Guide · Cyber Essentials

What is Cyber Essentials?

Cyber Essentials is the UK government-backed cyber security certification that shows your business has the five basic technical controls in place to defend against the most common internet-based attacks. This guide explains what it covers, who needs it, and how to get certified.

A short definition

Cyber Essentials is a certification scheme run by IASME on behalf of the National Cyber Security Centre (NCSC), part of GCHQ. Certification confirms that a business has implemented five specific technical controls across its devices, networks and cloud services. There are two levels: Cyber Essentials (self-assessment verified by a certifying body) and Cyber Essentials Plus (the same controls verified by an independent technical audit).

The five controls

Firewalls

Boundary firewalls and software firewalls configured to block unwanted inbound traffic on every device, including remote and home workers.

Secure configuration

Devices and software set up so that only what is needed is enabled — default passwords removed, unnecessary accounts and services disabled.

User access control

Staff have only the access they need, admin rights are limited and protected, and multi-factor authentication is in place on cloud services.

Malware protection

Approved anti-malware or application allow-listing in place on all devices, kept up to date and actively monitored.

Security update management

Operating systems, browsers and applications patched promptly — critical updates within 14 days of release.

Why it matters

Cyber Essentials is now a contractual requirement for many UK government contracts and a growing number of private-sector frameworks. Larger clients increasingly request it before signing supplier agreements, and many cyber insurance policies either require it or reduce premiums for certified businesses. Beyond the badge, the five controls genuinely block the bulk of opportunistic attacks aimed at SMEs.

Who it is for

Any UK organisation — from a five-person consultancy to a 200-person manufacturer — that wants to demonstrate baseline cyber hygiene. It is particularly relevant for businesses bidding on public-sector work, handling client or personal data, or looking to formalise their cyber security posture.

How long it takes

For a well-prepared SME, certification typically takes between two and eight weeks. Most of the timeline is preparation — closing gaps in patching, MFA coverage, admin accounts and device configuration before the assessment is submitted. The assessment itself is a structured questionnaire reviewed by an accredited certifying body.

How we help

Our Cyber Essentials certification support service handles the whole process: gap analysis, remediation, evidence gathering, the assessment submission, and (where required) the independent Cyber Essentials Plus audit. Most clients reach certification within a few weeks of starting.

Cyber Essentials is the foundation, not the finish line. Once certified, most SMEs layer on managed EDR and MDR services, Cyber Shield awareness training, and phishing simulation to cover the threats that the five technical controls do not address on their own.

Not sure if you are ready? Book a no-obligation free cyber security review and we will tell you exactly what stands between you and certification.

FAQ

Frequently asked questions

What is Cyber Essentials?

+

Cyber Essentials is a UK government-backed certification scheme, run by IASME on behalf of the National Cyber Security Centre (NCSC), part of GCHQ. It confirms that a business has five basic technical controls in place — firewalls, secure configuration, user access control, malware protection and security update management — to defend against the most common internet-based attacks. It is delivered as a self-assessment questionnaire, verified by an accredited certifying body, and results in a certificate and badge valid for 12 months. For most UK SMEs it is the entry point into structured cyber security, and increasingly a precondition for winning contracts and securing cyber insurance.

How does the Cyber Essentials assessment work?

+

You complete a self-assessment questionnaire describing how the five controls are implemented across every device, network and cloud service in scope — including laptops, phones, servers and services like Microsoft 365. An accredited certifying body reviews your answers and asks follow-up questions where anything is unclear. Once satisfied, they issue certification. There is no on-site visit or technical scan at the basic level; that step is added for Cyber Essentials Plus, which independently verifies the same controls through vulnerability scans and device checks rather than relying on self-reported answers alone.

Why should a business bother getting Cyber Essentials certified?

+

Because it closes the gaps that cause most SME breaches, and it opens doors commercially. Certification is mandatory for many UK government contracts, increasingly requested by larger private-sector clients during procurement, and often required — or rewarded with lower premiums — by cyber insurers. Beyond compliance, the five controls it enforces genuinely block the bulk of opportunistic, automated attacks aimed at small businesses, such as credential stuffing and unpatched remote access exploitation. It is a low-cost way to demonstrate credibility to customers, suppliers and insurers while meaningfully reducing your actual risk.

What does Cyber Essentials cost?

+

The certification body fee for Cyber Essentials is fixed nationally and scales with organisation size, typically a few hundred pounds for a small business. The larger and more variable cost is remediation — closing gaps in patching, multi-factor authentication, admin account controls and device configuration before you apply. Many SMEs already meet most requirements and only need targeted fixes, keeping total cost modest. Cyber Essentials Plus, with its independent technical audit, costs more than the basic level because it includes on-site or remote scanning and device sampling rather than a paper-based review.

How long does Cyber Essentials certification take?

+

For a well-prepared SME, certification typically takes two to eight weeks from start to finish. Most of that time is spent on preparation — fixing gaps in patching, enabling multi-factor authentication, tidying admin accounts and correcting device configuration — rather than on the assessment itself, which is usually reviewed within a few working days once submitted. Businesses starting from a weaker position, with legacy devices or no consistent patching process, should budget closer to the upper end. Using a support partner to run gap analysis up front usually shortens the timeline significantly.

Is Cyber Essentials suitable for small businesses?

+

Yes — it was specifically designed with small and medium businesses in mind, unlike heavier frameworks such as ISO 27001. The five controls are achievable without a dedicated IT security team, and many SMEs already meet most of them through standard use of Microsoft 365, modern firewalls and up-to-date devices. A five-person consultancy and a 200-person manufacturer both certify against the same scheme. It is proportionate, affordable and recognised across sectors, making it the natural starting point for any UK SME that has not yet formalised its cyber security.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

+

Cyber Essentials is a self-assessment questionnaire verified by a certifying body based on your written answers. Cyber Essentials Plus covers the same five controls but adds an independent technical audit, including vulnerability scans and hands-on checks across a representative sample of your devices. Plus provides much stronger assurance because it verifies what is actually configured rather than what is reported, which is why it is often specified in higher-value contracts and by insurers wanting more confidence. Most businesses start with basic Cyber Essentials and move to Plus once their controls are consistently in place.

How does Cyber Essentials compare with other security frameworks like ISO 27001?

+

Cyber Essentials is narrower and faster than ISO 27001. It focuses on five specific technical controls rather than a full information security management system covering policy, risk assessment, physical security and governance. ISO 27001 requires ongoing internal audits and typically takes months to implement, whereas Cyber Essentials can be achieved in weeks and is renewed annually through a lighter process. Many SMEs treat Cyber Essentials as the practical baseline and only pursue ISO 27001 later if a client or sector specifically requires the broader management system it certifies.

See our Cyber Essentials certification support

Reference pages on the certification and its controls

Short, factual definitions of the terms used in this guide, each with its own FAQ.

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way