Cyber Essentials deadline for criminal law firms: what you need to know before 1 October 2025

22/08/25 Wavenet
Law IT

From 1 October 2025, all criminal law firms in the UK will be required to hold Cyber Essentials certification. This new mandate is part of a broader push to strengthen cyber security within the legal sector and protect sensitive case data from the growing risk of cyber attacks.

If your firm has not yet started preparing, the time to act is now.

Why this matters

Criminal law firms handle highly sensitive information, client data, case files, court evidence, and communications that, if compromised, could have serious legal, reputational, and even personal consequences.

In recent years, the legal sector has become a prime target for cyber criminals, with ransomware, phishing, and data theft increasing in both frequency and sophistication. The introduction of this requirement recognises that cyber resilience is no longer optional, especially for firms working within the criminal justice system.

What is Cyber Essentials?

Cyber Essentials is a government-backed certification developed by the National Cyber Security Centre (NCSC). It sets out a basic but essential set of technical controls to protect organisations from common online threats.

  • Cyber Essentials – a self-assessment covering five key technical controls.
  • Cyber Essentials Plus – an advanced certification that includes an independent technical audit.

What does your firm need to do?

1. Understand the requirements

  • Review the five technical control areas: firewalls, secure configuration, user access control, malware protection, and patch management.
  • Consider whether you need Cyber Essentials or Cyber Essentials Plus, based on the nature of your work and data.

2. Audit your current systems

  • Identify gaps in your cyber defences.
  • A pre-assessment by a certified body can help you understand what’s needed to comply.

3. Implement changes

  • Work with internal IT teams or external consultants to make the necessary changes in infrastructure, processes, and policies.

4. Get certified

  • Once you're confident your systems meet the requirements, apply for certification through a recognised Certification Body.

5. Maintain and review

  • Certification is valid for 12 months. Make sure your defences stay up to date and build cyber security into your ongoing risk management practices.

The consequences of non-compliance

  • Ineligibility for certain legal aid or government-contracted work.
  • Increased scrutiny from regulators.
  • Loss of trust from clients and partners.
  • Higher cyber insurance premiums, or denial of coverage altogether.

Benefits beyond compliance

  • Reduced risk of cyber incidents.
  • Improved client confidence.
  • Demonstrated commitment to data protection.
  • Stronger positioning for tenders and contracts.

Don’t leave it too late

Certification can take time, especially if your systems need significant updates. Starting now ensures you’re not rushing at the last minute or risking non-compliance.

Start your Cyber Essentials journey here.

Legal, Cyber Security, CyberGuard, Blogs, Cyber Essentials

Latest blogs

See all posts
Placeholder thumbnail
Business continuity software: from compliance tool to strategic advantage

For many organisations, business continuity software still sits in the category of “necessary but non-essential”, a line item justified by regulation or audit, rather than by value. Too often, it’s viewed as an insurance policy that rarely gets used and delivers little measurable return. That perception is understandable. But it’s also fundamentally flawed. After more than three decades working across business continuity, operational resilience, and crisis management, I’ve seen first-hand how organisations behave under pressure. I’ve also worked with a wide range of continuity platforms, some impressive, others far less so. What has become increasingly clear is this: when the right software is implemented well, it materially strengthens an organisation’s ability to withstand disruption. And the larger and more complex the organisation, the greater that advantage becomes. Clarity in the moments that matter most Disruption compresses time and amplifies uncertainty. In those moments, resilience is not about having a document on a shelf, it’s about having absolute clarity on what needs to happen next. When an incident unfolds, leaders and response teams must be able to answer critical questions immediately: What actions need to be taken, and in what order? Who needs to be informed, and what do they need to know? Which services are truly critical and must be prioritised? Where and how will those services be recovered? And if recovery isn’t possible, what is the agreed fallback? Most organisations already hold the answers to these questions, but they’re scattered across spreadsheets, documents, and systems, often owned by different teams and updated at different times. In a crisis, that fragmentation quickly becomes a liability. This is where business continuity software proves its value. At its best, business continuity software does far more than store plans. It helps organisations understand themselves. By capturing and structuring information on critical services, recovery objectives, and the dependencies that underpin them, these platforms provide visibility that simply isn’t achievable through manual approaches alone. Technology, suppliers, facilities, data, and key people can all be mapped in a way that shows not just what’s important, but why it’s important and what it depends on. This insight enables organisations to create clear, actionable response strategies, playbooks, and contact groups that can be relied upon under pressure. It also allows teams to challenge assumptions, identify single points of failure, and uncover hidden risks before an incident exposes them. Many modern platforms also support real-time dependency analysis and data-gap reporting. This makes it possible to visualise upstream and downstream impacts and quickly understand the consequences of disruption. Attempting this level of analysis using spreadsheets or disconnected documents is slow, inefficient, and highly prone to human error, particularly during an incident. A single source of truth, when you need it most Another often overlooked benefit of business continuity software is the ability to act as a central, trusted source of truth. When offices are inaccessible, internal systems are unavailable, or teams are working remotely, continuity information still needs to be accessible. Secure, off-site platforms, typically available via both web browser and mobile, ensure that plans, contacts, and response information remain available even when the organisation itself is under strain. In practice, this accessibility can be the difference between a coordinated response and a reactive scramble. How business continuity software supports resilience Increasingly, business continuity software is being used not just to support response, but to underpin broader operational resilience objectives. Platforms such as Shadow-Planner, for example, are designed to help organisations move beyond static documentation and treat resilience as a living capability. By bringing together critical service identification, dependency mapping, recovery planning, and crisis response within a single environment, such tools help organisations maintain a clear, current view of their operational risk landscape. Used effectively, business continuity software supports better decision-making, clearer accountability, and faster mobilisation during disruption. It reduces reliance on individual knowledge, simplifies complexity, and helps ensure that the right information is available to the right people at the right time. Key takeaways Business continuity software should not be viewed as a compliance artefact or an emergency-only tool. When implemented and maintained properly, it becomes a strategic enabler, one that reduces risk, strengthens preparedness, and supports confident, coordinated action when disruption occurs. In an environment where resilience is increasingly scrutinised by regulators, customers, and boards alike, the real value of these platforms lies not in the software itself, but in the organisational clarity they enable. The right business continuity software doesn’t just help organisations respond to incidents. It helps make them stronger. By embedding resilience into everyday operations, it improves visibility of critical services, keeps plans accurate and actionable, and supports better decision-making. Business continuity becomes part of how the organisation operates, not just something it turns to in a crisis. About the author Colin Jeffs MBCI transitioned into business continuity from IT project management, where resilience was a core requirement of system implementation. He has over 30 years’ experience in business continuity, operational resilience, and crisis management, holding senior leadership roles within major financial institutions in the City of London. Colin now leads Wavenet’s award-winning operational resilience consulting and software division and co-designed the latest version of Shadow-Planner.

Read more

Stay service-savvy

Get all the latest news and insights straight to your inbox.