Cyber Security
What is Cyber Essentials? (And does your business need it?)
Cyber Essentials explained for UK small businesses: the five controls, Cyber Essentials vs Plus, who requires it, and the process, timeline and cost.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
Cyber Essentials is the UK government-backed certification, run by the NCSC through IASME, that confirms an organisation has five technical controls in place: firewalls, secure configuration, security update management, user access control and malware protection. You need it for public-sector contracts, cyber insurance on good terms, or customers who ask, and it is the right baseline for any SME.
If a customer, a tender or an insurer has asked whether you hold Cyber Essentials, you probably want two things: a clear explanation of what it is, and an honest view on whether it is worth doing for a business your size. This guide gives both, with the process, the timeline and the practical work involved for a firm of up to 250 people.
Cyber Essentials in one paragraph
Cyber Essentials is a UK government scheme, owned by the National Cyber Security Centre and delivered by IASME as the sole certification partner, that certifies an organisation has implemented five basic technical controls. Those five controls were chosen because they stop the large majority of common, untargeted cyber attacks: the automated scanning, credential stuffing, phishing and commodity malware that hit small businesses far more often than anything sophisticated. It is deliberately achievable by organisations with no security team, it is renewed annually, and it comes in two levels.
The five controls
Every question in the Cyber Essentials assessment maps to one of these. If you understand them, you understand the scheme.
1. Firewalls. Every device must be protected by a firewall: a boundary firewall between your network and the internet, and the software firewall on each computer. Default administrative passwords must be changed, administrative interfaces must not be reachable from the internet unless there is a documented need with MFA or IP restriction, and any service opened to the internet must have a business justification and be closed when no longer needed. In practice this means no remote desktop exposed to the world and a firewall that someone actually manages.
2. Secure configuration. Devices and software are set up to reduce their exposure: unnecessary accounts and software removed, default passwords changed, auto-run disabled, and devices locked with a PIN, password or biometric. The requirements set minimum standards for device locks and for how passwords are protected against brute force. Encryption is not strictly required, but it is expected practice and it is what protects you if a laptop goes missing.
3. Security update management. All software must be licensed and supported, and updates that the vendor rates as critical or high-risk must be applied within 14 days of release. Unsupported software, such as Windows 10 since October 2025 without extended support, is an automatic fail. This is the control that most often catches businesses out, because "updates are on" is not the same as being able to show every device is within 14 days.
4. User access control. Each person has their own account, access is granted on the basis of need, administrator accounts are separate from day-to-day accounts and used only for admin tasks, accounts are removed when people leave, and multi-factor authentication is enabled on all cloud services that offer it. There are minimum password standards and a requirement to protect against brute-force attempts. Our offboarding checklist and MFA guide cover the two parts that most SMEs need to fix.
5. Malware protection. Every device runs anti-malware software that is kept up to date and configured to scan files and web content, or is protected by application control that only permits approved software to run. Modern endpoint detection and response satisfies this comfortably, consumer antivirus on some machines and nothing on the server does not.
The scope is every device that accesses organisational data or services, including personally owned phones and laptops used for work email. That surprises many businesses and is why a bring-your-own-device policy with management is usually part of the preparation.
Cyber Essentials versus Cyber Essentials Plus
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| What it is | Verified self-assessment questionnaire | Independent technical audit of the same controls |
| Who checks | A director signs a declaration, a qualified assessor reviews the answers | An assessor tests: external vulnerability scan, internal scan and checks on a sample of devices, malware and email attachment tests, MFA and account separation checks |
| Prerequisite | None | A current Cyber Essentials certificate, with Plus completed within three months of it |
| Typical effort | Days to complete once controls are in place | An assessment day plus remediation of anything found |
| Cost | Fixed fee banded by organisation size, from a few hundred pounds | Set by the certification body, typically four figures, depending on size and number of sites |
| Who asks for it | Most public-sector contracts, most insurers and customers | Higher-risk contracts, MoD and some NHS or regulated supply chains, customers wanting independent verification |
For most small businesses, Cyber Essentials is the right first step and often all that is asked for. Plus is worth it when a contract requires it, when you want independent evidence for customers, or when you want to be sure the controls really are in place rather than believed to be. Our companion article on how much Cyber Essentials costs sets out the fees and the real cost, which is remediation.
