NodeZero Earns UK Cyber Essentials Plus for Its EU AWS Network

Horizon3's Cyber Essentials Plus certification for its NodeZero AWS EU infrastructure is a meaningful procurement signal for UK and European buyers, but its scoped, sampling-based assurance means reading the fine print is not optional.
By John Zadeh -
Cyber Essentials Plus certificate for NodeZero AWS EU dated 22 September 2026 against server rack backdrop
  • Horizon3's Cyber Essentials Plus certificate, issued 22 September 2026, is scoped exclusively to the NodeZero AWS EU network and employee home networks, with other NodeZero deployments and customer-deployed Host nodes explicitly excluded.
  • Cyber Essentials Plus tests only five baseline controls (firewalls, secure configuration, security update management, user access control, and malware protection) using sampling-based technical verification, making it a point-in-time snapshot rather than a continuous or comprehensive security guarantee.
  • UK Cabinet Office Procurement Policy Note PPN 014 requires Cyber Essentials or Cyber Essentials Plus for certain higher-risk central government contracts, which is the direct procurement logic behind why vendors apply the credential to EU-hosted infrastructure targeting UK buyers.
  • The certification is not a formal GDPR or NIS2 compliance instrument; it supports those regulatory narratives without constituting compliance under either framework.
  • Buyers should ask two questions of any certified vendor: exactly which infrastructure is in scope, and what higher-assurance standards cover the parts that are not, because scope documentation is the most commonly overlooked element of vendor security claims in procurement.
Summarise with AI:

Horizon3 has received Cyber Essentials Plus certification for the AWS EU infrastructure behind its NodeZero platform, with the certificate issued on 22 September 2026 and the achievement formally announced today via Business Wire. For UK buyers weighing AI-native security platforms, that is a same-day news peg with a concrete procurement consequence attached.

Cyber Essentials Plus is not a marketing badge. It is a scheme backed by the UK’s National Cyber Security Centre (NCSC), and it carries direct weight in government and government-adjacent procurement. Its relevance to a Germany-hosted, AWS-based EU deployment points to a live category of decision facing UK and European enterprises right now: how to evidence supplier security for cloud platforms that sit outside domestic borders but serve regulated buyers.

Here is what the certification actually tells you about the infrastructure behind NodeZero, and, just as importantly, where the boundary of that assurance sits. Read it correctly and you gain a calibrated signal for your own due diligence. Read it loosely and you risk crediting the platform with protection it was never certified to provide.

What the UK’s Cyber Essentials Plus scheme actually tests

It is tempting to treat any government-backed certification as a full security audit. Cyber Essentials Plus is deliberately not that, and understanding why is the starting point for reading any vendor’s claim.

The scheme, developed and governed by the NCSC, runs on two tiers. The first, Cyber Essentials, is a self-assessment the organisation completes and an external assessor reviews. The second, the Plus tier, adds independent technical testing on top. That testing is what converts a self-declaration into a verified credential, because an assessor confirms by technical means that the controls actually hold up against common attacks.

The framework checks five control areas:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

These are commodity-threat defences. They address the basic hacking and phishing techniques that use widely available tools, not advanced monitoring, secure software development, multi-tenant cloud isolation, or threat-hunting. The scheme is engineered as a baseline, and that design is intentional.

The 5 Core Controls of Cyber Essentials Plus

How the testing actually works

The authoritative reference for current practice is the Cyber Essentials Plus Test Specification v3.2, dated 28 April 2025. It sets out what licensed certification bodies must verify, including that the assessed scope matches the applicant’s valid Cyber Essentials certificate and that the described scope corresponds to the real networks in use.

Here is the nuance that matters most to a buyer. Assessments are sampling-based. Assessors test representative samples of devices and systems, not every asset in the estate. The certificate therefore confirms that sampled assets met the five controls at the point of assessment.

