Cyber Essentials Pathways offer large, complex organisations a potential route to Cyber Essentials Plus certification when prescribed technical controls cannot be implemented in the standard way. By allowing alternative controls to be assessed against the same security outcomes, the approach could help organisations running legacy or unsupported enterprise software demonstrate equivalent protection through evidence, layered controls and rigorous assessment.
The software no one is supposed to talk about
Walk through the finance floors of any FTSE 250 company, any NHS trust, or any Whitehall department running critical operations and you will almost certainly find it: software that the vendor no longer patches, quietly holding up the very systems that the country depends on.
Cyber Essentials was designed to improve the cyber posture of a nation. To work at scale, it had to be simple, clear and unequivocal. That simplicity has been one of its great strengths. It has also left little room for the complexities of large enterprise environments, particularly those built around legacy software and layered security controls.
For years, organisations have understood the tension. What they have lacked is a practical way to resolve it.
That may now be changing.
A quiet revolution at the NCSC
The National Cyber Security Centre, the UK’s official cyber authority, born from GCHQ, has done something that will reverberate through boardrooms, audit committees and procurement teams for years.
It has, in effect, acknowledged complexity.
Following an 18-month proof of concept, the NCSC is now moving what it calls Cyber Essentials Pathways into a broader, carefully managed phase. It is an emerging route to Cyber Essentials Plus certification that allows complex organisations to demonstrate an equivalent or better level of cyber protection, even where they cannot meet the standard technical controls in the prescribed way.
This is not a loophole. It is not a get-out-of-jail-free card. And it is not yet an open door.
It is something far more important: evidence that the security of an organisation cannot be reduced to a single question: “Did you apply the patch?”
The problem nobody wanted to name
For more than a decade, a quiet tension has been building in enterprise technology.
On one side: Oracle and SAP, the backbone of enterprise Britain. ERP systems that run payroll, supply chains and financial reporting for organisations employing hundreds of thousands of people. Systems so heavily customised, so deeply embedded in operational processes, that upgrading them carries a business risk and cost that many boards simply cannot justify.
On the other: the conventional wisdom of cyber compliance, which has often treated vendor-issued security patches, applied within defined windows, as the clearest evidence that risk is being managed.
Patching matters. But it is only one part of a much broader security posture that includes governance, access control, system hardening, network resilience, monitoring, threat detection and incident response.
When mainstream vendor support ends, security updates may become limited, require additional support arrangements or cease altogether. Under the traditional Cyber Essentials route, organisations that cannot meet the prescribed security update requirements may struggle to demonstrate compliance, regardless of the other protections they have put in place.
The result? Organisations forced to choose between business stability and cyber certification. Many chose stability and hoped no one looked too closely.
The rise of the alternative support economy
Into this gap stepped an industry that the mainstream technology press has largely ignored: third-party support providers.
These are firms, among them Spinnaker Support, a specialist in Oracle, SAP and VMware environments, that offer an alternative model for maintaining and supporting enterprise software outside the vendor’s standard support programme. That model covers the full support relationship, from resolving operational issues and supporting customisations to providing technical guidance and helping organisations maintain stable, reliable systems.
Security is a core component. Not patches in the traditional sense, but something arguably more sophisticated: layered security intelligence, vulnerability analysis, compensating controls and hardening advice, built around a deep understanding of how these enterprise platforms actually behave in production.
The sector has grown substantially, driven by organisations unwilling to pay ever-increasing vendor maintenance support fees for software that already does precisely what they need it to do without the need for updates or upgrades.
But it has operated under a shadow. Security sceptics, and occasionally vendors with a commercial interest in the argument, have long questioned whether any amount of compensating controls could substitute for vendor patches.
The NCSC has begun to change the terms of that debate.
What do Cyber Essentials Pathways mean for complex organisations?
The Cyber Essentials Pathways approach does not endorse third-party support. The NCSC is careful about that, and any honest reading of the documentation confirms it.
During the proof of concept, the NCSC worked with 22 organisations and their certification bodies to test whether alternative controls could be assessed consistently and defensibly. One participating organisation successfully achieved Cyber Essentials Plus through the Pathways approach. The principle is no longer theoretical. It has worked in practice, even as the model continues to be refined.
What Pathways does, and this is the crux of everything, is demonstrate that equivalent protection can be formally evaluated and, where the evidence satisfies the appropriate assessment process, form the basis for Cyber Essentials Plus certification.
The philosophical shift is profound.
The old way: “Have you applied the prescribed controls?”
The new way: “Can you demonstrate that your overall security posture achieves the same protective outcome?”
Organisations operating unpatched enterprise software now have evidence that an NCSC-backed assessment approach can provide a route for making that argument rigorously, evidentially and with a certification body able to assess it.
This is not a minor technical adjustment. It signals a potential reorientation in how cyber assurance can work for large, complex UK organisations.
Why it matters beyond the checkbox
The implications extend well beyond Cyber Essentials certification itself.
Cyber Essentials has become an important baseline across UK government supply chains and is increasingly considered in enterprise procurement and third-party assurance. The ability to demonstrate Pathways-equivalent protection could therefore carry weight far beyond the certificate itself.
More broadly, the NCSC’s move reflects a growing consensus in information security: that prescriptive, control-based compliance is a poor proxy for actual risk reduction.
The organisations that are genuinely secure are rarely those that have simply ticked every box on a vendor’s checklist. They are the ones that understand their threat landscape, implement layered defences, monitor continuously, and have the governance maturity to demonstrate what they do and why.
Cyber Essentials Pathways, for all the quiet language in which the approach is described, represent a government-backed recognition that equivalent security outcomes can sometimes be demonstrated through alternative controls.
The cyber arms race is not about patches. It never was.
The uncomfortable truth that few vendors want to confront is this: a patch is not, in itself, security. It is one tool in a broader exposure management framework that, for complex enterprise environments, must include network segmentation, privileged access control, continuous monitoring, threat intelligence, endpoint detection, configuration hardening and perhaps most critically, the organisational processes to bind all of these together.
For organisations running Oracle, SAP and VMware beyond mainstream vendor support, this toolkit has been available. What has been missing is a recognised framework within which to present it as credible assurance.
The NCSC is now building that framework. The organisations that move first to demonstrate equivalent protection will not just satisfy their auditors. They will redefine what security leadership looks like in the modern enterprise, grounded in evidence, layered protection and a clear understanding of how risk is managed in practice. It is an approach Spinnaker Support has championed for more than a decade.