MEG Achieves Cyber Essentials Plus Certification

Trust is fundamental to healthcare technology. Whether managing incidents, policies, audits or patient feedback, healthcare organisations need confidence that the software they rely on is supported by robust cyber security practices.

We're proud to announce that MEG has achieved Cyber Essentials Plus certification, the highest level of assurance under the UK Government-backed Cyber Essentials scheme.

Unlike the standard Cyber Essentials certification, Cyber Essentials Plus requires an independent technical assessment of an organisation's cyber security controls. Rather than relying solely on a self-assessment questionnaire, certified organisations undergo testing to verify that key security measures are operating effectively in practice.

For MEG, this certification demonstrates our continued commitment to protecting the systems, information and services that support healthcare quality, compliance and clinical governance.

Going Beyond Self-Assessment

Cyber Essentials was introduced by the UK Government to help organisations protect themselves against the most common cyber threats. It establishes a recognised baseline of cyber security controls covering areas such as secure configuration, access control, malware protection, firewalls and software updates.

Cyber Essentials Plus builds on these requirements by adding an independent technical audit. Certified assessors test an organisation's environment to verify that these controls are not only documented but are also working effectively.

For organisations evaluating software providers, this additional level of verification provides greater assurance that cyber security controls have been independently validated.

Learn more about Cyber Essentials Plus on the official website

The Importance of Independent Security Assurance

Healthcare organisations operate in an environment where cyber resilience is essential. Patient information, operational continuity and regulatory compliance all depend on secure digital systems and trusted technology partners.

As procurement teams and governance leaders increasingly assess the cyber security posture of software vendors, independently verified certifications provide valuable evidence that security is embedded into organisational processes rather than simply documented in policy.

Cyber Essentials Plus helps demonstrate that an organisation's cyber security controls have been externally assessed against a recognised government-backed standard, giving customers additional confidence during supplier evaluation and procurement.

Cyber Essentials vs Cyber Essentials Plus 

While both certifications are based on the same five technical security controls, the level of assurance they provide is different. Cyber Essentials is achieved through a verified self-assessment, whereas Cyber Essentials Plus includes an independent technical assessment to validate that those controls are working effectively in practice.

Comparison Table: Cyber Essentials vs Cyber Essentials Plus

Comparison Table: Cyber Essentials vs Cyber Essentials Plus

For healthcare organisations assessing software suppliers, Cyber Essentials Plus offers an additional level of confidence because an independent assessor has verified the effectiveness of the organisation's cyber security controls, rather than relying solely on self-declared compliance. 

Cyber Essentials Plus complements the wider governance and security framework that underpins the MEG platform.

Alongside our existing certifications and attestations, including:

  • ISO/IEC 27001:2022 - Information Security Management Systems 

  • ISO/IEC 27017:2015 - Code of practice for information security controls for cloud services

  • ISO/IEC 27018:2019 - Code of practice for protection of personally identifiable information in public clouds

  • ISO/IEC 42001:2023 - Artificial Intelligence Management Systems

  • ISO 9001:2015 - Quality Management Systems

  • NHS Data Security and Protection Toolkit (DSPT)

  • SOC 2 Type II - System and Organization Controls 2, Type II 

Cyber Essentials Plus reinforces our ongoing commitment to protecting customer information while supporting healthcare organisations with a secure, reliable quality management platform.

Together, these certifications and attestations demonstrate that security, privacy and responsible AI governance are integrated into how MEG develops, delivers and continually improves its software.

View our certifications and attestations

What This Means for MEG Customers

For existing customers, Cyber Essentials Plus provides further independent assurance that MEG continues to invest in maintaining strong cyber security practices across its organisation.

For healthcare providers evaluating quality management software, it offers another layer of confidence that cyber security is taken seriously and independently assessed as part of our wider governance framework.

While no certification can eliminate cyber risk entirely, independent verification demonstrates an ongoing commitment to maintaining recognised security standards and continually strengthening organisational resilience.


Security Is a Continuous Commitment

Achieving Cyber Essentials Plus is an important milestone, but it is not an end point. Cyber security is an ongoing process of assessment, improvement and vigilance. As threats continue to evolve, so too must the controls, governance and processes that organisations use to protect their systems and data.

At MEG, we remain committed to continually strengthening our security posture while providing healthcare organisations with a trusted platform for quality, compliance and clinical governance.

β€œAchieving Cyber Essentials Plus provides our customers with independent assurance that our security controls are not just documented, but effectively verified against robust, government-backed standards. This demonstrates our unwavering commitment to protecting the systems and patient data that our partners rely on. It’s an essential step in ensuring we remain a secure and dependable partner in healthcare quality and governance.”
— Mark O’Reilly (Chief Information Officer, MEG)

Frequently Asked Questions