Skip to main content
Dig IT Solutions logo

Cyber Security

What is Cyber Essentials? (And does your business need it?)

Cyber Essentials explained for UK small businesses: the five controls, Cyber Essentials vs Plus, who requires it, and the process, timeline and cost.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

Cyber Essentials is the UK government-backed certification, run by the NCSC through IASME, that confirms an organisation has five technical controls in place: firewalls, secure configuration, security update management, user access control and malware protection. You need it for public-sector contracts, cyber insurance on good terms, or customers who ask, and it is the right baseline for any SME.

If a customer, a tender or an insurer has asked whether you hold Cyber Essentials, you probably want two things: a clear explanation of what it is, and an honest view on whether it is worth doing for a business your size. This guide gives both, with the process, the timeline and the practical work involved for a firm of up to 250 people.

Cyber Essentials in one paragraph

Cyber Essentials is a UK government scheme, owned by the National Cyber Security Centre and delivered by IASME as the sole certification partner, that certifies an organisation has implemented five basic technical controls. Those five controls were chosen because they stop the large majority of common, untargeted cyber attacks: the automated scanning, credential stuffing, phishing and commodity malware that hit small businesses far more often than anything sophisticated. It is deliberately achievable by organisations with no security team, it is renewed annually, and it comes in two levels.

The five controls

Every question in the Cyber Essentials assessment maps to one of these. If you understand them, you understand the scheme.

1. Firewalls. Every device must be protected by a firewall: a boundary firewall between your network and the internet, and the software firewall on each computer. Default administrative passwords must be changed, administrative interfaces must not be reachable from the internet unless there is a documented need with MFA or IP restriction, and any service opened to the internet must have a business justification and be closed when no longer needed. In practice this means no remote desktop exposed to the world and a firewall that someone actually manages.

2. Secure configuration. Devices and software are set up to reduce their exposure: unnecessary accounts and software removed, default passwords changed, auto-run disabled, and devices locked with a PIN, password or biometric. The requirements set minimum standards for device locks and for how passwords are protected against brute force. Encryption is not strictly required, but it is expected practice and it is what protects you if a laptop goes missing.

3. Security update management. All software must be licensed and supported, and updates that the vendor rates as critical or high-risk must be applied within 14 days of release. Unsupported software, such as Windows 10 since October 2025 without extended support, is an automatic fail. This is the control that most often catches businesses out, because "updates are on" is not the same as being able to show every device is within 14 days.

4. User access control. Each person has their own account, access is granted on the basis of need, administrator accounts are separate from day-to-day accounts and used only for admin tasks, accounts are removed when people leave, and multi-factor authentication is enabled on all cloud services that offer it. There are minimum password standards and a requirement to protect against brute-force attempts. Our offboarding checklist and MFA guide cover the two parts that most SMEs need to fix.

5. Malware protection. Every device runs anti-malware software that is kept up to date and configured to scan files and web content, or is protected by application control that only permits approved software to run. Modern endpoint detection and response satisfies this comfortably, consumer antivirus on some machines and nothing on the server does not.

The scope is every device that accesses organisational data or services, including personally owned phones and laptops used for work email. That surprises many businesses and is why a bring-your-own-device policy with management is usually part of the preparation.

Cyber Essentials versus Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
What it isVerified self-assessment questionnaireIndependent technical audit of the same controls
Who checksA director signs a declaration, a qualified assessor reviews the answersAn assessor tests: external vulnerability scan, internal scan and checks on a sample of devices, malware and email attachment tests, MFA and account separation checks
PrerequisiteNoneA current Cyber Essentials certificate, with Plus completed within three months of it
Typical effortDays to complete once controls are in placeAn assessment day plus remediation of anything found
CostFixed fee banded by organisation size, from a few hundred poundsSet by the certification body, typically four figures, depending on size and number of sites
Who asks for itMost public-sector contracts, most insurers and customersHigher-risk contracts, MoD and some NHS or regulated supply chains, customers wanting independent verification

For most small businesses, Cyber Essentials is the right first step and often all that is asked for. Plus is worth it when a contract requires it, when you want independent evidence for customers, or when you want to be sure the controls really are in place rather than believed to be. Our companion article on how much Cyber Essentials costs sets out the fees and the real cost, which is remediation.

Who requires it

Public-sector contracts. Since 2014 UK central government has required Cyber Essentials for suppliers bidding for contracts that involve handling personal information or providing certain IT products and services. The Ministry of Defence applies it across its supply chain, and NHS bodies, local authorities, housing associations and universities increasingly include it in tenders. If you supply, or want to supply, any of these, assume it is a requirement.

Larger private customers. Supplier security questionnaires from corporate clients now routinely ask for Cyber Essentials, and some accept it in place of a lengthy bespoke questionnaire. It is a quick way for a customer to know you meet a recognised baseline.

Insurers. Cyber insurance applications ask about MFA, patching, backups and endpoint protection, which are the Cyber Essentials controls in different words. Certification makes the application straightforward, and organisations under a turnover threshold that certify the whole organisation are offered cyber liability insurance through the scheme at no extra cost, with details on the IASME site.

