Certification

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered through IASME, that verifies an organisation has five basic technical controls in place. Certification is awarded on the basis of a self-assessment questionnaire signed off by a board-level representative and reviewed by a licensed assessor.

Written and reviewed by , Senior Technical ConsultantLast reviewed 30 July 2026

At a glance

Introduced
2014
Governed by
NCSC, delivered by IASME
Assessment type
Verified self-assessment
Controls covered
Five
Validity
12 months
Typical timescale
2–6 weeks including remediation

The five controls

Cyber Essentials assesses five control areas. Every question in the assessment maps back to one of them, and all five must be satisfied across the scope you declare.

  • Firewalls — boundary and host-based firewalls configured to block unapproved inbound traffic.
  • Secure configuration — removing default accounts and passwords, disabling unused services and functionality.
  • User access control — accounts created through an approved process, administrative rights granted only where needed, multi-factor authentication on cloud services.
  • Malware protection — anti-malware software, application allow-listing, or sandboxing on all in-scope devices.
  • Security update management — supported software only, with high and critical patches applied within 14 days.

What is in scope

Scope normally covers the whole organisation: all end-user devices (including staff-owned devices used for work), servers, cloud services and internet-facing systems. A partial scope is permitted but must be a clearly separable business unit with its own network segregation, and the certificate then states that limitation.

Home working devices are in scope where they access organisational data. The home router itself is out of scope provided the device has a properly configured software firewall.

Why organisations certify

Cyber Essentials is mandatory for suppliers bidding on certain UK central government contracts that involve handling sensitive information. Beyond that requirement, it is widely requested in commercial supply chains, by insurers as a condition or discount factor on cyber policies, and by clients performing due diligence.

The NCSC's stated aim is that the five controls prevent the majority of common, untargeted internet-based attacks — the opportunistic scanning and credential attacks that make up most incidents affecting small businesses.

Full guide: What is Cyber Essentials?

Sources

The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.

  1. Cyber Essentials: overviewNational Cyber Security Centre
  2. Cyber Essentials certification schemeIASME Consortium
  3. Cyber Essentials Requirements for IT InfrastructureIASME Consortium
  4. Cyber Security Breaches SurveyUK Department for Science, Innovation and Technology

FAQ

What is Cyber Essentials — common questions

Direct answers to the questions asked most often about this topic.

How much does Cyber Essentials certification cost?

+

IASME certification fees are tiered by organisation size and start at around £300 plus VAT for a micro business with fewer than ten staff, rising through roughly £400, £500 and £600 plus VAT for larger bands. That fee covers the assessment itself. The larger variable cost is remediation: if devices are running unsupported operating systems, multi-factor authentication is not enabled, or patching is inconsistent, those issues must be corrected before certification is awarded. Organisations that use a partner to run the process typically also pay for readiness work, evidence gathering and submission support. Budgeting for both the fee and a remediation allowance gives a realistic picture of total cost.

How long does Cyber Essentials take to achieve?

+

The assessment questionnaire itself can usually be completed within a few days. The realistic end-to-end timescale is two to six weeks, because most organisations discover gaps during preparation that require configuration changes, software upgrades or device replacement. An organisation with a well-managed Microsoft 365 estate, enforced multi-factor authentication and consistent patching can move quickly. One with unsupported Windows versions, shared administrator accounts or unmanaged personal devices will need longer. Once submitted, the assessment is marked by a licensed assessor and the outcome is normally returned within a few working days.

Is Cyber Essentials a legal requirement?

+

No. Cyber Essentials is not a statutory obligation for businesses generally. It is contractually mandatory for suppliers on certain UK central government contracts involving sensitive or personal information, and for some Ministry of Defence supply chains. Outside those cases it is voluntary, but frequently requested: larger organisations often require it from suppliers, insurers may ask for it during underwriting, and public sector buyers commonly list it in tender requirements. Many SMEs pursue certification because a specific client contract depends on it rather than because a regulator demands it.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

+

Cyber Essentials is a self-assessment: the organisation answers the questionnaire, a board-level representative signs a declaration of accuracy, and a licensed assessor reviews the responses. Cyber Essentials Plus covers the same five controls but adds independent technical verification — an assessor tests a sample of devices, checks patch levels, attempts to deliver test malware and confirms multi-factor authentication is enforced. The controls required are identical; the difference is the level of assurance. Cyber Essentials Plus must be applied for within three months of achieving the base certification.

How long does Cyber Essentials certification last?

+

Certification is valid for twelve months from the date of issue and must be renewed annually. Renewal is a fresh assessment against the current version of the requirements, not an administrative rollover. The requirements are periodically revised — changes in recent years have covered cloud services, home working, multi-factor authentication and unsupported software — so an organisation that passed comfortably one year may find new questions apply the next. Treating the controls as ongoing operational standards, rather than an annual exercise, makes each renewal straightforward.

Can a very small business or sole trader certify?

+

Yes. There is no minimum organisation size, and sole traders and micro businesses certify regularly, often because a client contract requires it. The questionnaire is the same, but the scope is smaller and usually simpler: a handful of laptops, a Microsoft 365 or Google Workspace tenant, and a small number of cloud applications. Certification fees are lowest in the micro band. The most common obstacles for very small organisations are personal devices used for work, missing multi-factor authentication and unsupported operating systems on older hardware.

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way