Free initial consultation · Flexible ongoing and project-based services Speak to our team: 020 3048 4048

What Is Cyber Essentials and Does Your Business Need It?

By Published 27 May 2026 8 min read
what is cyber essentials

Quick answer: Cyber Essentials is a UK Government-backed certification scheme that verifies your business has five fundamental technical controls in place to block the most common internet-based cyber attacks. It costs from £330+VAT for a self-assessed certificate, takes most small businesses one to two weeks to complete, and is often required to win public sector contracts or bid for cyber insurance. From April 2026, the scheme’s technical requirements (version 3.3) were tightened to make multi-factor authentication and rapid security patching mandatory pass/fail conditions.

43%of UK businesses identified a cyber attack or breach in the past 12 months
£330+VATstarting cost for a micro business (1–9 employees)
£25,000free cyber liability insurance included with most certifications
12 monthscertificate validity before you need to recertify

What is Cyber Essentials?

Cyber Essentials is a certification scheme created by the UK Government’s National Cyber Security Centre (NCSC) and delivered through IASME, the scheme’s official partner. It was designed to give businesses of any size a clear, affordable way to demonstrate that they have basic cyber security protections in place, and to show customers, suppliers and insurers that they take security seriously.

Rather than trying to defend against every conceivable threat, Cyber Essentials focuses on the technical controls that stop the vast majority of everyday, opportunistic cyber attacks: the kind carried out by automated tools scanning the internet for open doors, not sophisticated targeted hacking. Government analysis has consistently found that this small set of controls, applied consistently, closes off most of the routes attackers actually use against small and medium-sized businesses.

For context on how common these attacks have become, the Government’s own Cyber Security Breaches Survey found that 43% of UK businesses identified a cyber attack or breach in the previous 12 months, rising sharply among medium and large organisations. Certification is one of the most direct, evidence-based ways to reduce that risk.

Cyber Essentials vs Cyber Essentials Plus

There are two levels of certification, and understanding the difference matters before you decide which one your business needs.

  Cyber Essentials Cyber Essentials Plus
Assessment method Self-assessment questionnaire, verified by an independent assessor Everything in standard Cyber Essentials, plus a hands-on technical audit and vulnerability scan of your systems
Typical timescale 1–2 weeks 4–8 weeks (self-assessment must be passed first)
Typical cost From £330+VAT (micro business) Typically £1,500–£1,900+VAT, depending on organisation size and complexity
Best suited to Most small and medium businesses, first-time applicants, contract requirements that only specify base-level certification Organisations handling sensitive data, NHS and defence supply chains, businesses that need independently verified proof rather than self-declared compliance

Many businesses start with standard Cyber Essentials and move up to Plus once they win contracts that specifically require the audited version. It’s worth checking your target contracts or insurer requirements before committing to the more expensive option.

The five technical controls

Certification is built around five control areas. An assessor checks that each one is properly implemented across every device, server and cloud service your business uses to handle information or connect to the internet.

  • FirewallsEvery internet connection is protected by a correctly configured firewall, including on individual devices used outside the office, to control what traffic is allowed in and out of your network.
  • Secure configurationDevices and software are set up to reduce vulnerabilities, removing or disabling unnecessary user accounts, default passwords and functions that aren’t needed for business use.
  • User access controlStaff only have the account privileges they need to do their job, administrator accounts are tightly controlled, and multi-factor authentication protects all accounts where it’s available, including cloud services.
  • Malware protectionAnti-malware software is installed and kept up to date across all devices, or an equivalent method such as application allow-listing or sandboxing is used instead.
  • Security update managementSoftware, operating systems and firmware are kept up to date, with critical and high-risk security updates applied promptly across all in-scope devices.

What changed in the April 2026 update (version 3.3)

The Cyber Essentials technical requirements are reviewed regularly by the NCSC and IASME to keep pace with how businesses actually work and how attackers actually operate. The version 3.3 update, which applies to all assessments created on or after 26 April 2026, made two changes that businesses preparing for certification need to know about.

  • Multi-factor authentication is now a mandatory auto-fail requirementMFA must be enabled on all user, administrator and cloud service accounts wherever the service supports it. Applicants who cannot demonstrate this now fail the assessment outright, rather than losing points, reflecting how central MFA has become to blocking account takeover attacks.
  • Faster patching for critical vulnerabilities (new questions A6.4 and A6.5)Critical and high-severity security updates must now be applied within 14 days of release across all in-scope devices, and applicants must confirm they have a process in place to identify and apply them within that window. Missing this is also now an auto-fail condition.

If your business already held a valid Cyber Essentials certificate before the update, IASME has confirmed a six-month transition period applies before the new requirements are enforced at your next renewal, giving existing certificate holders time to tighten their MFA coverage and patching processes rather than being caught out immediately.

