Install any skill in seconds. Free to start, no credit card required.
Get Started Free →UK NCSC Cyber Essentials Plus (CE+) v3.3 Danzell expert. Reference-depth framework plugin with assessment, scope determination, and evidence checklist — backed by the SCF crosswalk. Five core controls: Firewalls, Secure Configuration, User Access Control (MFA mandatory for all cloud services), Malware Protection, and Patch Management.
.claude/skills/grcengclub-cyber-essentials-plus-expert/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 4% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 24% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 65% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 128% | 0% |
| case-21 | ✗→✓ | ▲ Improved | -6% | 0% |
Reference-depth expertise for UK NCSC Cyber Essentials Plus (CE+) v3.3 Danzell (effective 27 April 2026). This plugin bundles the SCF crosswalk (26 SCF controls → 5 CE+ controls) with framework-specific context.
emea-gbr-cyber-essentials-requirements-3-3Cyber Essentials Plus is a UK government-backed certification scheme that requires organisations to demonstrate they have implemented five foundational technical security controls: Firewalls, Secure Configuration, User Access Control, Malware Protection, and Patch Management. CE+ is the independently-verified tier — unlike self-assessed Cyber Essentials, an accredited assessor conducts hands-on technical testing of the organisation's systems to verify the controls are in place and effective. The scheme is mandated for UK government supply chain contracts involving personal data or sensitive information, and is widely adopted as a baseline security standard across UK public and private sector organisations.
Any organisation operating in the UK, or supplying to UK government, can pursue CE+ certification. There is no revenue, headcount, or sector threshold — sole traders through FTSE 100 companies all use the same question set. The certification applies to a defined boundary chosen by the applicant; the boundary must include all devices that can access organisational data or services. UK government contracts handling personal data or sensitive information require CE+ as a minimum; some contracts (particularly MOD and intelligence community supply chain) require Cyber Essentials Plus specifically. There is no territorial carve-out for organisations headquartered outside the UK if they operate systems within a UK boundary or bid for UK government contracts.
The NCSC owns the Cyber Essentials scheme and sets the technical requirements. The IASME Consortium manages the certification body network and accredits assessors. Enforcement is indirect — there is no regulatory penalty for not holding CE+ unless a contract or regulatory condition requires it. UK government procurement rules (published by DSIT / Cabinet Office) mandate CE+ for relevant contracts; failure to maintain certification can result in contract termination or disqualification from future tenders. Maximum financial exposure therefore flows from contract loss rather than direct fines.
/cyber-essentials-plus:assess before a GDPR gap assessment to avoid re-covering the same ground./grc-engineer:map-controls-unified to identify overlaps./cyber-essentials-plus:scope — determine applicability and define certification boundary/cyber-essentials-plus:assess — run a gap assessment against all five controls/cyber-essentials-plus:evidence-checklist — enumerate evidence requirements by controlAll three delegate to /grc-engineer:gap-assessment with SCF framework ID emea-gbr-cyber-essentials-requirements-3-3 for the control-by-control mechanics, and wrap the results in CE+-specific terminology.
Full-depth plugins add framework-specific workflow commands tied to the audit ritual. Candidates for CE+:
/cyber-essentials-plus:question-set — walk through the Danzell v3.3 question set interactively and pre-populate answers from connector evidence/cyber-essentials-plus:assessor-prep — generate the assessor pack (asset inventory, network diagram, firewall exports, patch report) ready for the technical verification visit/cyber-essentials-plus:boundary-review — help the organisation define and justify their certification boundary, flag devices that must be included, and identify candidates for explicit exclusion/cyber-essentials-plus:mfa-audit — enumerate all cloud services in scope and verify MFA is enforced on every one, given the mandatory MFA requirement under Danzell v3.3| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-18 | pass→pass | 19,492 | 13,107 | -33% | 1 | 1 | 0% | 2,878 | 3,748 | +30% | 0 | 0 | — |
case-11 | pass→pass | 11,870 | 8,533 | -28% | 1 | 1 | 0% | 1,736 | 3,165 | +82% | 0 | 0 | — |
case-19 | pass→pass | 16,759 | 9,487 | -43% | 1 | 1 | 0% | 2,340 | 3,215 | +37% | 0 | 0 | — |
case-20 | pass→pass | 13,737 | 8,368 | -39% | 1 | 1 | 0% | 2,111 | 3,167 | +50% | 0 | 0 | — |
case-01 | fail→pass | 36,974 | 54,436 | +47% | 1 | 1 | 0% | 5,682 | 5,892 | +4% | 0 | 0 | — |
case-12 | pass→pass | 16,431 | 12,182 | -26% | 1 | 1 | 0% | 2,533 | 3,697 | +46% | 0 | 0 | — |
case-02 | pass→pass | 15,586 | 18,794 | +21% | 1 | 1 | 0% | 2,246 | 3,247 | +45% | 0 | 0 | — |
case-03 | pass→pass | 13,853 | 10,992 | -21% | 1 | 1 | 0% | 2,077 | 3,600 | +73% | 0 | 0 | — |
case-04 | pass→pass | 14,957 | 11,928 | -20% | 1 | 1 | 0% | 2,259 | 3,745 | +66% | 0 | 0 | — |
case-05 | pass→pass | 9,453 | 8,172 | -14% | 1 | 1 | 0% | 1,563 | 3,098 | +98% | 0 | 0 | — |
case-06 | fail→pass | 11,724 | 2,726 | -77% | 1 | 1 | 0% | 1,830 | 2,262 | +24% | 0 | 0 | — |
case-07 | pass→pass | 12,980 | 11,812 | -9% | 1 | 1 | 0% | 1,962 | 3,703 | +89% | 0 | 0 | — |
case-08 | fail→pass | 8,793 | 3,064 | -65% | 1 | 1 | 0% | 1,396 | 2,302 | +65% | 0 | 0 | — |
case-09 | pass→pass | 3,138 | 4,176 | +33% | 1 | 1 | 0% | 449 | 2,438 | +443% | 0 | 0 | — |
case-10 | pass→pass | 11,492 | 11,321 | -1% | 1 | 1 | 0% | 1,733 | 3,619 | +109% | 0 | 0 | — |
case-13 | fail→pass | 6,564 | 2,840 | -57% | 1 | 1 | 0% | 981 | 2,239 | +128% | 0 | 0 | — |
case-14 | pass→pass | 5,825 | 9,768 | +68% | 1 | 1 | 0% | 870 | 3,375 | +288% | 0 | 0 | — |
case-15 | pass→fail | 13,787 | 16,533 | +20% | 1 | 1 | 0% | 2,550 | 4,767 | +87% | 0 | 0 | — |
case-16 | pass→pass | 14,717 | 13,992 | -5% | 1 | 1 | 0% | 2,534 | 4,128 | +63% | 0 | 0 | — |
case-17 | pass→pass | 14,129 | 13,464 | -5% | 1 | 1 | 0% | 2,096 | 3,885 | +85% | 0 | 0 | — |
case-21 | fail→pass | 15,887 | 2,373 | -85% | 1 | 1 | 0% | 2,362 | 2,214 | -6% | 0 | 0 | — |
case-22 | pass→pass | 9,024 | 6,033 | -33% | 1 | 1 | 0% | 1,354 | 2,605 | +92% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +18 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.