Guide
The small business guide to Cyber Essentials
Cyber Essentials is a UK government-backed certification covering five basic technical controls: firewalls, secure configuration, user access control, malware protection and security update management. Certification costs a few hundred pounds for a small business and takes a few weeks. The certificate is the easy part; the value is in the remediation work you do to earn it.
By James 10 min read
What Cyber Essentials actually is
Cyber Essentials is a certification scheme backed by the National Cyber Security Centre and delivered through IASME. It assesses whether a business has five basic technical controls in place. It is deliberately not a comprehensive security standard. It is a floor, aimed at the attacks that make up the overwhelming majority of what actually happens to small businesses.
There are two levels. Cyber Essentials is a self-assessment questionnaire, verified by an assessor. Cyber Essentials Plus is the same set of controls with hands-on technical verification, an assessor tests your machines rather than taking your word for it.
The scheme is renewed annually. That matters, because the controls are not a one-off project: they describe a state you have to keep being in.
The five controls, in plain terms
Firewalls. Every device is behind a properly configured firewall, whether that is a boundary firewall at the office or the software firewall on a laptop working from a coffee shop. Default administrative passwords are changed, and inbound rules exist only where there is a documented business need.
Secure configuration. Devices and software are set up deliberately rather than left at defaults. Unnecessary accounts and software are removed, default passwords are changed, and auto-run is disabled. This is the control most often failed on details nobody thinks about: a spare admin account left over from setup, a piece of software installed for a trial in 2022.
User access control. People have the access their job needs and no more. Administrative accounts are separate from day-to-day accounts, and they are not used for reading email. Accounts are removed when people leave. Multi-factor authentication is required on cloud services.
Malware protection. Endpoint protection is installed, kept current, and actually monitored, on every device in scope, including the ones people bought themselves and use for work.
Security update management. Everything in scope is supported by its vendor and patched. High and critical severity updates are applied within 14 days. This is the control that catches most businesses out, because it includes third-party software and it includes the machine nobody has logged into since February.
Free, before any money changes hands
Want this looked at properly, for nothing?
Ninety minutes mapping how the work actually flows, then a written plan and a fixed quote you keep either way. A working session, not a sales meeting.
- No obligation, no follow-up sequence
- You keep the plan and the quote
or call 01623 354250
What it costs, honestly
The certification fee itself is banded by organisation size and starts at a few hundred pounds for a micro business, rising into the high hundreds for larger small businesses. Cyber Essentials Plus adds an assessor’s hands-on testing and typically costs between one and a half and three thousand pounds depending on size and complexity.
That is not the real cost. The real cost is the remediation: the machines running an unsupported operating system, the admin accounts that need restructuring, the multi-factor rollout, and occasionally a firewall that needs replacing because it stopped receiving updates two years ago.
For a business that is broadly in decent shape, remediation is a few days of work. For one that has not looked at any of this for five years, it can be a genuine project. That is why a gap analysis first is worth doing. It converts an unknown into a number before you commit to a submission date.
Preparation is included on our Complete plan
Gap analysis against the five controls, the remediation work, and the evidence gathering that makes the assessment straightforward rather than a scramble. Most of the underlying controls are in place on the Support plan anyway. The Complete plan adds the structured preparation and the evidence.
Do you actually need it?
You need it if you bid for central government contracts involving sensitive information. It has been mandatory for those since 2014. Increasingly you also need it if you supply larger private organisations, because it has become a standard question in supplier due diligence, or if your professional indemnity insurer has started asking.
You do not need it simply because someone told you it was best practice. If nobody is asking, the honest position is that doing the five controls properly is worth far more than the certificate, and you can do that without paying an assessor.
Where the certificate does add value beyond contracts is as a forcing function. Plenty of businesses have known for years that their patching is patchy and their admin accounts are a mess. A submission date is remarkably effective at getting that fixed.
Where small businesses most often fail
Unsupported software in scope. An old operating system on one machine in the corner, or a phone that no longer receives security updates, will fail an otherwise clean assessment. Scope everything before you start rather than discovering it at question forty.
Multi-factor authentication not applied to everything. Applying it to most accounts is not a pass. Administrator accounts in particular have to be covered.
Administrator accounts used for daily work. A single account used for both email and administration is a fail, and it is extremely common in businesses under twenty people.
Personal devices in scope. If staff use their own phones for work email, those devices are in scope and must meet the controls. Deciding what to do about that is a business decision, and it needs making before the questionnaire rather than during.
Patching within 14 days for third-party software. Windows updates are usually fine. The browser plugin, the PDF reader and the design package are the ones that get missed.
How long it takes
For a business already in reasonable shape, four to six weeks from starting the gap analysis to holding a certificate. Two weeks of that is typically remediation and the rest is scheduling and the assessment itself.
For a business starting from a poor position, three months is more realistic, mostly because replacing unsupported equipment and restructuring accounts cannot be rushed without breaking things.
The renewal each year is far quicker, provided the controls have been maintained rather than reassembled annually, which is the whole argument for treating this as part of ongoing support rather than as a yearly consultancy exercise.