Your own standards. Even without an external demand, the five controls are the sensible baseline for any business connected to the internet, and the annual cycle forces a review that would otherwise not happen.

The process, step by step

  1. Gap assessment. Review your systems against the current question set: every device, every cloud service, every user, every firewall. This is where the surprises are found, such as the unsupported server, MFA exceptions, or the depot manager's personal laptop.
  2. Remediation. Fix the gaps. For a typical SME this means enforcing MFA and conditional access, removing local administrator rights, putting patching under management with reporting, replacing or upgrading unsupported systems, tidying firewall rules, and deploying EDR everywhere.
  3. Evidence and documentation. Build the device and software inventory, confirm the scope, and write down the processes the questionnaire asks about (leaver removal, patch timescales, device standards).
  4. Choose a certification body. IASME licenses certification bodies across the UK, you buy the assessment from one of them. Pick one that is responsive and comfortable with businesses your size.
  5. Complete the self-assessment. The questionnaire is answered online. A board member or equivalent signs the declaration. The assessor reviews and may come back with clarifications, you have a short window to respond.
  6. Certificate issued. Valid for twelve months. You appear on the public register and can use the badge.
  7. Cyber Essentials Plus, if required. Book the audit within three months of the basic certificate. The assessor scans your external addresses, tests a sample of devices and user accounts, and checks that malware protection and email defences behave as claimed.
  8. Maintain and renew. The controls have to stay in place all year. Monitoring and managed patching keep you compliant between certificates, see why security needs continuous monitoring.

Typical timeline

A business that already runs managed patching, EDR, enforced MFA and a proper firewall can complete the questionnaire in a week or two. A business starting from a mixed estate with some unsupported machines and partial MFA should allow four to eight weeks for preparation, most of which is doing the remediation, not paperwork. Plus adds an assessment day and typically two to four weeks for scheduling and any fixes.

The single biggest cause of delay is hardware: discovering that several PCs cannot run a supported operating system and need replacing. Finding that out early is the main value of the gap assessment.

Where Dig IT fits

We do not certify. Certification bodies are licensed by IASME, and it is a conflict of interest for the firm that fixes your systems to also mark the exam. What we do is prepare businesses for it: a cyber security audit against the five controls, the remediation work, the evidence, and support through the questionnaire and any Plus assessment. For businesses we already support, most of the controls are part of the managed service and the annual renewal is a light task. Our Cyber Essentials preparation service describes the engagement.

Does your business need it?

If you sell to the public sector or to larger companies, yes, and sooner rather than later, because it takes weeks to prepare and tenders do not wait. If you want cyber insurance on sensible terms, it will make the application easier. If neither applies, the honest answer is that you still need the five controls, because they are what stop the attacks that actually reach small businesses, and certification is a modest extra cost that proves you have them.

What to do next

If you have been asked for Cyber Essentials or want to know how far away you are, start with an IT health check. It assesses your systems against the five controls and gives you a plain list of what would need to change, how long it would take and what it would cost.

Frequently asked questions

What are the five Cyber Essentials controls?
Firewalls (a boundary firewall and device firewalls, with nothing exposed unnecessarily), secure configuration (default passwords changed, unneeded software and services removed), security update management (critical and high-risk patches applied within 14 days, no unsupported software), user access control (named accounts, least privilege, MFA on cloud services) and malware protection (anti-malware or application control on every device).
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment: you answer a questionnaire, a director signs it, and a qualified assessor reviews the answers. Cyber Essentials Plus tests the same five controls but an assessor independently verifies them with vulnerability scans, checks on a sample of devices, and tests of malware and email defences. Plus must be completed within three months of passing the basic level.
Is Cyber Essentials a legal requirement?
Not in general law, but it is a contractual requirement for many UK central government contracts that involve handling personal data or providing certain IT services, and increasingly for NHS, local authority, education and defence supply chains. Larger private-sector customers and cyber insurers also ask for it as a condition of business or cover.
How long does Cyber Essentials take?
For a business that already has the controls in place, the self-assessment can be completed and returned within a week or two. For a typical small business with gaps, allow four to eight weeks for preparation such as enforcing MFA, retiring unsupported systems and putting patching under management. Cyber Essentials Plus adds an assessment day and any remediation, usually two to four weeks more.
Does Cyber Essentials cover the whole business?
By default it covers your whole organisation. You can define a smaller scope, such as one office or one network, but it must be a sensible, clearly separated sub-set and the certificate will say so. Most small businesses certify the whole organisation because customers and insurers expect it and because a partial scope invites questions.
How long is a Cyber Essentials certificate valid?
Twelve months. Recertification is an annual process, and the question set is updated periodically so the requirements can tighten between years. Treating renewal as a yearly review of your controls, rather than a form-filling exercise, is the most useful way to run it.
Does Dig IT Solutions certify Cyber Essentials?
No. Certification is issued only by certification bodies licensed through IASME, and it is a conflict of interest for the same firm to both fix your systems and mark the exam. We prepare businesses for certification: gap assessment, remediation, evidence and help with the questionnaire, then you submit to a certification body.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us