Who requires it
Public-sector contracts. Since 2014 UK central government has required Cyber Essentials for suppliers bidding for contracts that involve handling personal information or providing certain IT products and services. The Ministry of Defence applies it across its supply chain, and NHS bodies, local authorities, housing associations and universities increasingly include it in tenders. If you supply, or want to supply, any of these, assume it is a requirement.
Larger private customers. Supplier security questionnaires from corporate clients now routinely ask for Cyber Essentials, and some accept it in place of a lengthy bespoke questionnaire. It is a quick way for a customer to know you meet a recognised baseline.
Insurers. Cyber insurance applications ask about MFA, patching, backups and endpoint protection, which are the Cyber Essentials controls in different words. Certification makes the application straightforward, and organisations under a turnover threshold that certify the whole organisation are offered cyber liability insurance through the scheme at no extra cost, with details on the IASME site.
Your own standards. Even without an external demand, the five controls are the sensible baseline for any business connected to the internet, and the annual cycle forces a review that would otherwise not happen.
The process, step by step
- Gap assessment. Review your systems against the current question set: every device, every cloud service, every user, every firewall. This is where the surprises are found, such as the unsupported server, MFA exceptions, or the depot manager's personal laptop.
- Remediation. Fix the gaps. For a typical SME this means enforcing MFA and conditional access, removing local administrator rights, putting patching under management with reporting, replacing or upgrading unsupported systems, tidying firewall rules, and deploying EDR everywhere.
- Evidence and documentation. Build the device and software inventory, confirm the scope, and write down the processes the questionnaire asks about (leaver removal, patch timescales, device standards).
- Choose a certification body. IASME licenses certification bodies across the UK, you buy the assessment from one of them. Pick one that is responsive and comfortable with businesses your size.
- Complete the self-assessment. The questionnaire is answered online. A board member or equivalent signs the declaration. The assessor reviews and may come back with clarifications, you have a short window to respond.
- Certificate issued. Valid for twelve months. You appear on the public register and can use the badge.
- Cyber Essentials Plus, if required. Book the audit within three months of the basic certificate. The assessor scans your external addresses, tests a sample of devices and user accounts, and checks that malware protection and email defences behave as claimed.
- Maintain and renew. The controls have to stay in place all year. Monitoring and managed patching keep you compliant between certificates, see why security needs continuous monitoring.
Typical timeline
A business that already runs managed patching, EDR, enforced MFA and a proper firewall can complete the questionnaire in a week or two. A business starting from a mixed estate with some unsupported machines and partial MFA should allow four to eight weeks for preparation, most of which is doing the remediation, not paperwork. Plus adds an assessment day and typically two to four weeks for scheduling and any fixes.
The single biggest cause of delay is hardware: discovering that several PCs cannot run a supported operating system and need replacing. Finding that out early is the main value of the gap assessment.
Where Dig IT fits
We do not certify. Certification bodies are licensed by IASME, and it is a conflict of interest for the firm that fixes your systems to also mark the exam. What we do is prepare businesses for it: a cyber security audit against the five controls, the remediation work, the evidence, and support through the questionnaire and any Plus assessment. For businesses we already support, most of the controls are part of the managed service and the annual renewal is a light task. Our Cyber Essentials preparation service describes the engagement.
Does your business need it?
If you sell to the public sector or to larger companies, yes, and sooner rather than later, because it takes weeks to prepare and tenders do not wait. If you want cyber insurance on sensible terms, it will make the application easier. If neither applies, the honest answer is that you still need the five controls, because they are what stop the attacks that actually reach small businesses, and certification is a modest extra cost that proves you have them.
What to do next
If you have been asked for Cyber Essentials or want to know how far away you are, start with an IT health check. It assesses your systems against the five controls and gives you a plain list of what would need to change, how long it would take and what it would cost.