Who needs Cyber Essentials, and why it matters beyond compliance

Cyber Essentials isn’t a legal requirement for most UK businesses, but it has become a practical necessity in several situations. It’s mandatory for any organisation bidding for UK Government contracts that involve handling personal data or providing certain technical products and services. Many private-sector supply chains, particularly in finance, healthcare and defence, now require suppliers to hold it as a condition of doing business. Cyber insurers increasingly ask about it during underwriting, and some offer preferential premiums to certified businesses because the certification demonstrably lowers claim risk.

There’s also a direct financial incentive built into the scheme. Most Cyber Essentials certifications for businesses with a turnover under £20 million, domiciled in the UK or Crown Dependencies, come with £25,000 of free cyber liability insurance from IASME as part of the certification package (this is opt-in and applies to the whole organisation, not per device). Businesses that want more cover can purchase higher tiers, with £100,000 or £250,000 of coverage available for an additional premium depending on annual revenue. For a business that has never carried cyber insurance before, this alone can offset a meaningful part of the certification cost.

How much does Cyber Essentials cost?

Pricing for standard Cyber Essentials is banded by company size, based on employee numbers:

Organisation size Employees Typical price (+VAT)
Micro 1–9 From £330
Small 10–49 From £400
Medium 50–249 From £450
Large 250+ From £500

Cyber Essentials Plus costs more because it includes an assessor’s time for hands-on testing rather than just a document review, typically £1,500–£1,900+VAT depending on the size and complexity of your IT environment. Exact pricing varies between certification bodies, so it’s worth getting a specific quote for your business rather than relying on list prices alone.

What happens if you fail the assessment?

Failing isn’t unusual, and it isn’t the end of the process. If your self-assessment doesn’t meet the required standard, most certification bodies allow you to fix the specific gaps identified and resubmit within a set window, often at no extra charge, rather than starting the whole application again. Common reasons businesses fail on the first attempt include missing MFA on cloud accounts, out-of-date software on a handful of devices that were overlooked, and unmanaged personal devices being used to access company data without adequate controls.

Practical tip: Run through the five controls internally before you submit, particularly MFA coverage and patch status, since these are now auto-fail conditions under the current requirements. A short internal IT audit beforehand catches most of the gaps that cause assessments to fail.

How long does certification take?

Standard Cyber Essentials typically takes one to two weeks from starting the self-assessment questionnaire to receiving your certificate, assuming your systems are already reasonably well configured. Businesses starting from scratch, with gaps to close first, should budget longer. Cyber Essentials Plus takes longer still, usually four to eight weeks in total, because the standard assessment must be passed first before the technical audit can be scheduled.

Frequently asked questions

Is Cyber Essentials the same as ISO 27001?

No. Cyber Essentials is a focused, lower-cost certification covering five essential technical controls, typically completed in one to two weeks. ISO 27001 is a much broader information security management standard covering policies, risk management and organisational processes, and usually takes several months to implement. Many businesses use Cyber Essentials as a starting point before working towards ISO 27001.

Does Cyber Essentials cover cloud services like Microsoft 365?

Yes. Cloud services your business uses to handle data or communications, including email and productivity platforms such as Microsoft 365, fall within scope and must meet the same requirements, including mandatory MFA. If you rely heavily on Microsoft 365, it’s worth checking your backup and account security setup covers this before applying.

How often do I need to renew?

Certificates are valid for 12 months from the date of issue. You’ll need to complete a fresh self-assessment (or technical audit, for Plus) each year to maintain certification.

Can a small business with no in-house IT team get certified?

Yes, and it’s common. Many small businesses work with a managed IT support provider to get their systems into a compliant state and complete the assessment, rather than attempting it without technical support.

Getting ready for certification

The businesses that pass Cyber Essentials quickly and without repeat attempts are almost always the ones that address the technical gaps before they submit, rather than treating the assessment itself as the starting point. That typically means confirming MFA is switched on everywhere it’s supported, checking every device is receiving security updates promptly, and making sure firewalls and access controls are consistently configured, not just on the office network but on remote and mobile devices too. If any of your business runs on WordPress, it’s also worth reviewing common WordPress security mistakes and having a plan for ransomware protection in place, since these overlap directly with what an assessor will be checking.

Get Cyber Essentials ready with expert support

UK IT Services helps businesses prepare for and pass Cyber Essentials first time, closing technical gaps before you submit.

Talk to Our Cyber Security Team

About the author

Kevin Marshal

Kevin Marshal is a content writer at UK IT Services, a UK-based IT support, cyber security and digital agency. He turns complex technology topics into clear, practical guidance that business owners and decision-makers can actually use. Drawing on the expertise of the wider UK IT Services team, Kevin writes about managed IT support, cyber security, Microsoft 365, web design and development, and digital marketing, always with a focus on what works for small and medium-sized UK businesses. His goal is simple: help organisations make smarter, safer technology decisions without the jargon.

Latest insights

Talk to a UK-based IT specialist

Managed IT support, cyber security and digital services for businesses across the UK.

Get a Free Consultation
Call Us Free Consultation