For you, that reframes the credential entirely. It is a verified baseline snapshot at a moment in time, not a guarantee of continuous, comprehensive protection across all infrastructure. That distinction is the difference between a credential you can rely on and one you can over-read.

What Horizon3’s certificate covers, and what it does not

The specifics of Horizon3’s certificate are precise, and that precision cuts both ways. The certificate was issued to Horizon3.ai, Inc. on 22 September 2026 and is valid through 22 September 2027. It is scoped to the NodeZero AWS EU network and to employee home networks.

That EU network underpins NodeZero’s dedicated Germany-based deployment, which Horizon3 operates as a distinct EU data sovereignty site separate from its other instances. For a European buyer concerned with where data physically sits, the certification landing on exactly this environment is the relevant point.

Now the boundary. The certificate covers a partial organisation, not Horizon3’s entire service footprint, and the excluded elements are documented explicitly.

In scope Out of scope
NodeZero AWS EU network Other NodeZero deployments
Employee home networks Customer-deployed NodeZero Host nodes

Certificate at a glance Issued 22 September 2026, valid through 22 September 2027. Scope: NodeZero AWS EU network and employee home networks. Excluded: other NodeZero deployments and customer-deployed NodeZero Host nodes.

What this means for you is concrete. If you deploy NodeZero outside the certified EU AWS network, or if you run customer-deployed Host nodes, you are working with infrastructure that sits outside the certified perimeter. That is a direct question to put to the vendor during procurement, not an assumption to make.

Scope documentation is the single most overlooked element of vendor security claims in procurement conversations. Horizon3 documenting its scope and exclusions openly is a transparency positive. The risk sits with buyers who do not read the fine print and attribute assurance to parts of the service the certificate never touched.

Worth noting on timing: the announcement was distributed via Business Wire on 28 September 2026, but earlier Horizon3 releases on 5 August 2026 and 25 August 2026 already referenced the same certification. The credential predates its dedicated announcement.

Why cloud security vendors are seeking this credential for EU deployments

Horizon3’s decision is not an isolated marketing move. It is an instance of a recognisable procurement logic that other cloud security vendors are following, and seeing the pattern gives the individual certificate its proper weight.

The driver is procurement policy. Cabinet Office Procurement Policy Note PPN 014 requires suppliers bidding for certain higher-risk central government contracts to hold Cyber Essentials or Cyber Essentials Plus, or to demonstrate equivalent controls, before award. That turns the badge into a practical gateway for selling into UK public-sector and government-adjacent markets, with NHS bodies, financial services firms, and large enterprises increasingly expecting it too.

Cabinet Office PPN 014 specifies that suppliers bidding for certain higher-risk central government contracts must demonstrate, prior to contract award, that they hold Cyber Essentials or Cyber Essentials Plus certification or can evidence equivalent controls.

The logic runs in three steps:

  1. PPN 014 creates the contractual requirement for higher-risk central government work.
  2. The vendor certifies the relevant infrastructure subset, in Horizon3’s case the EU-hosted deployment.
  3. The badge then functions as a recognised gateway signal in bid responses.

The cross-border angle explains why an EU deployment gets a UK credential. A vendor with a Germany-hosted environment applying a UK government-backed scheme to it produces a trust signal that UK and UK-adjacent buyers already recognise in their own due-diligence processes.

The regulatory narrative, and its limits

Vendors also attach a compliance story to the badge. They position it alongside the General Data Protection Regulation (GDPR) requirement for “appropriate technical and organisational measures” and the baseline technical control expectations under NIS2, the EU’s network and information security directive.

Be precise here. Cyber Essentials Plus is not a formal GDPR or NIS2 certification. It supports those narratives without constituting compliance under either. The NCSC’s own Cyber Essentials Supply Chain Playbook frames the badge as a due-diligence tool, not a comprehensive assurance instrument.

