Cyber Essentials is a UK government-backed certification scheme managed by the National Cyber Security Centre (NCSC). It sets a baseline of five technical controls that protect businesses against the most common forms of cyber attack. Certification is open to organisations of any size, costs from £320 plus VAT, and is mandatory for any business bidding on UK government contracts that involve handling sensitive data.
What Cyber Essentials Actually Does
Most cyber attacks aren’t sophisticated. They’re automated, opportunistic, and aimed at the easiest targets available. Attackers probe thousands of systems looking for unpatched software, weak passwords, or misconfigured firewalls. If your defences are even slightly better than average, many attacks will simply move on.
That’s the logic behind Cyber Essentials. The scheme doesn’t try to harden you against nation-state threats or advanced persistent attacks. It focuses on the preventable stuff, the digital equivalent of leaving your front door unlocked, and sets a minimum standard that closes off the most common attack routes.
The NCSC estimates that the five controls at the heart of the scheme can protect against the majority of commodity cyber attacks. For most small and medium-sized businesses, getting certified is less about earning a badge and more about forcing a structured audit of your own systems.
The Cyber Essentials Checker: Start Before You Pay
Before committing to a formal assessment, use the free Cyber Essentials Readiness Tool on the NCSC website. This is the official cyber essentials checker, and it lets you work through the five control areas at your own pace to identify gaps before any money changes hands.
This matters more than it might seem. Around 80% of certification failures come down to configuration oversights rather than missing technology. Businesses that go straight to the paid assessment without a prior audit often fail on issues that would have taken an afternoon to fix. The readiness tool is free, takes a few hours to complete honestly, and will tell you exactly where you stand.
Key things to check before you start the formal process:
- Have all default admin passwords on routers and network devices been changed?
- Are software updates applied within 14 days of release across all devices in scope?
- Do staff accounts follow the principle of least privilege, meaning users only have access to what they actually need?
- Is multi-factor authentication enabled on internet-facing accounts and critical systems?
- Are all devices covered by active, updated malware protection?
If you’re running a business where staff work from home, pay particular attention to home routers. The default password printed on the back of a domestic router does not count as a changed password. Every remote worker’s router must have had its admin credentials changed, and this is one of the most frequently failed checks.
The Cyber Essentials Checklist: Five Controls Explained
The formal Cyber Essentials checklist covers five technical control areas. Every one of them must be in place to achieve certification.
Firewalls
Firewalls control traffic entering and leaving your network. Every internet-facing connection must be protected by a correctly configured firewall or equivalent boundary device. The scheme requires that default configurations are replaced, unnecessary ports and services are closed, and rules are documented and reviewed.
This applies to cloud services as well as on-premise networks. If your business uses cloud-hosted software, the firewall requirements extend to those environments too.
Secure Configuration
Devices and software must be configured to reduce unnecessary exposure. That means disabling features and services that aren’t needed, removing default accounts, and ensuring that the settings on every device in scope are actively managed rather than left on factory defaults.
This control catches a surprising number of businesses out. Many organisations install software, accept the defaults, and never revisit the configuration. Cyber Essentials requires you to demonstrate that you’ve made deliberate, security-conscious choices.
User Access Control
Access to systems and data should be restricted to those who genuinely need it. The scheme requires role-based access controls, regular reviews of who has access to what, and prompt revocation when someone leaves or changes role.
Multi-factor authentication is required for all administrator accounts and for any accounts accessing cloud services or systems from outside the network. This is non-negotiable under the current version of the scheme.
Malware Protection
All devices must be protected against malware, either through anti-malware software or application allow-listing. If you use anti-malware software, it must be kept up to date. If you use allow-listing, only explicitly approved applications should be permitted to run.
Businesses running modern versions of Windows with Windows Defender active and up to date will generally satisfy this control, provided the software is actually switched on and not suppressed by another tool.
Security Update Management
This is the control that catches the most businesses off guard. Cyber Essentials requires that high-risk and critical security updates are applied within 14 days of release. The scheme specifically looks at vulnerabilities with a CVSS score of 7 or above.
