Cyber Essentials and your firewall: meeting the requirements with pfSense Plus

Updated August 2026 · Written by the Firewall Buddy team. Our own company (iTVerse Technology Services Ltd, which Firewall Buddy is part of) holds Cyber Essentials Plus — so this is the scheme as we live it, not just read about it. Certification itself comes from an approved assessor.

What Cyber Essentials actually asks of your firewall

Cyber Essentials is the NCSC-backed baseline that more and more UK contracts, insurers and supply chains require. It covers five control areas, and boundary firewalls is the first. Strip away the scheme language and the firewall requirements come down to: change every default password; block all unauthenticated inbound connections by default; have a documented business case for every rule that opens a port; make sure the firewall's admin interface isn't reachable from the internet (or is protected if it must be); and disable anything that opens ports automatically, like UPnP.

None of that is exotic. It is, however, exactly the housekeeping that ages badly on a firewall nobody looks at — which is why the firewall question section catches businesses out at renewal time.

How pfSense Plus maps to each requirement

Default-deny inbound: pfSense's WAN blocks unsolicited inbound traffic out of the box — the assessor's first question is answered before you start. Documented rules: every rule in pfSense takes a description field; we write the business justification into the rule itself, so your documentation lives where the config lives. Admin interface: the web GUI is never exposed to the WAN — management happens on the LAN or over VPN only, which satisfies the scheme without needing exceptions. Credentials: forced strong admin password, and unique per device. UPnP: off unless there's a written reason.

The same appliance also helps with the scheme's other areas: WireGuard VPN brings home workers inside your boundary, VLANs separate guest Wi-Fi and card machines from business systems, and pfBlockerNG cuts the malware noise reaching users in the first place.

The part people miss: it has to stay compliant

Cyber Essentials is renewed annually, and the failure mode we see isn't the initial setup — it's drift. A rule added 'temporarily' for a supplier and never removed; firmware nobody updated; the documentation that no longer matches the config. Our managed plans exist for precisely this: firmware kept current, rule changes logged with justifications, and a config that matches its paperwork when renewal comes round. The Professional plan's monthly written report is, in effect, your ongoing evidence file.

Getting there from here

If you're buying new: any Netgate appliance we sell can be delivered CE-aligned with Advanced setup (£349) — controls configured, rules documented, a summary sheet for your assessor. Already running something else? Our migration service rebuilds your rules with the justifications attached, which many customers find is the first time their firewall config and their paperwork have ever agreed. And if a question on the CE form has you stuck, ask us — no charge for pointing you straight.

Still not sure? Let us help — free

Two-minute quiz, or email us a quick description of your network and we'll give you an honest recommendation — even if it's the cheaper model.

Take the quiz → Ask us

Frequently asked questions

Is pfSense 'Cyber Essentials certified'?+
No product is — that's the key thing to understand. Cyber Essentials assesses how your organisation configures and manages its technology, not which brands you buy. A Netgate firewall running pfSense Plus fully supports every firewall-related requirement of the scheme; whether you pass depends on how it (and the rest of your IT) is set up.
Does a home worker need a separate firewall for Cyber Essentials?+
Under the current scheme, home workers' devices are in scope but their home routers generally are not — the software firewall on the device plus your corporate controls do the work. A common strong pattern is routing home workers through WireGuard VPN to the office firewall, so their traffic gets the same boundary protections as on-site staff.
Can you set up our Netgate firewall to be Cyber Essentials ready?+
Yes — our Advanced setup (£349) covers the firewall-side controls: default-deny inbound, documented and justified rules, admin interface locked away from the internet, strong unique credentials, and UPnP disabled. We'll also hand you the rule documentation your assessor will ask about. We're not a certification body, so the certificate itself comes from an approved assessor — but the firewall section won't be the thing that trips you up.
Do we need Cyber Essentials Plus, or is basic enough?+
Basic Cyber Essentials is self-assessed and is the common requirement in UK supply chains and for some insurance. CE Plus adds an independent technical audit of the same controls. The firewall configuration requirements are the same — Plus just means someone verifies them. Set the firewall up properly once and both routes are covered.