Horizon3 has received Cyber Essentials Plus certification for the AWS EU infrastructure behind its NodeZero platform, with the certificate issued on 22 September 2026 and the achievement formally announced today via Business Wire. For UK buyers weighing AI-native security platforms, that is a same-day news peg with a concrete procurement consequence attached.
Cyber Essentials Plus is not a marketing badge. It is a scheme backed by the UK’s National Cyber Security Centre (NCSC), and it carries direct weight in government and government-adjacent procurement. Its relevance to a Germany-hosted, AWS-based EU deployment points to a live category of decision facing UK and European enterprises right now: how to evidence supplier security for cloud platforms that sit outside domestic borders but serve regulated buyers.
Here is what the certification actually tells you about the infrastructure behind NodeZero, and, just as importantly, where the boundary of that assurance sits. Read it correctly and you gain a calibrated signal for your own due diligence. Read it loosely and you risk crediting the platform with protection it was never certified to provide.
What the UK’s Cyber Essentials Plus scheme actually tests
It is tempting to treat any government-backed certification as a full security audit. Cyber Essentials Plus is deliberately not that, and understanding why is the starting point for reading any vendor’s claim.
The scheme, developed and governed by the NCSC, runs on two tiers. The first, Cyber Essentials, is a self-assessment the organisation completes and an external assessor reviews. The second, the Plus tier, adds independent technical testing on top. That testing is what converts a self-declaration into a verified credential, because an assessor confirms by technical means that the controls actually hold up against common attacks.
The framework checks five control areas:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
These are commodity-threat defences. They address the basic hacking and phishing techniques that use widely available tools, not advanced monitoring, secure software development, multi-tenant cloud isolation, or threat-hunting. The scheme is engineered as a baseline, and that design is intentional.
How the testing actually works
The authoritative reference for current practice is the Cyber Essentials Plus Test Specification v3.2, dated 28 April 2025. It sets out what licensed certification bodies must verify, including that the assessed scope matches the applicant’s valid Cyber Essentials certificate and that the described scope corresponds to the real networks in use.
Here is the nuance that matters most to a buyer. Assessments are sampling-based. Assessors test representative samples of devices and systems, not every asset in the estate. The certificate therefore confirms that sampled assets met the five controls at the point of assessment.
For you, that reframes the credential entirely. It is a verified baseline snapshot at a moment in time, not a guarantee of continuous, comprehensive protection across all infrastructure. That distinction is the difference between a credential you can rely on and one you can over-read.
What Horizon3’s certificate covers, and what it does not
The specifics of Horizon3’s certificate are precise, and that precision cuts both ways. The certificate was issued to Horizon3.ai, Inc. on 22 September 2026 and is valid through 22 September 2027. It is scoped to the NodeZero AWS EU network and to employee home networks.
That EU network underpins NodeZero’s dedicated Germany-based deployment, which Horizon3 operates as a distinct EU data sovereignty site separate from its other instances. For a European buyer concerned with where data physically sits, the certification landing on exactly this environment is the relevant point.
Now the boundary. The certificate covers a partial organisation, not Horizon3’s entire service footprint, and the excluded elements are documented explicitly.
| In scope | Out of scope |
|---|---|
| NodeZero AWS EU network | Other NodeZero deployments |
| Employee home networks | Customer-deployed NodeZero Host nodes |
Certificate at a glance Issued 22 September 2026, valid through 22 September 2027. Scope: NodeZero AWS EU network and employee home networks. Excluded: other NodeZero deployments and customer-deployed NodeZero Host nodes.
What this means for you is concrete. If you deploy NodeZero outside the certified EU AWS network, or if you run customer-deployed Host nodes, you are working with infrastructure that sits outside the certified perimeter. That is a direct question to put to the vendor during procurement, not an assumption to make.
