Cyber Essentials is a UK government-backed certification that shows your business has the basic controls in place to defend against the most common cyber attacks.
It was created by the government and is overseen by the National Cyber Security Centre (NCSC). The idea behind it is simple: the majority of cyber attacks are not sophisticated, targeted operations. They are opportunistic, using well-known weaknesses that basic security hygiene would close. Cyber Essentials sets out five straightforward controls that, put in place properly, stop the bulk of those attacks. This post explains what it covers, why it is worth having, and exactly how to get certified.
Prefer to watch? Here's Cyber Essentials explained in five minutes, what it is, the five controls, and how to get certified.
Cyber Essentials is a certification scheme, not a piece of software. It confirms that your organisation meets a defined baseline of cyber security across five technical areas. You complete a self-assessment questionnaire about how your business is set up, and an accredited certification body reviews it and, if you meet the standard, certifies you.
The scheme is delivered on the NCSC's behalf by IASME, the sole delivery partner, working through a network of licensed certification bodies. Certification lasts for twelve months, after which you renew, which keeps your controls current as your business and the threats change.
There are two levels. Standard Cyber Essentials is a verified self-assessment: you declare that your controls are in place. Cyber Essentials Plus adds an independent technical audit that tests them. This post covers the standard certification. Part two covers Plus.
There are three practical reasons, beyond the obvious one of being more secure.
First, it genuinely reduces your risk. The NCSC designed the five controls to defend against the most common internet-based threats, the sort that make up the vast majority of attacks most businesses face. Getting the basics right is the single highest-value thing most organisations can do.
Second, it is increasingly required to win work. Cyber Essentials is mandatory for certain UK central government contracts, particularly those that involve handling personal data or providing certain technical products and services. Beyond government, a growing number of private-sector clients and tenders ask for it as a condition of doing business, because it is a quick, recognised signal that you take security seriously.
Third, it supports your cyber insurance. Many insurers now look for certification before offering good cover, and the standard certification includes cyber liability insurance for UK organisations with an annual turnover under £20 million, provided you certify your whole organisation.
For businesses operating across several sites, there is an added benefit: working towards Cyber Essentials forces you to apply the same controls consistently in every location, rather than leaving each office to do its own thing.
The certification is built around five technical controls. None of them is complicated, and most businesses already have parts of them in place.
Firewalls. A firewall sits between your internal network and the internet, controlling what is allowed in and out. The control is about making sure firewalls are in place and properly configured, rather than left on default settings.
Secure configuration. Devices and software often ship with settings that favour convenience over security, such as default passwords or unnecessary features switched on. This control is about tightening those, removing what you do not need and locking down what you do.
Security update management. Out-of-date software is one of the most common ways attackers get in. This control requires that supported software is kept up to date and that critical or high-risk security updates are applied promptly, usually within 14 days of release.
User access control. Not everyone needs access to everything. This control is about giving people only the access their role requires, managing admin accounts carefully, and using strong authentication such as multi-factor authentication to protect logins.
Malware protection. This covers protecting your devices from malicious software, whether through anti-malware tools, restricting devices to approved applications, or other approved methods.
The current assessment uses the NCSC's "Danzell" question set, in force since April 2026. It keeps the requirements in step with how businesses work today, and it made two things stricter: multi-factor authentication is now required across all cloud services where available, and high-risk or critical security updates must be applied within 14 days.
Getting certified takes five steps. First, choose your route: self-led, using IASME's free resources yourself, or supported, where a Cyber Advisor or certification body helps.
How long it takes depends almost entirely on how ready your controls already are. A well-run business might complete it in a week or two. One that needs to tighten patching, access control or configuration first should allow longer. This is where many businesses bring in their IT provider, both to get the controls right and to make the self-assessment straightforward.
Cyber Essentials costs between £320 and £600 plus VAT, depending on your organisation's size. The fee is set by IASME and tiered:
That fee covers the assessment itself, a year of unlimited self-assessment attempts, and the included cyber liability insurance for eligible organisations. Two things to keep in mind. Some certification bodies add their own fee on top of the IASME price, and if you need help preparing your controls or fixing gaps, that support is a separate cost. For most businesses, the preparation is the real investment, not the certificate fee.
Is Cyber Essentials right for your business?
For the large majority of organisations, yes. It is deliberately designed to suit businesses of any size and sector, and it gives you a recognised, affordable way to prove you have the fundamentals covered. If you handle client data, bid for contracts, or simply want to reduce your exposure to everyday attacks, it earns its place.
It is worth being clear about what it is and is not. Cyber Essentials is a baseline, not a complete security strategy. It closes the common gaps that most attacks exploit, but it sits alongside other measures such as staff training, backups and monitoring rather than replacing them. Think of it as the foundation you build on, and a credential you can show for it.
If Cyber Essentials is the verified self-assessment, the natural next question is how you prove those controls actually work in practice. That is what Cyber Essentials Plus adds, and it is what we cover in part two of this series.
Cyber Essentials is one of the highest-value, lowest-effort steps most businesses can take. The hardest part is usually getting the five controls lined up before you apply, and that is where we come in.
We have provided Cyber Essentials consultancy since the framework launched in 2014, and we help businesses across the UK get certified, across one site or many.
Find out how we can help: Cyber Essentials with entrust IT
FAQ
How long does Cyber Essentials certification last? Twelve months. After that you renew, which keeps your controls up to date as your business and the threat landscape change.
What is the difference between Cyber Essentials and Cyber Essentials Plus? Standard Cyber Essentials is a verified self-assessment: you declare how your controls are set up and a certification body reviews it. Cyber Essentials Plus adds an independent, hands-on technical audit that tests those controls in practice. Part two of this series covers Plus in detail.
How much does Cyber Essentials cost? The IASME fee is tiered by size, from £320 plus VAT for a micro organisation up to £600 plus VAT for a large one. Some certification bodies add their own fee, and any help preparing your controls is a separate cost.
Is Cyber Essentials mandatory? Not for every business, but it is required for some UK government contracts, especially those handling personal data, and a growing number of private-sector clients ask for it. Many insurers also look for it.
Do we need Cyber Essentials for every site? The certification covers your organisation, so the controls need to be applied consistently across all your locations and devices in scope. For multi-site businesses, that consistency is one of the main benefits of going through the process.