Home / Cyber Security / Cyber Essentials / Cyber Essentials — The Complete UK Business Guide

Cyber Essentials — The Complete UK Business Guide

Cyber Essentials is a UK government-backed certification scheme designed to help organisations of all sizes protect themselves against the most common cyber threats. Developed by the National Cyber Security Centre (NCSC) and overseen by IASME, it defines a baseline set of technical security controls that, when implemented correctly, guard against the vast majority of internet-based attacks. The scheme operates at two levels — Cyber Essentials and Cyber Essentials Plus — with the higher level involving an independent technical audit on top of the standard self-assessment. Recognised across the public and private sectors, Cyber Essentials certification is increasingly seen as a minimum standard for any UK business that handles sensitive data or operates within regulated supply chains.

Who Needs Cyber Essentials?

Since 2014, Cyber Essentials has been mandatory for all UK central government contracts that involve handling personal data or delivering certain technical products and services. This requirement has since expanded significantly — many local authorities, NHS trusts, and defence contractors now insist that their suppliers hold a valid certificate before any work can begin. Beyond government, large enterprises in finance, legal, and professional services increasingly require Cyber Essentials as a condition of supplier onboarding, and the scheme is becoming a baseline expectation within cyber insurance underwriting.

Even for businesses with no immediate contractual obligation, achieving certification is sound practice. The NCSC estimates that the five technical controls covered by Cyber Essentials could prevent around 80% of common cyber attacks. Certification is administered through IASME-accredited assessors — IASME being the main certification body licensed by the NCSC to deliver the scheme across the UK. Whether you are a sole trader, an SME, or a larger organisation, the certification process provides a clear and affordable route to improving your security baseline.

Start Here

The Five Technical Controls

Cyber Essentials is built around five core technical controls, each targeting a different layer of your IT environment.

  1. Firewalls — A boundary firewall must be in place to protect every internet-connected device, ensuring that only necessary and authorised network traffic is permitted in and out of your systems.
  2. Secure Configuration — Devices and software must be configured securely from the outset, with unnecessary features, default accounts, and unused services removed or disabled to reduce the attack surface.
  3. User Access Control — User accounts must operate with the minimum permissions needed to perform their role, and administrator-level access must be tightly controlled, monitored, and granted only where genuinely required.
  4. Malware Protection — Organisations must deploy at least one form of malware protection — such as anti-malware software or application allowlisting — across all devices that connect to the internet or handle sensitive data.
  5. Patch Management — All software, operating systems, and firmware must be kept up to date, with high-risk patches applied within 14 days of release and unsupported software removed from the environment.

Our complete guide to the five controls explains each one in plain English and what you need to have in place to pass.

Cyber Essentials vs Cyber Essentials Plus

The standard Cyber Essentials certification is based on a self-assessment questionnaire. You answer a set of questions about your technical controls, and an IASME-accredited certifying body reviews and verifies your responses. It is a cost-effective option and typically costs between £300 and £500 depending on the size of your organisation and the assessor you choose.

Cyber Essentials Plus includes everything in the standard assessment but goes further with an independent technical audit carried out by a qualified assessor. This involves vulnerability scanning, hands-on testing of your devices, and verification that your controls work as described — rather than simply relying on your own answers. CE Plus typically costs between £1,000 and £3,000, again depending on organisation size and scope. If you are bidding for Ministry of Defence contracts, working within the NHS supply chain, or want to provide clients with a higher level of assurance, CE Plus is the appropriate choice. For most SMEs with no specific requirement for the higher tier, standard Cyber Essentials offers excellent value.

How Long Does Cyber Essentials Certification Take?

If your technical controls are already in good shape, the standard Cyber Essentials assessment can be completed in one to two weeks. The bulk of the time is spent working through the self-assessment questionnaire and addressing any gaps before submission. First-time applicants most commonly find shortfalls in patch management — particularly around legacy software and firmware — and in user access control, where admin privileges have accumulated over time without regular review.

Cyber Essentials Plus adds several more weeks to the process, as the independent technical audit must be scheduled and carried out after the self-assessment is approved. Once issued, all Cyber Essentials certificates are valid for 12 months, after which renewal is required to maintain certified status. Building the annual renewal into your IT calendar from the outset helps avoid lapses that could affect contract eligibility.

Benefits of Cyber Essentials Certification

  • Eligibility to bid for UK government contracts that require Cyber Essentials as a condition of tender.
  • Access to reduced cyber insurance premiums — a number of UK insurers offer discounts or improved terms to certified organisations.
  • Demonstrates due diligence to clients, partners, and prospects, providing independent evidence that your security baseline meets a recognised standard.
  • Provides a structured framework for identifying and closing common security gaps, improving your overall security posture in a measurable way.
  • Use of the official NCSC-backed Cyber Essentials certificate and digital badge in your marketing materials, proposals, and website.
  • A prerequisite for working within the Ministry of Defence supply chain and many other regulated sectors.
  • Supports compliance with wider regulatory requirements, including aspects of UK GDPR relating to appropriate technical security measures.
  • Annual renewal creates a regular security review cycle, helping organisations keep pace with a changing threat landscape rather than treating security as a one-off exercise.