Cyber Essentials Explained: A Guide for Business Owners

Cyber Essentials is a UK government-backed certification scheme managed by the National Cyber Security Centre (NCSC). It sets a baseline of five technical controls that protect businesses against the most common forms of cyber attack. Certification is open to organisations of any size, costs from £320 plus VAT, and is mandatory for any business bidding on UK government contracts that involve handling sensitive data.

What Cyber Essentials Actually Does

Most cyber attacks aren’t sophisticated. They’re automated, opportunistic, and aimed at the easiest targets available. Attackers probe thousands of systems looking for unpatched software, weak passwords, or misconfigured firewalls. If your defences are even slightly better than average, many attacks will simply move on.

That’s the logic behind Cyber Essentials. The scheme doesn’t try to harden you against nation-state threats or advanced persistent attacks. It focuses on the preventable stuff, the digital equivalent of leaving your front door unlocked, and sets a minimum standard that closes off the most common attack routes.

The NCSC estimates that the five controls at the heart of the scheme can protect against the majority of commodity cyber attacks. For most small and medium-sized businesses, getting certified is less about earning a badge and more about forcing a structured audit of your own systems.

The Cyber Essentials Checker: Start Before You Pay

Before committing to a formal assessment, use the free Cyber Essentials Readiness Tool on the NCSC website. This is the official cyber essentials checker, and it lets you work through the five control areas at your own pace to identify gaps before any money changes hands.

This matters more than it might seem. Around 80% of certification failures come down to configuration oversights rather than missing technology. Businesses that go straight to the paid assessment without a prior audit often fail on issues that would have taken an afternoon to fix. The readiness tool is free, takes a few hours to complete honestly, and will tell you exactly where you stand.

Key things to check before you start the formal process:

  • Have all default admin passwords on routers and network devices been changed?
  • Are software updates applied within 14 days of release across all devices in scope?
  • Do staff accounts follow the principle of least privilege, meaning users only have access to what they actually need?
  • Is multi-factor authentication enabled on internet-facing accounts and critical systems?
  • Are all devices covered by active, updated malware protection?

If you’re running a business where staff work from home, pay particular attention to home routers. The default password printed on the back of a domestic router does not count as a changed password. Every remote worker’s router must have had its admin credentials changed, and this is one of the most frequently failed checks.

The Cyber Essentials Checklist: Five Controls Explained

The formal Cyber Essentials checklist covers five technical control areas. Every one of them must be in place to achieve certification.

Firewalls

Firewalls control traffic entering and leaving your network. Every internet-facing connection must be protected by a correctly configured firewall or equivalent boundary device. The scheme requires that default configurations are replaced, unnecessary ports and services are closed, and rules are documented and reviewed.

This applies to cloud services as well as on-premise networks. If your business uses cloud-hosted software, the firewall requirements extend to those environments too.

Secure Configuration

Devices and software must be configured to reduce unnecessary exposure. That means disabling features and services that aren’t needed, removing default accounts, and ensuring that the settings on every device in scope are actively managed rather than left on factory defaults.

This control catches a surprising number of businesses out. Many organisations install software, accept the defaults, and never revisit the configuration. Cyber Essentials requires you to demonstrate that you’ve made deliberate, security-conscious choices.

User Access Control

Access to systems and data should be restricted to those who genuinely need it. The scheme requires role-based access controls, regular reviews of who has access to what, and prompt revocation when someone leaves or changes role.

Multi-factor authentication is required for all administrator accounts and for any accounts accessing cloud services or systems from outside the network. This is non-negotiable under the current version of the scheme.

Malware Protection

All devices must be protected against malware, either through anti-malware software or application allow-listing. If you use anti-malware software, it must be kept up to date. If you use allow-listing, only explicitly approved applications should be permitted to run.

Businesses running modern versions of Windows with Windows Defender active and up to date will generally satisfy this control, provided the software is actually switched on and not suppressed by another tool.

Security Update Management

This is the control that catches the most businesses off guard. Cyber Essentials requires that high-risk and critical security updates are applied within 14 days of release. The scheme specifically looks at vulnerabilities with a CVSS score of 7 or above.

Any device running software that is no longer supported by the vendor, meaning it no longer receives security updates, will cause an automatic failure. If you’re running Windows 10 on any device in scope, check its support status before you apply.

Cyber Essentials vs Cyber Essentials Plus

There are two levels of certification. Understanding the difference is important before you decide which to pursue.