Any device running software that is no longer supported by the vendor, meaning it no longer receives security updates, will cause an automatic failure. If you’re running Windows 10 on any device in scope, check its support status before you apply.
Cyber Essentials vs Cyber Essentials Plus
There are two levels of certification. Understanding the difference is important before you decide which to pursue.
| Feature | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment method | Self-assessment questionnaire | Independent technical audit |
| Who verifies answers | Certification body reviews responses | Auditor tests systems directly |
| Evidence required | Your own declarations | Verified against live systems |
| Suitable for | Most SMEs, government contracts | Government contracts requiring Plus, higher-risk sectors |
| Typical cost | £320 to £600 + VAT | £1,500 to £5,000+ + VAT |
| Certificate validity | 12 months | 12 months |
For most small businesses, basic Cyber Essentials is sufficient. Cyber Essentials Plus is worth considering if you handle particularly sensitive data, work in regulated sectors such as financial services or healthcare, or if a customer or procurement framework specifically requires it.
Cyber Essentials Certification Cost: What to Budget
The cyber essentials certification cost depends on your organisation’s size. The pricing structure is tiered, with fees running from £320 plus VAT for micro-organisations up to £600 plus VAT for larger businesses. The table below gives the full breakdown.
| Organisation Size | Employees | Assessment Fee (+ VAT) |
|---|---|---|
| Micro | 0 to 9 | £320 |
| Small | 10 to 49 | £350 |
| Medium | 50 to 249 | £450 |
| Large | 250+ | £600 |
These are the assessment fees payable to the certification body. The total cyber essentials cost will almost always be higher once you account for the work required to meet the controls in the first place.
Remediation costs vary significantly. A business whose systems are already well-managed might spend nothing beyond the assessment fee. One starting from a low baseline might need to invest in new firewall hardware, updated software licences, or external consultancy support. Hardware and software remediation can run from £500 to £5,000 or more, depending on the size and complexity of your environment.
If you bring in a consultant to help prepare, rates typically run from £100 to £250 per hour in the UK. Factor in two to five days of work for a small business, more for anything more complex.
It’s worth noting that if your business turns over less than £20 million annually, achieving basic Cyber Essentials certification automatically includes free cyber liability insurance up to £25,000. This covers data recovery costs, business interruption, and legal expenses. For many micro and small businesses, that alone offsets a meaningful portion of the certification cost. Given that cyber security sits alongside other areas of business compliance, it’s worth reviewing your overall compliance posture at the same time, just as you would when staying compliant with commercial property management regulations.
Certification lasts 12 months. Budget for annual renewal from the outset.
Who Needs Cyber Essentials
Cyber Essentials is technically voluntary for most businesses, but in practice it’s becoming a de facto requirement in a growing number of contexts.
Any organisation bidding for UK central government contracts that involve handling personal data or providing certain technical products and services must hold a valid Cyber Essentials certificate. Many local authorities, NHS bodies, and large private-sector organisations are also starting to require it from suppliers.
Beyond procurement, there’s a strong case for certification on its own merits. It forces a structured review of your security posture, produces documented evidence that you’ve taken reasonable steps to protect data, and gives staff a clearer understanding of what good security practice looks like. That last point matters more than it might appear: physical and digital security measures work best when the people using them understand why they exist.
Sectors where Cyber Essentials is particularly worth pursuing include:
- Professional services handling client data, such as solicitors, accountants, and consultants
- Healthcare and social care providers
- Technology businesses and software developers
- Any business that processes payment card data or significant volumes of personal data
- Businesses supplying to the public sector or regulated industries
Quick Reference Summary
| Question | Answer |
|---|---|
| What is Cyber Essentials? | A UK government-backed certification covering five cyber security controls |
| Who runs it? | The National Cyber Security Centre (NCSC) |
| How many control areas? | Five: firewalls, secure configuration, access control, malware protection, patch management |
| Basic certification cost | £320 to £600 + VAT, depending on organisation size |
| Cyber Essentials Plus cost | Typically £1,500 to £5,000+ + VAT |
| Is it mandatory? | For most government contracts involving sensitive data, yes |
| How long does certification last? | 12 months |
| Free insurance included? | Yes, up to £25,000 cyber liability cover for organisations with under £20m turnover |
| Where to start? | Use the free Cyber Essentials Readiness Tool on the NCSC website |
Frequently Asked Questions
What is the Cyber Essentials checker and where do I find it?
