Trust is fundamental to healthcare technology. Whether managing incidents, policies, audits or patient feedback, healthcare organisations need confidence that the software they rely on is supported by robust cyber security practices.
We're proud to announce that MEG has achieved Cyber Essentials Plus certification, the highest level of assurance under the UK Government-backed Cyber Essentials scheme.
Unlike the standard Cyber Essentials certification, Cyber Essentials Plus requires an independent technical assessment of an organisation's cyber security controls. Rather than relying solely on a self-assessment questionnaire, certified organisations undergo testing to verify that key security measures are operating effectively in practice.
For MEG, this certification demonstrates our continued commitment to protecting the systems, information and services that support healthcare quality, compliance and clinical governance.
Going Beyond Self-Assessment
Cyber Essentials was introduced by the UK Government to help organisations protect themselves against the most common cyber threats. It establishes a recognised baseline of cyber security controls covering areas such as secure configuration, access control, malware protection, firewalls and software updates.
Cyber Essentials Plus builds on these requirements by adding an independent technical audit. Certified assessors test an organisation's environment to verify that these controls are not only documented but are also working effectively.
For organisations evaluating software providers, this additional level of verification provides greater assurance that cyber security controls have been independently validated.
Learn more about Cyber Essentials Plus on the official website
The Importance of Independent Security Assurance
Healthcare organisations operate in an environment where cyber resilience is essential. Patient information, operational continuity and regulatory compliance all depend on secure digital systems and trusted technology partners.
As procurement teams and governance leaders increasingly assess the cyber security posture of software vendors, independently verified certifications provide valuable evidence that security is embedded into organisational processes rather than simply documented in policy.
Cyber Essentials Plus helps demonstrate that an organisation's cyber security controls have been externally assessed against a recognised government-backed standard, giving customers additional confidence during supplier evaluation and procurement.
Cyber Essentials vs Cyber Essentials Plus
While both certifications are based on the same five technical security controls, the level of assurance they provide is different. Cyber Essentials is achieved through a verified self-assessment, whereas Cyber Essentials Plus includes an independent technical assessment to validate that those controls are working effectively in practice.
Comparison Table: Cyber Essentials vs Cyber Essentials Plus
For healthcare organisations assessing software suppliers, Cyber Essentials Plus offers an additional level of confidence because an independent assessor has verified the effectiveness of the organisation's cyber security controls, rather than relying solely on self-declared compliance.
Cyber Essentials Plus complements the wider governance and security framework that underpins the MEG platform.
Alongside our existing certifications and attestations, including:
ISO/IEC 27001:2022 - Information Security Management Systems
ISO/IEC 27017:2015 - Code of practice for information security controls for cloud services
ISO/IEC 27018:2019 - Code of practice for protection of personally identifiable information in public clouds
ISO/IEC 42001:2023 - Artificial Intelligence Management Systems
ISO 9001:2015 - Quality Management Systems
NHS Data Security and Protection Toolkit (DSPT)
SOC 2 Type II - System and Organization Controls 2, Type II
Cyber Essentials Plus reinforces our ongoing commitment to protecting customer information while supporting healthcare organisations with a secure, reliable quality management platform.
Together, these certifications and attestations demonstrate that security, privacy and responsible AI governance are integrated into how MEG develops, delivers and continually improves its software.
View our certifications and attestations
What This Means for MEG Customers
For existing customers, Cyber Essentials Plus provides further independent assurance that MEG continues to invest in maintaining strong cyber security practices across its organisation.
For healthcare providers evaluating quality management software, it offers another layer of confidence that cyber security is taken seriously and independently assessed as part of our wider governance framework.
While no certification can eliminate cyber risk entirely, independent verification demonstrates an ongoing commitment to maintaining recognised security standards and continually strengthening organisational resilience.
Security Is a Continuous Commitment
Achieving Cyber Essentials Plus is an important milestone, but it is not an end point. Cyber security is an ongoing process of assessment, improvement and vigilance. As threats continue to evolve, so too must the controls, governance and processes that organisations use to protect their systems and data.
At MEG, we remain committed to continually strengthening our security posture while providing healthcare organisations with a trusted platform for quality, compliance and clinical governance.
βAchieving Cyber Essentials Plus provides our customers with independent assurance that our security controls are not just documented, but effectively verified against robust, government-backed standards. This demonstrates our unwavering commitment to protecting the systems and patient data that our partners rely on. Itβs an essential step in ensuring we remain a secure and dependable partner in healthcare quality and governance.β
Frequently Asked Questions
-
Cyber Essentials Plus is the highest level of certification within the UK Government-backed Cyber Essentials scheme. It includes an independent technical assessment that verifies an organisation has implemented effective cyber security controls to defend against common cyber threats.
-
Cyber Essentials is based on a self-assessment that confirms an organisation has implemented the required security controls.
Cyber Essentials Plus includes an additional independent technical audit, where assessors verify that those controls are operating effectively through testing.
-
Healthcare organisations rely on software providers to protect sensitive information and support critical services. When evaluating technology suppliers, independently verified cyber security certifications can provide additional assurance that recognised security controls have been implemented and tested.
-
No. The two certifications serve different purposes.ISO/IEC 27001 is an international standard for Information Security Management Systems that focuses on managing information security risks across an organisation.
Cyber Essentials Plus focuses specifically on verifying technical controls designed to defend against common cyber attacks. Many organisations implement both as part of a broader cyber security strategy.
-
Cyber Essentials Plus is a voluntary certification. However, many public sector organisations and NHS procurement frameworks increasingly recognise Cyber Essentials as an important indicator of cyber security maturity, and some contracts may require suppliers to hold Cyber Essentials certification.
-
MEG's Cyber Essentials Plus certification provides independent assurance that our cyber security controls have been technically assessed against a recognised government-backed standard. It reinforces our commitment to maintaining a secure platform for healthcare quality, compliance and clinical governance while complementing our wider security and governance certifications.
