If you run a UK business, you've probably heard the phrase 'Cyber Essentials' from a client, your insurer or a tender document — usually with very little explanation of what it actually means. This guide fixes that, in plain English, in under ten minutes.
By the end you'll know what the certification covers, whether you genuinely need it, what it typically costs, and the quickest way to find out if your business would pass today.
What is Cyber Essentials, in one sentence?
Cyber Essentials is a UK government-backed certification, run by IASME on behalf of the National Cyber Security Centre, that proves your business has the basic technical controls in place to stop the most common cyber attacks.
It's deliberately not a deep, complex framework like ISO 27001. It targets the boring fundamentals that, in practice, would block the vast majority of attacks aimed at UK SMEs.
The five control areas it covers
Cyber Essentials focuses on five technical control areas. If you get these right, you'll be in a much better place than most small businesses in the UK.
- Firewalls — every internet-connected device is protected by a properly configured firewall.
- Secure configuration — devices and software are set up to reduce attack surface (no default passwords, no unused accounts, no unnecessary services).
- User access control — accounts have only the privileges they need, with multi-factor authentication on cloud services and admin accounts.
- Malware protection — anti-malware or application allow-listing is in place on every in-scope device.
- Security update management — operating systems and applications are patched within 14 days of a high or critical fix.
Cyber Essentials vs Cyber Essentials Plus
There are two levels. Cyber Essentials is a verified self-assessment: you answer a structured question set and an assessor reviews it. Cyber Essentials Plus is the same scope, but with an independent hands-on technical audit on a sample of your devices and cloud services.
Most UK SMEs start with the standard tier and move to Plus when a contract, client or insurer requires it. If you're not sure which is right for you, our team can talk you through it in 30 minutes.
Related service
See our Cyber Essentials certification service
We handle scope, evidence and remediation so you certify first time — no jargon, fixed price.
Explore See our Cyber Essentials certification serviceDo I actually need Cyber Essentials?
No UK business is legally required to hold Cyber Essentials. In practice, you should seriously consider it if any of the following apply:
- You bid for UK central government contracts that handle personal or sensitive information — it's mandatory.
- You're in the supply chain of a larger organisation that mandates it (very common in legal, finance, manufacturing and professional services).
- Your cyber insurance renewal questionnaire is asking about it — many UK underwriters now treat it as the baseline.
- You want a credible, recognisable way to show clients you take security seriously, without committing to a 12-month ISO project.
If none of those apply today but at least one is likely within 12 months, certifying early is almost always cheaper than scrambling later.
What does it cost?
The certification fee itself is small. The real cost is the remediation work needed to actually pass — usually multi-factor authentication, patching, removing standing admin rights and tightening cloud configuration.
- Cyber Essentials assessment fee: £320–£600 + VAT depending on business size.
- Cyber Essentials Plus assessment fee: typically £1,500–£4,000+ depending on devices and complexity.
- Remediation tooling and time: highly variable; under a managed security subscription, most of this is already included.
How long does it take?
With a clean environment, the standard certification can be completed in 2–4 weeks. With remediation, plan for 6–10 weeks. Cyber Essentials Plus typically adds another 2–4 weeks for the technical audit window.
How do I know if I'd pass today?
Most SMEs don't pass first time, and they fail for the same boring reasons — missing MFA on admin accounts, patching that's slipped past 14 days, unsupported software, and BYOD devices touching company data without management.
The fastest way to find out where you stand is a short pre-assessment. We offer this as a free 30-minute review with a UK specialist — no obligation, no sales pitch, just a plain-English view of what would pass and what would need work.
Related service
Get an honest cyber security assessment
A clear, prioritised gap analysis against Cyber Essentials and modern best practice.
Explore Get an honest cyber security assessmentThe bottom line
If clients, insurers or contracts are starting to ask about your security posture, Cyber Essentials is almost always the right first step. It's affordable, it's recognised, and the remediation work is genuinely useful even if you never show anyone the certificate.
Not sure if it applies to you? Book a free 30-minute review and we'll tell you straight.