There is a documented risk in this structure. Because the scheme is enforced through contracts rather than law, practitioner commentary warns that some organisations optimise for passing the audit to reach contracts without building resilience beyond the five controls. For you, the presence of Cyber Essentials Plus signals a vendor has cleared the baseline procurement bar. It does not replace examining what higher-assurance standards they hold on top.

Reading Horizon3’s certification as a buyer signal, not a security guarantee

Pull the three threads together and a single, usable lens emerges. The framework is a deliberate baseline, the certificate covers a specific partial-organisation slice, and the procurement logic explains why vendors pursue it. Applied consistently, that lens works on any vendor’s Cyber Essentials Plus claim, not just this one.

Bring two questions to every certified vendor you evaluate:

Government cybersecurity procurement signals such as contract renewal patterns, compliance certification depth, and sovereign client rosters often reveal more about a vendor’s institutional credibility than headline-grabbing announcements, a dynamic that applies equally to UK public-sector buyers evaluating EU-hosted platforms.

  • What exactly is in scope, and which parts of the service footprint are excluded?
  • What supplementary standards and controls cover the remainder?

Horizon3’s transparency in documenting its scope and exclusions is the model for how a certification claim should be presented. When a vendor gives you that clarity, it hands you what you need to ask the right follow-on questions. When a vendor’s certification communication lacks that clarity, the absence is itself a due-diligence signal.

For UK and European enterprises procuring cloud-hosted security platforms, Cyber Essentials Plus on a defined EU infrastructure subset is a meaningful but bounded step. Treat it as a verified baseline, then point your next layer of diligence squarely at what sits outside the certified boundary.

This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.

Frequently Asked Questions

What is Cyber Essentials Plus certification and what does it test?

Cyber Essentials Plus is a UK government-backed scheme governed by the NCSC that independently verifies five baseline security controls: firewalls, secure configuration, security update management, user access control, and malware protection. Unlike the self-assessment Cyber Essentials tier, the Plus tier adds hands-on technical testing by a licensed assessor, converting a self-declaration into a verified credential.

What does Horizon3's Cyber Essentials Plus certificate actually cover?

The certificate, issued on 22 September 2026 and valid through 22 September 2027, covers the NodeZero AWS EU network and employee home networks only. Other NodeZero deployments and customer-deployed NodeZero Host nodes are explicitly out of scope, meaning infrastructure outside that boundary carries no assurance from this certificate.

Why are cloud security vendors pursuing Cyber Essentials Plus for EU deployments?

Cabinet Office Procurement Policy Note PPN 014 requires suppliers bidding for certain higher-risk UK central government contracts to hold Cyber Essentials or Cyber Essentials Plus certification before award, making it a practical procurement gateway. Vendors with EU-hosted infrastructure apply the UK credential to produce a recognised trust signal for UK and UK-adjacent buyers during bid responses.

Does Cyber Essentials Plus certification mean a vendor is GDPR or NIS2 compliant?

No. Cyber Essentials Plus supports GDPR and NIS2 compliance narratives by demonstrating baseline technical controls, but it is not a formal certification under either framework. The NCSC itself frames the badge as a due-diligence tool rather than a comprehensive assurance instrument.

How should procurement teams use a vendor's Cyber Essentials Plus certificate in due diligence?

Treat the certificate as a verified baseline snapshot for the specific scoped infrastructure, then ask two follow-on questions: which parts of the service footprint are excluded from the certificate, and what supplementary standards cover the remainder. A vendor that documents scope and exclusions openly, as Horizon3 has done, provides the clarity needed to direct the next layer of diligence correctly.

John Zadeh
By John Zadeh
Founder & CEO
John Zadeh is an investor and media entrepreneur with over a decade in financial markets. As Founder and CEO of StockWire X and Discovery Alert, Australia's largest mining news site, he's built an independent financial publishing group serving investors across the globe.
Learn More

Breaking ASX Alerts Direct to Your Inbox

Join +20,000 subscribers receiving alerts.

Join thousands of investors who rely on StockWire X for timely, accurate market intelligence.

About the Publisher