copy is available to customers and prospects on request. If you would like to talk through how Metafore protects customer data in your deployment, get in touch.

Article by

Ravi Kalyan

Subscribe to Metafore blog

Get notified about new product features, customer updates, and more.

related posts

Aug 18, 2026

Product

The Data Problem Underneath Financial Crime Compliance

Aug 3, 2026

Industry

Why nobody has solved the banking ontology problem

Jul 16, 2026

Company

Metafore has completed its SOC 2 Type 1 examination

Aug 18, 2026

Product

The Data Problem Underneath Financial Crime Compliance

Aug 3, 2026

Industry

Why nobody has solved the banking ontology problem

Jul 16, 2026

Company

Metafore has completed its SOC 2 Type 1 examination

Jul 2, 2026

Product

What Holds a Multi-Agent System Together

contact us

Connect With Us

Request a demo learn how Metafore can transform your enterprise.

contact us

Connect With Us

Request a demo learn how Metafore can transform your enterprise.