FeatureCyber EssentialsCyber Essentials Plus
Assessment methodSelf-assessment questionnaireIndependent technical audit
Who verifies answersCertification body reviews responsesAuditor tests systems directly
Evidence requiredYour own declarationsVerified against live systems
Suitable forMost SMEs, government contractsGovernment contracts requiring Plus, higher-risk sectors
Typical cost£320 to £600 + VAT£1,500 to £5,000+ + VAT
Certificate validity12 months12 months

For most small businesses, basic Cyber Essentials is sufficient. Cyber Essentials Plus is worth considering if you handle particularly sensitive data, work in regulated sectors such as financial services or healthcare, or if a customer or procurement framework specifically requires it.

Cyber Essentials Certification Cost: What to Budget

The cyber essentials certification cost depends on your organisation’s size. The pricing structure is tiered, with fees running from £320 plus VAT for micro-organisations up to £600 plus VAT for larger businesses. The table below gives the full breakdown.

Organisation SizeEmployeesAssessment Fee (+ VAT)
Micro0 to 9£320
Small10 to 49£350
Medium50 to 249£450
Large250+£600

These are the assessment fees payable to the certification body. The total cyber essentials cost will almost always be higher once you account for the work required to meet the controls in the first place.

Remediation costs vary significantly. A business whose systems are already well-managed might spend nothing beyond the assessment fee. One starting from a low baseline might need to invest in new firewall hardware, updated software licences, or external consultancy support. Hardware and software remediation can run from £500 to £5,000 or more, depending on the size and complexity of your environment.

If you bring in a consultant to help prepare, rates typically run from £100 to £250 per hour in the UK. Factor in two to five days of work for a small business, more for anything more complex.

It’s worth noting that if your business turns over less than £20 million annually, achieving basic Cyber Essentials certification automatically includes free cyber liability insurance up to £25,000. This covers data recovery costs, business interruption, and legal expenses. For many micro and small businesses, that alone offsets a meaningful portion of the certification cost. Given that cyber security sits alongside other areas of business compliance, it’s worth reviewing your overall compliance posture at the same time, just as you would when staying compliant with commercial property management regulations.

Certification lasts 12 months. Budget for annual renewal from the outset.

Who Needs Cyber Essentials

Cyber Essentials is technically voluntary for most businesses, but in practice it’s becoming a de facto requirement in a growing number of contexts.

Any organisation bidding for UK central government contracts that involve handling personal data or providing certain technical products and services must hold a valid Cyber Essentials certificate. Many local authorities, NHS bodies, and large private-sector organisations are also starting to require it from suppliers.

Beyond procurement, there’s a strong case for certification on its own merits. It forces a structured review of your security posture, produces documented evidence that you’ve taken reasonable steps to protect data, and gives staff a clearer understanding of what good security practice looks like. That last point matters more than it might appear: physical and digital security measures work best when the people using them understand why they exist.

Sectors where Cyber Essentials is particularly worth pursuing include:

  • Professional services handling client data, such as solicitors, accountants, and consultants
  • Healthcare and social care providers
  • Technology businesses and software developers
  • Any business that processes payment card data or significant volumes of personal data
  • Businesses supplying to the public sector or regulated industries

Quick Reference Summary

QuestionAnswer
What is Cyber Essentials?A UK government-backed certification covering five cyber security controls
Who runs it?The National Cyber Security Centre (NCSC)
How many control areas?Five: firewalls, secure configuration, access control, malware protection, patch management
Basic certification cost£320 to £600 + VAT, depending on organisation size
Cyber Essentials Plus costTypically £1,500 to £5,000+ + VAT
Is it mandatory?For most government contracts involving sensitive data, yes
How long does certification last?12 months
Free insurance included?Yes, up to £25,000 cyber liability cover for organisations with under £20m turnover
Where to start?Use the free Cyber Essentials Readiness Tool on the NCSC website

Frequently Asked Questions

What is the Cyber Essentials checker and where do I find it?

The Cyber Essentials checker is the official Readiness Tool provided free by the NCSC on the Cyber Essentials website. It walks you through the five control areas before you commit to a paid assessment, helping you identify gaps in your current setup. Using it before applying for certification significantly reduces the chance of failing the formal assessment.

What are the five controls in the Cyber Essentials checklist?

The five controls are: firewalls, secure configuration, user access control, malware protection, and security update management. Every control must be fully in place for certification to be granted. Failing any single one, even a minor misconfiguration, will result in a failed assessment and require remediation before resubmission.

How much does Cyber Essentials certification cost?

The basic assessment fee starts at £320 plus VAT for micro-organisations with fewer than ten employees and rises to £600 plus VAT for organisations with 250 or more employees. Cyber Essentials Plus, which involves an independent technical audit, typically costs between £1,500 and £5,000 plus VAT, depending on the certification body and the scope of the audit.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment, where you answer a questionnaire and a certification body reviews your responses. Cyber Essentials Plus involves an independent auditor testing your systems directly to verify your answers. Plus costs significantly more but provides stronger assurance and is required for certain government contracts and higher-risk procurement frameworks.

