Call Anytime

0800 208 8456

Cyber Essentials Guide

Cyber Essentials: The UK Government Certification That's Becoming Impossible to Ignore

You’ve probably seen the term “Cyber Essentials” appearing more and more. On tender documents. In supply chain questionnaires. In emails from clients asking whether you’re certified. Maybe you’ve been putting it off because it sounds complicated, expensive, or both.

Here’s the good news: it’s neither. Cyber Essentials is a straightforward cybersecurity certification backed by the UK government. It proves that your business has the basic security controls in place to protect against the most common cyber threats.

This guide covers everything you need to know – in plain English – so you can decide whether it’s right for your business and how to get certified as quickly and painlessly as possible.

Cyber Essentials in Plain English

Cyber Essentials is a UK government-backed certification scheme designed to help businesses protect themselves against the most common cyberattacks. It was developed by the National Cyber Security Centre (NCSC) and is administered through accredited certification bodies. Full details are available at ncsc.gov.uk/cyberessentials.

There are two levels:

Level

Cyber Essentials

Cyber Essentials Plus

What It Involves

A self-assessment questionnaire verified by an external assessor
Everything above, plus an independent, hands-on technical audit of your systems

Best For

Businesses that need to demonstrate baseline cybersecurity controls
Businesses handling sensitive data, government work, or answering supply chain security requirements
Level What It Involves Best For
Cyber Essentials A self-assessment questionnaire verified by an external assessor Businesses that need to demonstrate baseline cybersecurity controls
Cyber Essentials Plus Everything above, plus an independent, hands-on technical audit of your systems Businesses handling sensitive data, government work, or answering supply chain security requirements

Every one of these is preventable. With the right IT provider, they should never be an issue in the first place.

Do You Actually Need Cyber Essentials?

Technically, Cyber Essentials is voluntary. In practice, it’s becoming essential for more and more businesses:
You bid on government contracts
Since 2014, Cyber Essentials has been a mandatory requirement for any UK government contract that involves handling sensitive or personal data. If you’re in the public sector supply chain, you need it.
Large organisations are increasingly requiring their suppliers and partners to hold Cyber Essentials certification. If you’ve been asked about it on a tender, questionnaire, or due diligence form, that’s only going to happen more frequently.
Some cyber insurance providers offer reduced premiums or more favourable terms for Cyber Essentials certified businesses. It’s a tangible financial incentive.
Being certified gives you a competitive edge. When two businesses bid for the same contract and one holds Cyber Essentials, the decision is easier for the buyer. It’s a trust signal that says “we take security seriously.”
Beyond the commercial advantages, the five controls that Cyber Essentials covers are genuinely effective at preventing the most common attacks. Getting certified isn’t just a badge – it’s a meaningful improvement in how well protected your business actually is.

"Cyber Essentials is no longer a nice-to-have. It's becoming the minimum standard your clients, insurers, and partners expect."

The Five Areas Cyber Essentials Covers

The certification is built around five technical controls. They’re not complicated, but they need to be done properly and applied consistently across your entire organisation.

Firewalls

What it means

Your business has a properly configured boundary between your internal network and the internet. This includes your main internet connection, your office routers, and any remote workers' home networks.

In practice

Every device that connects to the internet needs to be behind a firewall. Default passwords must be changed. Unnecessary services must be disabled.

Secure Configuration

What it means

Your computers, servers, and devices are set up securely - with unnecessary software removed, default accounts disabled, and only essential services running.

In practice

Every machine should be configured with security in mind, not convenience. Autorun features, guest accounts, and unnecessary software are all removed or disabled.

User Access Control

What it means

People can only access the systems and data they need for their role. Admin accounts are tightly controlled and only used when necessary.

In practice

Regular users should not have admin rights. Admin accounts should have separate, strong credentials. Access should be reviewed regularly, and leavers should be removed immediately.

Malware Protection

What it means

Your devices are protected against viruses, ransomware, and other malicious software.

In practice

Anti-malware software must be installed on all devices, kept up to date, and configured to scan regularly. The settings should prevent users from running untrusted applications or disabling the protection.

Security Update Management

What it means

All software and operating systems are kept up to date with the latest security patches.

In practice

Critical and high-severity patches must be applied within 14 days of release. Unsupported software (anything no longer receiving updates from the manufacturer) must be removed or isolated.

The five Cyber Essentials controls align closely with the SECUR IT Success Framework - particularly the Resist and Control pillars. Certification gives you a verifiable baseline that sits within a broader security strategy.

How Much Does Cyber Essentials Certification Cost?

The certification itself is not expensive. The cost, if there is one, comes from remediation – fixing the gaps that the assessment identifies. For businesses with a good IT provider already in place, most of the controls should already be covered.

Self-Assessment

£300 – £500

Basic certification for small to medium businesses.

Essentials Plus

£1,500 – £3,000

Includes a technical audit and verified vulnerability scan.

Recommended

IT Support

Varies

Expert help to prepare your network and remediate gaps.

For businesses working with Cyber Kaizen, Cyber Essentials readiness is built into our Standard and Premium plans. We handle the preparation, guide you through the assessment, and make sure you pass first time.

From Start to Certified - What to Expect?

If your IT is already well managed
Two to four weeks. The controls are likely already in place. It’s a matter of documenting them and completing the assessment.
Four to eight weeks. This includes fixing any gaps – updating outdated systems, tightening access controls, configuring firewalls properly – before submitting the assessment.
The Cyber Essentials self-assessment can be completed in a single day. Your IT provider should be doing the heavy lifting, not you. You’ll answer some questions about your business and sign off, but the technical detail should be handled by your IT team.
The independent audit typically takes half a day to a full day on-site (or remotely), depending on the size and complexity of your environment.

Why Businesses Fail Cyber Essentials and How to Avoid It?

The most common reasons are surprisingly simple:

Outdated Software

If any device in your organisation is running an operating system or application that's no longer supported, you'll fail.

Critical Impact

Unpatched systems

Security patches that haven't been applied within 14 days of release will cause a failure.

High Impact

Everyone has admin rights

If regular users have admin access on their machines, that's a fail.

Critical Impact

No MFA on cloud services

If your Microsoft 365 or email accounts don't have multi-factor authentication enabled, you'll fail.

Critical Impact

Default passwords still in use

On routers, firewalls, printers, or any network devices.

High Impact

Every one of these is preventable. With the right IT provider, they should never be an issue in the first place.

Want to Get Cyber Essentials Certified?
We'll Get You There.

We’ve helped dozens of UK businesses achieve Cyber Essentials and Cyber Essentials Plus certification – first time, every time. We’ll handle the preparation, the remediation, and the assessment process.

Start with a free IT Health Check. We’ll assess your current posture against the five Cyber Essentials controls and tell you exactly where you stand – and what needs fixing before you apply.

No obligation. No jargon. Just a clear path to certification.

"Cyber Kaizen made the whole Cyber Essentials process painless. We passed first time and barely had to lift a finger."

- Managing Director

65-employee engineering firm

Prefer to learn live?

Join our next free webinar.

You Might Also Like

Cybersecurity Essentials: Where to Start

Six steps that cover 90% of your risk, in plain English.

Download the Free Guide

How to Switch IT Provider Without Disruption

The step-by-step process for switching without downtime.

Download the Free Guide

Download the Free Guide

Fill the form below to download the guide