The Cyber Essentials checker is the official Readiness Tool provided free by the NCSC on the Cyber Essentials website. It walks you through the five control areas before you commit to a paid assessment, helping you identify gaps in your current setup. Using it before applying for certification significantly reduces the chance of failing the formal assessment.
What are the five controls in the Cyber Essentials checklist?
The five controls are: firewalls, secure configuration, user access control, malware protection, and security update management. Every control must be fully in place for certification to be granted. Failing any single one, even a minor misconfiguration, will result in a failed assessment and require remediation before resubmission.
How much does Cyber Essentials certification cost?
The basic assessment fee starts at £320 plus VAT for micro-organisations with fewer than ten employees and rises to £600 plus VAT for organisations with 250 or more employees. Cyber Essentials Plus, which involves an independent technical audit, typically costs between £1,500 and £5,000 plus VAT, depending on the certification body and the scope of the audit.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment, where you answer a questionnaire and a certification body reviews your responses. Cyber Essentials Plus involves an independent auditor testing your systems directly to verify your answers. Plus costs significantly more but provides stronger assurance and is required for certain government contracts and higher-risk procurement frameworks.
Does Cyber Essentials certification come with free cyber insurance?
Yes. Organisations with an annual turnover below £20 million that achieve basic Cyber Essentials certification automatically receive free cyber liability insurance up to £25,000. The cover includes data recovery costs, business interruption losses, and legal expenses arising from a cyber incident. This is included at no extra cost through the certification body.
How long does Cyber Essentials certification last?
Certification is valid for 12 months from the date of issue. You’ll need to renew annually to maintain your certified status. Most certification bodies will contact you ahead of the renewal date, but it’s worth diarising the expiry date yourself to avoid a lapse, particularly if certification is a contractual requirement with a client or public sector body.
Can a small business fail Cyber Essentials because of remote workers?
Yes, and it’s more common than many businesses expect. Home routers are in scope if employees work from home regularly. The default admin password on a domestic router, typically printed on a sticker, does not meet the scheme’s requirements. Every home worker’s router must have had its credentials changed. This single oversight is one of the most frequent reasons small businesses fail their first assessment.
Is Cyber Essentials mandatory for UK businesses?
It’s mandatory for any organisation bidding on UK government contracts that involve handling personal data or providing certain technical services. For most other businesses it’s technically voluntary, though an increasing number of large private-sector organisations and public bodies now require it from suppliers. Even where it isn’t required, the five controls represent a sensible minimum standard for any business that handles data.
How long does it take to get Cyber Essentials certified?
For a business that already meets most of the controls, the process can take as little as one to two weeks from starting the questionnaire to receiving the certificate. Where remediation work is needed, such as patching unsupported software, reconfiguring firewalls, or rolling out multi-factor authentication, the timeline extends accordingly. Allow four to eight weeks if you’re starting from scratch.
What happens if my business fails the Cyber Essentials assessment?
You’ll receive feedback identifying which controls weren’t met. You can then carry out the necessary remediation and resubmit. Most certification bodies allow at least one resubmission within the original assessment period, though policies vary. There’s no penalty for failing, but you won’t receive a certificate until all five controls are fully in place. Using the free readiness tool before you apply is the most straightforward way to avoid this outcome.
Next Steps
If you haven’t used the Cyber Essentials Readiness Tool yet, that’s the right place to start. It’s free, takes a few hours to work through honestly, and will give you a clear picture of where your business stands against each of the five controls before any money is committed.
Once you’ve identified any gaps, the remediation work is usually more straightforward than it looks. Most businesses find that the main costs are time and, where external help is needed, a short burst of consultancy rather than significant new hardware. The annual renewal cost is predictable and, for smaller businesses, the included cyber liability insurance makes the net cost lower still. If you’re reviewing your business costs more broadly, the tax deductions available to small business owners may be worth checking at the same time, since some cyber security expenditure can qualify as an allowable business expense.