Does Cyber Essentials certification come with free cyber insurance?

Yes. Organisations with an annual turnover below £20 million that achieve basic Cyber Essentials certification automatically receive free cyber liability insurance up to £25,000. The cover includes data recovery costs, business interruption losses, and legal expenses arising from a cyber incident. This is included at no extra cost through the certification body.

How long does Cyber Essentials certification last?

Certification is valid for 12 months from the date of issue. You’ll need to renew annually to maintain your certified status. Most certification bodies will contact you ahead of the renewal date, but it’s worth diarising the expiry date yourself to avoid a lapse, particularly if certification is a contractual requirement with a client or public sector body.

Can a small business fail Cyber Essentials because of remote workers?

Yes, and it’s more common than many businesses expect. Home routers are in scope if employees work from home regularly. The default admin password on a domestic router, typically printed on a sticker, does not meet the scheme’s requirements. Every home worker’s router must have had its credentials changed. This single oversight is one of the most frequent reasons small businesses fail their first assessment.

Is Cyber Essentials mandatory for UK businesses?

It’s mandatory for any organisation bidding on UK government contracts that involve handling personal data or providing certain technical services. For most other businesses it’s technically voluntary, though an increasing number of large private-sector organisations and public bodies now require it from suppliers. Even where it isn’t required, the five controls represent a sensible minimum standard for any business that handles data.

How long does it take to get Cyber Essentials certified?

For a business that already meets most of the controls, the process can take as little as one to two weeks from starting the questionnaire to receiving the certificate. Where remediation work is needed, such as patching unsupported software, reconfiguring firewalls, or rolling out multi-factor authentication, the timeline extends accordingly. Allow four to eight weeks if you’re starting from scratch.

What happens if my business fails the Cyber Essentials assessment?

You’ll receive feedback identifying which controls weren’t met. You can then carry out the necessary remediation and resubmit. Most certification bodies allow at least one resubmission within the original assessment period, though policies vary. There’s no penalty for failing, but you won’t receive a certificate until all five controls are fully in place. Using the free readiness tool before you apply is the most straightforward way to avoid this outcome.

Next Steps

If you haven’t used the Cyber Essentials Readiness Tool yet, that’s the right place to start. It’s free, takes a few hours to work through honestly, and will give you a clear picture of where your business stands against each of the five controls before any money is committed.

Once you’ve identified any gaps, the remediation work is usually more straightforward than it looks. Most businesses find that the main costs are time and, where external help is needed, a short burst of consultancy rather than significant new hardware. The annual renewal cost is predictable and, for smaller businesses, the included cyber liability insurance makes the net cost lower still. If you’re reviewing your business costs more broadly, the tax deductions available to small business owners may be worth checking at the same time, since some cyber security expenditure can qualify as an allowable business expense.

Business Division
Business Division
Business Division is a blog put together to share free tips, advice and insightful information, helpful to the UK business owners. We cover topics relating to sales and marketing, finance, legal, health and safety and investment-related insights.

Related posts

Latest posts

What Is an Addendum to a Contract?

# Don't Let Verbal Agreements Unravel Your Contracts When a client asks for extra work, a deadline shifts, or a new party enters the picture, what protects you legally? If your answer is "we sorted it over email," you may be more exposed than you think. A contract addendum is the proper tool for documenting changes to signed agreements — and without one, courts will default to the original document. Discover exactly what an addendum must include, how it differs from an amendment, and when your business genuinely needs one.

What Is a Board Resolution? A Guide for Company Owners

Decisions made informally at board level can unravel quickly when a bank, regulator, or shareholder starts asking questions. A board resolution is the document that proves your company acted correctly — by the right people, through the right process, with the right authority. Yet many company owners either skip them entirely or draft them poorly. This guide explains exactly what a board resolution is, how it works, which type you need, and where things commonly go wrong.

UK GDPR vs EU GDPR: What Business Owners Need to Know

# UK GDPR and EU GDPR Aren't the Same — and the Gap Is Growing If you assumed Brexit simply copy-pasted EU data protection law into UK legislation, think again. Whilst UK GDPR and EU GDPR share the same DNA, they are now distinct legal regimes — and the Data (Use and Access) Act 2025 has pushed them further apart. From a brand-new seventh lawful basis to relaxed rules on automated decision-making and analytics cookies, the differences are real and carry serious compliance implications. If your business serves customers on both sides of the Channel, you need to understand exactly where the two frameworks diverge.