Contents
Introduction
If Cyber Essentials keeps appearing in your tenders, supplier questionnaires and insurance renewals, you are not alone. It has become one of the most requested pieces of paper in UK business, and yet very few of the people being asked for it have been told plainly what it actually is. This guide fixes that by answering the question: what is Cyber Essentials? It explains what Cyber Essentials covers, how it differs from Cyber Essentials Plus, what it costs, and where it sits in a sensible security plan, so you can decide whether you need it and what to do next.
Cybersecurity has a lot of confusing jargon, but don’t worry, we have an A-Z Cybersecurity Glossary that can help make cybersecurity easier to understand.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme that shows you have put five basic security controls in place. It was launched in 2014, it is overseen by the National Cyber Security Centre (NCSC), and since 2020 it has been run day to day by IASME as the NCSC’s delivery partner. When you certify, you complete a questionnaire about how your organisation is set up, and a qualified assessor reviews your answers.
The point of the scheme is deliberately modest. Most successful attacks are not the work of elite hackers; they are automated attempts that sweep the internet looking for the easy targets, meaning the unpatched device, the account with no multi-factor authentication, the default password nobody changed. Cyber Essentials is designed to close those open doors, which is enough to make your organisation a poor target for the high-volume, low-effort attacks that make up the bulk of the threat.
The five technical controls
Everything in Cyber Essentials comes back to five control areas. The exact requirements are reviewed and tightened periodically, so always check the current version with IASME before you certify, but the five areas themselves are stable.
- Firewalls. Making sure the boundary between your systems and the internet is properly configured, so only the traffic that should get through does.
- Secure configuration. Setting up devices and software safely rather than leaving them on their default settings, which are widely known and easily abused.
- Security update management. Keeping operating systems and applications patched, because unpatched software is one of the most common ways in.
- User access control. Giving people only the access they need, and keeping administrator rights limited to those who genuinely require them.
- Malware protection. Having a sensible defence against malicious software, whether through anti-malware tools, application allow-listing, or both.
None of these is exotic, but the value of the scheme is that it makes you confirm, in writing and to an assessor, that you actually do all five consistently, which is where a surprising number of organisations discover a gap.
Cyber Essentials versus Cyber Essentials Plus
If you’ve asked yourself, “what is cyber essentials?”, then you’ve probably also wondered, “what is cyber essentials plus?” Basically, there are two levels, and the difference comes down to who checks the work.
Standard Cyber Essentials is a self-assessment, where you answer the questionnaire honestly, and an assessor reviews your responses. Cyber Essentials Plus covers the same five controls, but adds an independent, hands-on technical audit, where a certified assessor runs external vulnerability scans and checks a sample of your actual devices to verify that the controls are really in place rather than simply declared. In other words, standard Cyber Essentials takes your word for it, and Cyber Essentials Plus comes and looks.
Plus builds on the standard certificate rather than replacing it, and it normally has to be completed within three months of passing the basic assessment. If you are heading for the audit, our guide on how to prepare for your Cyber Essentials Plus audit walks through what to expect and how to avoid the common trip-ups.
What does Cyber Essentials cost?
The headline fee for standard Cyber Essentials is set by IASME and tiered by organisation size. As of 2026 it ranges from roughly £320 plus VAT for a micro organisation up to about £600 plus VAT for a large one, and the certificate lasts twelve months, so you recertify each year to keep it valid. Because the tiers are reviewed periodically, it is worth confirming the current figure with your certification body before you budget.
Cyber Essentials Plus costs more because of the technical audit, and it is priced by the assessor according to the size and complexity of your environment, commonly in the range of £1,500 to £3,000 plus VAT. Notably, the assessment fee is rarely the biggest number. For most organisations the larger cost is the remediation work needed to meet the controls in the first place, which is still far cheaper than dealing with a breach.
There is one benefit that often goes unnoticed. Eligible UK organisations with an annual turnover under £20 million that certify their whole organisation automatically receive £25,000 of cyber liability insurance at no extra cost, which for a smaller business can offset a meaningful chunk of the fee.
Why bother getting certified?
The most compelling reason is that the controls genuinely work against the attacks most businesses actually face. According to the NCSC’s 2024 Annual Review, organisations that implement the Cyber Essentials controls are 92% less likely to make a claim on their cyber insurance, which is a striking figure for a baseline scheme.
Beyond the security itself, certification has become a commercial requirement. It has been mandatory since 2014 for UK government contracts that involve handling sensitive or personal data, and larger companies increasingly expect their suppliers to hold it before they will do business, which means a missing certificate can quietly cost you work. It also functions as a trust signal to clients and insurers who want evidence that you take the basics seriously, particularly if you are too small to be chasing a full ISO 27001 programme yet.
Where Cyber Essentials fits, and where it stops
Here is the part that matters most, and the part the certificate itself will never tell you. Cyber Essentials is a baseline, and not a finish line. It is a questionnaire and an evidence review, not a security assessment, which means it does not include penetration testing, threat-led attack simulation, monitoring or incident response rehearsal. It confirms the front door is locked; it does not test what a determined attacker could do once they start trying.
Crucially, that is not a criticism of the scheme, because it was never meant to do those things. The mistake is treating the certificate as proof that you are secure. Passing Cyber Essentials and then stopping is how organisations end up with a valid certificate on the wall and a serious weakness nobody has ever looked for. We cover that gap in more detail in why Cyber Essentials alone will not protect your business, which is worth reading before you assume the box is ticked.
For most organisations the sensible path is to earn Cyber Essentials first, then build on it: independent testing to find the weaknesses the questionnaire cannot see, and, depending on your sector, the standards that sit above it, such as ISO 27001 or the compliance-driven testing behind frameworks like PCI DSS. If you want to talk through what that next step looks like for your setup, our penetration testing services are a good place to start.
How to get certified
The process is more straightforward than the official language suggests. In short:
- Check your readiness. The NCSC provides a free readiness tool, and going through it first tells you where your gaps are before you pay for anything.
- Fix the gaps. This is the remediation work mentioned above, and it is usually the real effort involved.
- Choose an IASME-approved certification body and complete the self-assessment questionnaire.
- Pass the assessment and receive your certificate, badge and register listing.
- If you need it, book your Cyber Essentials Plus audit within three months of passing.
Conclusion
Cyber Essentials is the right first move for almost any UK organisation. It is affordable, it is widely recognised, it opens doors with clients and insurers, and it measurably reduces your risk from the attacks you are most likely to meet. Just hold on to the distinction that matters: it proves you have the basics in place, and the basics are the start of a security plan rather than the whole of one.
When you have outgrown the questionnaire and want to know what an attacker could actually reach, that is where testing comes in. You can book a call and we will point you towards the right next step, whether that is certification support or your first pentest.