Scope documentation is the single most overlooked element of vendor security claims in procurement conversations. Horizon3 documenting its scope and exclusions openly is a transparency positive. The risk sits with buyers who do not read the fine print and attribute assurance to parts of the service the certificate never touched.
Worth noting on timing: the announcement was distributed via Business Wire on 28 September 2026, but earlier Horizon3 releases on 5 August 2026 and 25 August 2026 already referenced the same certification. The credential predates its dedicated announcement.
Why cloud security vendors are seeking this credential for EU deployments
Horizon3’s decision is not an isolated marketing move. It is an instance of a recognisable procurement logic that other cloud security vendors are following, and seeing the pattern gives the individual certificate its proper weight.
The driver is procurement policy. Cabinet Office Procurement Policy Note PPN 014 requires suppliers bidding for certain higher-risk central government contracts to hold Cyber Essentials or Cyber Essentials Plus, or to demonstrate equivalent controls, before award. That turns the badge into a practical gateway for selling into UK public-sector and government-adjacent markets, with NHS bodies, financial services firms, and large enterprises increasingly expecting it too.
Cabinet Office PPN 014 specifies that suppliers bidding for certain higher-risk central government contracts must demonstrate, prior to contract award, that they hold Cyber Essentials or Cyber Essentials Plus certification or can evidence equivalent controls.
The logic runs in three steps:
- PPN 014 creates the contractual requirement for higher-risk central government work.
- The vendor certifies the relevant infrastructure subset, in Horizon3’s case the EU-hosted deployment.
- The badge then functions as a recognised gateway signal in bid responses.
The cross-border angle explains why an EU deployment gets a UK credential. A vendor with a Germany-hosted environment applying a UK government-backed scheme to it produces a trust signal that UK and UK-adjacent buyers already recognise in their own due-diligence processes.
The regulatory narrative, and its limits
Vendors also attach a compliance story to the badge. They position it alongside the General Data Protection Regulation (GDPR) requirement for “appropriate technical and organisational measures” and the baseline technical control expectations under NIS2, the EU’s network and information security directive.
Be precise here. Cyber Essentials Plus is not a formal GDPR or NIS2 certification. It supports those narratives without constituting compliance under either. The NCSC’s own Cyber Essentials Supply Chain Playbook frames the badge as a due-diligence tool, not a comprehensive assurance instrument.
There is a documented risk in this structure. Because the scheme is enforced through contracts rather than law, practitioner commentary warns that some organisations optimise for passing the audit to reach contracts without building resilience beyond the five controls. For you, the presence of Cyber Essentials Plus signals a vendor has cleared the baseline procurement bar. It does not replace examining what higher-assurance standards they hold on top.
Reading Horizon3’s certification as a buyer signal, not a security guarantee
Pull the three threads together and a single, usable lens emerges. The framework is a deliberate baseline, the certificate covers a specific partial-organisation slice, and the procurement logic explains why vendors pursue it. Applied consistently, that lens works on any vendor’s Cyber Essentials Plus claim, not just this one.
Bring two questions to every certified vendor you evaluate:
Government cybersecurity procurement signals such as contract renewal patterns, compliance certification depth, and sovereign client rosters often reveal more about a vendor’s institutional credibility than headline-grabbing announcements, a dynamic that applies equally to UK public-sector buyers evaluating EU-hosted platforms.
- What exactly is in scope, and which parts of the service footprint are excluded?
- What supplementary standards and controls cover the remainder?
Horizon3’s transparency in documenting its scope and exclusions is the model for how a certification claim should be presented. When a vendor gives you that clarity, it hands you what you need to ask the right follow-on questions. When a vendor’s certification communication lacks that clarity, the absence is itself a due-diligence signal.
For UK and European enterprises procuring cloud-hosted security platforms, Cyber Essentials Plus on a defined EU infrastructure subset is a meaningful but bounded step. Treat it as a verified baseline, then point your next layer of diligence squarely at what sits outside the certified boundary.
This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.