Scoping: the decision that determines everything else
Before answering a single question, decide what is in scope. Cyber Essentials is assessed against a defined boundary, and the boundary you choose determines both the difficulty and the value of the certificate.
Whole-organisation scope is the default and the one buyers expect. It includes every device that accesses organisational data or services: office machines, laptops, servers, cloud services, and staff phones used for work email. It is harder to pass and it is the only scope that answers a supplier questionnaire cleanly.
A sub-scope: one department, one site, one system, is permitted and is occasionally the right answer for a large or complex organisation. For a business of five to fifty people it usually is not, because it produces a certificate with a caveat, and the caveat is the first thing a procurement team reads.
The practical work is listing everything honestly. Businesses routinely forget the machine in the workshop, the tablet on the counter, the laptop a director keeps at home, and the phone belonging to a member of staff who reads work email on it. Each of those is in scope, and each has to meet the controls.
Keeping it after you have it
Cyber Essentials is renewed annually, and the annual renewal is where the value either compounds or evaporates. A business that maintains the five controls through the year renews in a fortnight. A business that lets things drift and reassembles the answers each summer pays for the same remediation repeatedly.
The four things that drift most: patching discipline on third-party software, accounts belonging to leavers, devices that quietly fall out of support as vendors end updates, and multi-factor coverage as new services get added without anyone applying the standard.
All four are ordinary support tasks rather than security projects, which is the argument for treating certification as a by-product of decent day-to-day IT rather than as an annual event. If your provider is doing the job properly, the renewal questionnaire should mostly already be true.
One more reason to keep it current: insurers and larger clients increasingly ask for the certificate date as well as its existence. An expired certificate answers the question badly.
What Cyber Essentials does not cover
It is worth being clear about the ceiling, because certification occasionally produces a false sense of completeness. Cyber Essentials assesses five technical controls at a point in time. It does not assess how your staff behave, how you would respond to an incident, whether your backups restore, or whether the supplier holding your data is any good.
Those omissions matter because they cover most of what actually goes wrong in a small business. Invoice redirection fraud is a process failure rather than a technical one, and it will pass straight through a certified environment. So will a member of staff entering credentials into a convincing fake login page, unless multi-factor authentication catches it, which is precisely why the multi-factor control is the one worth doing properly rather than minimally.
The two things worth adding alongside certification are both cheap. First, backups with restores tested on a schedule, because that is what turns a ransomware incident from an existential event into a bad week. Second, a written incident process that says who is called, in what order, and who is authorised to take systems offline. Neither is assessed by Cyber Essentials and both are worth more than the certificate on the day something happens.
None of this argues against certification. It argues against treating it as the finish line, which is how it is occasionally sold.
Frequently asked questions
If the answer is not here, ask us. You will get a straight one, from someone who does the work.
Mon–Fri, 9am–5:30pm
What is Cyber Essentials?
A UK government-backed certification scheme, delivered through IASME, assessing five basic technical controls: firewalls, secure configuration, user access control, malware protection and security update management. It is a deliberate floor rather than a comprehensive standard, aimed at the attacks that make up most of what happens to small businesses.
How much does Cyber Essentials cost?
The certification fee is banded by organisation size and starts at a few hundred pounds for a micro business. Cyber Essentials Plus, which adds hands-on technical testing, typically costs between one and a half and three thousand pounds. The larger cost is usually the remediation work needed to pass.
Do I need Cyber Essentials?
Yes if you bid for central government contracts involving sensitive information, and increasingly if you supply larger private organisations or your professional indemnity insurer asks. If nobody is asking, doing the five controls properly is worth more than the certificate itself.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
The same five controls. Cyber Essentials is a self-assessment questionnaire verified by an assessor; Cyber Essentials Plus adds hands-on technical verification where an assessor tests your machines rather than taking your word for it.
How long does Cyber Essentials take?
Four to six weeks for a business already in reasonable shape, of which about two weeks is remediation. Three months is more realistic if you are starting from a poor position, mainly because replacing unsupported equipment cannot be rushed.
Why do small businesses fail Cyber Essentials?
Most often: unsupported software or an out-of-date phone left in scope, multi-factor authentication applied to most but not all accounts, administrator accounts used for daily email, personal devices in scope that do not meet the controls, and third-party software not patched within 14 days.
Are staff personal phones in scope?
If they are used for work email or to access work data, yes. That is a business decision worth making deliberately before you start the questionnaire rather than discovering it partway through.
What scope should we choose for Cyber Essentials?
Whole-organisation, in almost every case for a small business. A sub-scope covering one department or system is permitted, but it produces a certificate with a caveat attached, and the caveat is the first thing a procurement team reads.
Is Cyber Essentials enough on its own?
No, and it does not claim to be. It assesses five technical controls at a point in time. It does not assess staff behaviour, your incident response, or whether your backups restore, which between them cover most of what actually goes wrong in a small business. Add tested backups and a written incident process alongside it.