TL;DR:
- Cyber Essentials is a UK government-backed certification covering five basic security controls: firewalls, secure configuration, access control, malware protection, and patch management
- It’s available in two tiers — self-assessed (Cyber Essentials) and independently verified (Cyber Essentials Plus)
- It’s mandatory for any contract involving UK government data or systems, and increasingly required by larger customers and insurers
Cyber Essentials is one of those things that a lot of small business owners have heard of but haven’t quite got around to. It sounds like it might be complicated, expensive, or aimed at larger organisations. It’s none of those things. Getting certified takes a few weeks of preparation, costs a few hundred pounds for most small businesses, and provides a practical baseline that demonstrably reduces exposure to the most common cyber attacks.
Here’s what you need to know.
What Cyber Essentials Actually Covers
The scheme was developed by the UK government and is managed by IASME on behalf of the National Cyber Security Centre (NCSC). It defines five technical controls that, when properly implemented, protect against the majority of opportunistic cyber attacks:
1. Firewalls Your internet-connected devices and networks must be protected by a properly configured firewall. This means the default settings on your router aren’t sufficient — the firewall needs to be actively configured to block unnecessary inbound connections.
2. Secure configuration Software and devices should be configured securely from the start, with unnecessary features and services disabled. Default passwords must be changed on all devices and accounts. This covers laptops, mobile devices, routers, cloud services, and anything else with an internet connection.
3. User access control User accounts should have only the privileges they need to do their jobs. Admin accounts should be separate from everyday user accounts and used only for admin tasks. Multi-factor authentication (MFA) is now required for accounts with admin privileges and for cloud services.
4. Malware protection Devices should have appropriate protection against malware. This includes anti-malware software, application allowlisting (on systems where it’s feasible), or sandboxing. Mobile devices should be covered alongside laptops and desktops.
5. Patch management Software and operating systems must be kept up to date. This means applying security patches within 14 days of release for high and critical vulnerabilities, and ensuring unsupported software is removed or replaced.
These five controls sound basic because they are. That’s the point. The NCSC’s analysis shows that the vast majority of successful cyber attacks exploit exactly these gaps — unpatched systems, weak passwords, broad admin access, inadequate firewall rules. Cyber Essentials is a floor, not a ceiling, but it’s a floor that a significant proportion of small businesses haven’t actually reached.
The Two Certification Tiers
Cyber Essentials (self-assessed) You complete an online questionnaire covering your implementation of the five controls. The questionnaire is reviewed by a certified assessor. If your answers indicate compliance, you’re certified. The process is self-reported — there’s no technical verification of your actual configuration. Cost is typically £300–600 for small businesses through IASME-approved certification bodies.
Cyber Essentials Plus Everything in the basic scheme, plus an independent technical assessment. An assessor actually tests your systems — checking that your patch status matches what you reported, verifying firewall configurations, testing whether malware would be blocked, confirming MFA is in place. This involves a hands-on assessment of a sample of your devices and infrastructure. Cost is higher and varies by organisation size, typically £1,500–5,000 for small businesses.
The certification body you choose matters less than you’d think — they’re all working from the same IASME-governed questionnaire and assessment methodology. What varies is how much support they offer during preparation.
When You Need It
Government contracts: Cyber Essentials (at minimum) is mandatory for any UK government contract involving the handling of personal data or other sensitive information, or the provision of certain technical products or services. If you’re supplying to any central government department, Cyber Essentials is a prerequisite. Many local government and NHS procurement processes require it as well.
Supply chain requirements: Large private sector organisations increasingly require Cyber Essentials from their suppliers, particularly if you’ll have access to their systems, data, or networks. Check your contracts and tender requirements — you may already be obligated.
Cyber insurance: Insurers are increasingly looking at Cyber Essentials certification as a positive underwriting factor. Some insurers now offer reduced premiums or simplified application processes for certified businesses. It won’t guarantee you get a policy or a specific rate, but it signals that you’ve done basic due diligence.
As a credibility signal: Displaying a Cyber Essentials badge on your website or proposals tells customers and partners that you’ve met a government-defined security standard. For small businesses competing against larger suppliers, it’s a concrete differentiator.
Preparing for the Assessment
The questionnaire is more granular than the five-control summary suggests. Before attempting certification, you should work through the following:
Inventory your in-scope devices. The assessment covers all devices that can access your organisational data or services — laptops, desktops, mobile phones, tablets, cloud servers. If staff use personal devices for work (BYOD), those devices are in scope too. Know what you have.
Check your firewall rules. Default router configurations often allow more inbound connections than necessary. Your broadband router’s admin interface should have the default admin password changed and be configured to block inbound connections except where explicitly required. Many small businesses fail this control because they’ve never reviewed the out-of-box router configuration.
Audit user accounts and admin access. List every user account across your systems. Identify which have admin rights. Admin accounts should not be used for everyday activities like browsing the web or reading email — they should be separate accounts used only for administrative tasks. MFA must be enabled on admin accounts and on any cloud services (Microsoft 365, Google Workspace, accounting software).
Check your patch status. Run Windows Update and check that all devices are current. Audit software versions — old versions of browsers, office software, or design tools are common failure points. Remove or replace software that’s no longer receiving security updates.
Document your malware protection. Know what anti-malware product you’re using, that it’s active on all in-scope devices, and that its definitions are current. Mobile device management (MDM) is increasingly relevant here if you have staff with work email on personal phones.
Common Failure Points
The most frequent reasons small businesses fail the assessment:
BYOD devices not included in scope. If your staff access work email on personal phones, those phones need to meet the same requirements as company-issued devices. This catches many applicants by surprise.
Outdated software on one machine. A single laptop with an old version of software that’s no longer patched can fail the entire assessment. Uninstall anything you’re not using and update everything you are.
Admin accounts used daily. If the owner uses the same admin account to browse the web that they use to install software, this fails the access control requirement. Create a separate standard account for day-to-day work.
Default router admin credentials unchanged. This is still common in small offices that set up their broadband connection years ago and never revisited the router configuration.
MFA not enabled on cloud accounts. Microsoft 365 and Google Workspace both offer MFA — it needs to be enabled for all accounts, and mandatory (not optional) for admin accounts.
Is It Worth Doing if You Don’t Have a Specific Requirement?
Yes, with the caveat that “worth doing” means something different depending on your situation.
If you’re a micro-business with no government contracts, no large enterprise customers, and no plans to scale: the self-assessed Cyber Essentials is still worth doing because the preparation process forces you to review your security baseline systematically. You’ll almost certainly find something that needed fixing. The certification itself costs a few hundred pounds and takes a few weeks of preparation time. That’s a reasonable investment for the assurance it provides.
If you have government contracts or significant enterprise customers: Cyber Essentials is likely already required and Cyber Essentials Plus may be more appropriate. The Plus certification gives customers a higher level of assurance because it’s independently verified.
The NCSC maintains a free online tool called the Cyber Action Plan that walks you through the controls in plain language and identifies gaps before you attempt the assessment. It’s a useful starting point even if you’re not immediately pursuing certification.
Cyber Essentials isn’t the whole answer to cyber security for a small business. It doesn’t cover incident response, staff awareness training, or business continuity planning. But it covers the fundamentals that would prevent the majority of the attacks that actually hit small businesses — and it gives you a credible, government-recognised way to demonstrate that to customers, partners, and insurers.