Cyber Essentials and your firewall: meeting the requirements with pfSense Plus
Updated August 2026 · Written by the Firewall Buddy team. Our own company (iTVerse Technology Services Ltd, which Firewall Buddy is part of) holds Cyber Essentials Plus — so this is the scheme as we live it, not just read about it. Certification itself comes from an approved assessor.
What Cyber Essentials actually asks of your firewall
Cyber Essentials is the NCSC-backed baseline that more and more UK contracts, insurers and supply chains require. It covers five control areas, and boundary firewalls is the first. Strip away the scheme language and the firewall requirements come down to: change every default password; block all unauthenticated inbound connections by default; have a documented business case for every rule that opens a port; make sure the firewall's admin interface isn't reachable from the internet (or is protected if it must be); and disable anything that opens ports automatically, like UPnP.
None of that is exotic. It is, however, exactly the housekeeping that ages badly on a firewall nobody looks at — which is why the firewall question section catches businesses out at renewal time.
How pfSense Plus maps to each requirement
Default-deny inbound: pfSense's WAN blocks unsolicited inbound traffic out of the box — the assessor's first question is answered before you start. Documented rules: every rule in pfSense takes a description field; we write the business justification into the rule itself, so your documentation lives where the config lives. Admin interface: the web GUI is never exposed to the WAN — management happens on the LAN or over VPN only, which satisfies the scheme without needing exceptions. Credentials: forced strong admin password, and unique per device. UPnP: off unless there's a written reason.
The same appliance also helps with the scheme's other areas: WireGuard VPN brings home workers inside your boundary, VLANs separate guest Wi-Fi and card machines from business systems, and pfBlockerNG cuts the malware noise reaching users in the first place.
The part people miss: it has to stay compliant
Cyber Essentials is renewed annually, and the failure mode we see isn't the initial setup — it's drift. A rule added 'temporarily' for a supplier and never removed; firmware nobody updated; the documentation that no longer matches the config. Our managed plans exist for precisely this: firmware kept current, rule changes logged with justifications, and a config that matches its paperwork when renewal comes round. The Professional plan's monthly written report is, in effect, your ongoing evidence file.
Getting there from here
If you're buying new: any Netgate appliance we sell can be delivered CE-aligned with Advanced setup (£349) — controls configured, rules documented, a summary sheet for your assessor. Already running something else? Our migration service rebuilds your rules with the justifications attached, which many customers find is the first time their firewall config and their paperwork have ever agreed. And if a question on the CE form has you stuck, ask us — no charge for pointing you straight.
Two-minute quiz, or email us a quick description of your network and we'll give you an honest recommendation — even if it's the cheaper model.