Home / Cyber Security / Cyber Essentials / What Is Cyber Essentials? The UK Business Guide

What Is Cyber Essentials? The UK Business Guide

What Is Cyber Essentials? The UK Business Guide

If you run a business in the UK, you have almost certainly come across the term Cyber Essentials — whether through a government tender requirement, a customer questionnaire, or your cyber insurance renewal. Yet despite being one of the most widely referenced cybersecurity certifications in the country, many business owners remain unclear on exactly what it is, what it covers, and why it matters. This guide cuts through the jargon and gives you a clear, practical overview of the scheme, who it is aimed at, and what achieving certification actually involves.

What Is Cyber Essentials?

Cyber Essentials is a UK government-backed cybersecurity certification scheme designed to help organisations of all sizes protect themselves against the most common and frequently occurring cyber attacks. It was launched in 2014 by the National Cyber Security Centre (NCSC), the UK’s leading authority on cybersecurity, and is administered in partnership with IASME, a not-for-profit organisation that oversees the network of accredited certification bodies that carry out assessments.

The scheme is intentionally focused on the fundamentals. Rather than trying to guard against sophisticated, nation-state-level threats, Cyber Essentials targets the kind of commodity cyber attacks that the vast majority of UK businesses actually face — opportunistic attacks that exploit basic security weaknesses. The NCSC’s own research indicates that implementing the scheme’s controls reduces an organisation’s risk from these common attacks by around 80 per cent. That is a significant reduction for what is, in most cases, a straightforward and affordable process.

Who Runs Cyber Essentials?

The scheme is owned and managed by the NCSC, which sits within GCHQ and serves as the UK government’s primary technical authority on cybersecurity. Day-to-day delivery is handled by IASME, which acts as the sole accreditation body for the scheme. IASME in turn accredits a network of certification bodies — independent organisations that have been assessed and approved to carry out Cyber Essentials assessments on behalf of applicants. This tiered structure means that when you seek certification, you deal with an IASME-accredited certification body, not the NCSC or IASME directly.

The Two Tiers of Certification

Cyber Essentials is available at two levels, each with a different assessment approach and level of assurance.

Cyber Essentials

The entry-level certification is based on a verified self-assessment. Your organisation completes an online questionnaire covering the five technical control areas (more on those below), and the answers are reviewed and verified by an IASME-accredited certification body. If your responses demonstrate that the required controls are in place, your organisation is awarded Cyber Essentials certification. This level is suitable for smaller organisations or those just beginning their cybersecurity journey.

Cyber Essentials Plus

The higher tier involves the same five technical controls but requires a hands-on technical audit carried out by an accredited assessor. Rather than relying on your self-reported answers, the assessor independently verifies that the controls are actually implemented correctly — testing your systems directly. Cyber Essentials Plus carries greater assurance and is increasingly expected by larger clients and government departments in higher-risk supply chain relationships.

The Five Technical Controls

Both tiers of certification are built around the same five core technical controls, which the NCSC considers the most effective baseline defences against common cyber attacks:

  • Firewalls — ensuring that internet-facing devices and networks are protected by properly configured firewalls
  • Secure configuration — making sure that devices and software are set up securely, removing unnecessary features and default credentials
  • User access control — limiting access to data and systems to those who genuinely need it, using appropriate account controls
  • Malware protection — defending against malicious software through tools such as antivirus and application whitelisting
  • Patch management — keeping software and devices up to date by applying security patches in a timely manner

These controls are deliberately not exhaustive. They represent the baseline that every UK organisation should have in place, regardless of size or sector. The NCSC is clear that Cyber Essentials is a starting point, not a complete cybersecurity strategy — but it is a meaningful and important one.

How Long Does Certification Last?

Cyber Essentials certification is valid for 12 months from the date of issue. Organisations must renew annually, which reflects the fact that the threat landscape, software versions, and organisational IT environments change continuously. Annual renewal also ensures that the scheme remains a live, maintained commitment rather than a one-time tick-box exercise.

Who Needs Cyber Essentials?

The UK government has required suppliers bidding for certain central government contracts to hold Cyber Essentials certification since the scheme launched in 2014. This requirement is particularly firm for contracts that involve the handling of sensitive or personal information, as well as for Ministry of Defence (MOD) suppliers. The NCSC actively promotes the scheme for all UK businesses regardless of size — from sole traders and small businesses through to large enterprises and public sector bodies.

Beyond the government mandate, many large private sector organisations now require Cyber Essentials from suppliers within their own supply chains, treating it as a minimum baseline of assurance before entering into commercial relationships. The scheme has become something of a de facto standard in UK business-to-business procurement, particularly in sectors such as financial services, healthcare, and defence.

UK cyber insurance providers have also taken notice. Many insurers now ask applicants whether they hold Cyber Essentials certification as part of the underwriting process, and a growing number offer reduced premiums to certified organisations — recognising that the controls in place genuinely lower the likelihood and potential impact of a claim.

A Uniquely British Scheme

One aspect of Cyber Essentials that is easy to overlook is how distinctly British it is. There is no direct equivalent in the United States or the European Union. The US has frameworks such as NIST Cybersecurity Framework and CMMC (Cybersecurity Maturity Model Certification) for defence contractors, while the EU has ENISA guidance and the NIS2 Directive — but none of these are structured in the same way or aimed so specifically at establishing a national baseline for all organisations.

Cyber Essentials does map loosely to parts of wider frameworks such as ISO 27001 and NIST, meaning that organisations pursuing those certifications will find that the groundwork they have done for Cyber Essentials is not wasted. However, Cyber Essentials sits at a different level — it is more accessible, less resource-intensive, and explicitly designed for the full breadth of the UK business landscape, not just enterprises with dedicated security teams.

Is Cyber Essentials Right for Your Organisation?

If your organisation operates in the UK, trades with the public sector, works within a regulated supply chain, or simply wants to demonstrate a credible baseline of cybersecurity practice to customers and partners, Cyber Essentials is worth serious consideration. The cost of certification varies depending on the size of your organisation and the tier you pursue, but it is generally accessible even for small businesses. Given that the NCSC’s own evidence suggests the scheme blocks around 80 per cent of common attacks, the return on that investment is difficult to argue with.

Whether you are new to the scheme or exploring whether to upgrade from Cyber Essentials to Cyber Essentials Plus, the first step is to find an IASME-accredited certification body. From there, the process is well-structured and guided — and the resulting certification is increasingly one that UK businesses simply cannot afford to be without.