What Cyber Essentials is
Cyber Essentials is a UK certification scheme backed by the government and overseen by the National Cyber Security Centre (NCSC), with IASME as the delivery partner that licenses the certification bodies. It sets a basic standard of technical controls that protect organisations from the most common internet-based attacks: the automated, opportunistic kind that go looking for an unpatched system or a weak password.
It isn't a full security management standard like ISO 27001. It's a baseline, and that's its strength. It's achievable for a small business, and it deals with the attacks small businesses are most likely to face.
The five controls
The scheme is built around five technical controls. Put like this they sound obvious. The value is in checking each one properly across every device and cloud service in scope, including the laptop someone uses at home and the old PC in the stock room.
- Firewalls: a properly set-up boundary between your devices and the internet
- Secure configuration: removing default passwords, unused software and unnecessary accounts
- Security update management: installing high-risk and critical updates within 14 days of release
- User access control: people have only the access they need, admin accounts are kept for admin work, and multi-factor authentication is on for cloud services
- Malware protection: stopping malicious software from running on your devices
Cyber Essentials or Cyber Essentials Plus?
There are two levels, and both cover the same five controls.
Cyber Essentials is a self-assessment. You answer a detailed questionnaire about your set-up, and a certification body reviews your answers. It's the right starting point for most small businesses.
Cyber Essentials Plus adds an independent technical audit. An assessor tests a sample of your devices and systems to check the controls actually work in practice. It's more rigorous, it costs more, and it's often what larger clients or particular contracts ask for. You need the basic Cyber Essentials certificate first.
Who needs it
Even if nobody is asking, working through the requirements is one of the cheapest ways for a small business to find and close obvious gaps. You're more likely to need the certificate itself if:
- You bid for UK central government contracts that involve handling certain personal information or providing some ICT services
- You supply the Ministry of Defence, where the requirements can go further
- Your clients include larger firms whose supplier questionnaires ask for it
- You handle sensitive client data and want a recognised way to show you take security seriously
How certification works
Certification goes through a licensed certification body. You complete the online assessment, the certification body reviews it, and if everything meets the standard you're certified. The certificate lasts twelve months, after which you recertify, which is a useful prompt to check nothing has slipped.
The fee is set centrally and scales with the size of your organisation, and IASME publishes the current prices on its website. Eligible small UK organisations that certify their whole organisation also get cyber liability insurance included. For most businesses the bigger cost is time: finding out what devices, accounts and software you actually have, and fixing whatever doesn't meet the requirements.
What usually trips small businesses up
Most small businesses fall down on the same handful of issues:
- Unsupported software, such as old versions of Windows that no longer get security updates
- Personal devices used for work, which are in scope if they access business data or services
- Staff using administrator accounts for everyday work
- Forgetting that the controls apply to Microsoft 365, Google Workspace and other cloud services too
- Multi-factor authentication not switched on everywhere it's available
- Default passwords left on routers and other network equipment
Is it worth it?
For most small businesses that handle client data, yes. It closes the gaps attackers most often exploit, it answers the security question in supplier checks and tenders, and it forces an inventory of your IT that's useful in its own right. It won't make you immune to every attack. It will make you a much harder target than a business that hasn't done it, and opportunistic attackers go for the easy ones.
How long does Cyber Essentials take?
If your IT is in good shape, a few days to gather the information and complete the assessment. If you need to replace unsupported devices, turn on multi-factor authentication or tidy up admin access, allow a few weeks to fix things first.
Can you fail Cyber Essentials?
Yes. If your answers show a control isn't met, you won't be certified until it is. It's usually better to prepare properly and fix gaps before you submit than to find them during the assessment.
Is Cyber Essentials the same as ISO 27001?
No. Cyber Essentials is a focused technical baseline aimed at common attacks. ISO 27001 is a full information security management standard covering policies, risk management and continual improvement. Many organisations start with Cyber Essentials and move to ISO 27001 later if clients or contracts need it.
Want to get ready for Cyber Essentials without the guesswork?
We help small businesses audit their devices and cloud accounts, fix what's missing and get ready for certification. It's a free, no-pressure consultation, and we never chase you afterwards.