What Is the Cyber Essentials Certificate? Everything UK Organisations Need to Know

No Data, No Party.

Whether you’re responding to a tender, preparing for certification, or strengthening your organisation’s cyber security, the Cyber Essentials certificate gives you a practical place to start. Backed by the UK government, the scheme helps organisations build stronger, secure digital foundations that support confident growth and demonstrate they’re taking cyber security seriously.

Launched in 2014 and overseen by the National Cyber Security Centre (NCSC), it gives organisations a clear, structured way to show that their digital foundations are sound.

If a client has asked about it, you’ve spotted it in a contract requirement, or you simply want to understand what your security posture actually looks like, this guide covers the scheme from top to bottom.

What Is Cyber Essentials and Who Runs It?

The NCSC owns and governs the Cyber Essentials scheme. Day-to-day delivery sits with the IASME Consortium, which acts as the sole accreditation body and manages a network of accredited certification bodies that carry out assessments directly with organisations.

The scheme is updated every year to reflect how organisations work today, with recent updates strengthening requirements around cloud services, multi-factor authentication and patch management.If your organisation uses cloud-hosted services or remote working tools, those environments now fall squarely within scope.

Whether you have ten employees or ten thousand, if your organisation uses internet-connected systems, Cyber Essentials gives you a practical framework for protecting them. You don’t need to be a large enterprise or a technology company. If your organisation uses internet-connected systems, it applies to you. In fact, many organisations work alongside their IT partner or managed service provider to prepare for certification.

What Are the Five Technical Controls Organisations Should Know?

The scheme is built around five specific technical controls. Each one addresses a common attack vector, and together they can prevent over 80% of common cyber attacks, including phishing, malware, and opportunistic intrusion.

  1. Firewalls: Boundary protection that prevents unauthorised access to your network and devices. This includes both network firewalls and software firewalls on individual devices.
  2. Secure configuration: Removing default settings, unnecessary software, and unused features that create vulnerabilities. Out-of-the-box settings are often designed for convenience, not security.
  3. User access control: Limiting user privileges to what each person genuinely needs to do their job. Standard user accounts should not have administrative rights by default.
  4. Malware protection: Defending against malicious software through anti-malware tools or application allow-listing, which restricts devices to running only approved software.
  5. Security update management: Keeping software, operating systems, and devices patched and up to date. Unpatched systems are one of the most common entry points for attackers.

Each control maps to a practical configuration decision your IT team or managed service provider can act on. These are practical controls that help reduce everyday cyber risk.

Cyber Essentials vs Cyber Essentials Plus: What's the Difference?

Cyber Essentials has two certification levels. Which one fits your organisation depends on your risk profile and what your contracts actually require.

Cyber Essentials vs Cyber Essentials Plus: Key Differences

Feature Cyber Essentials Cyber Essentials Plus
Assessment method Verified self-assessment questionnaire Independent hands-on technical audit
Technical audit required From £320 +VAT Yes
Cost range Data confidentiality  Higher, varies by organisation size
Certificate validity 12 months 12 months
Assurance level Self-declared, reviewed by certification body Independently verified
Ideal for
Most organisations, supply chain eligibility Sensitive contracts, higher-assurance environments

 

The base level, Cyber Essentials, works through a structured self-assessment questionnaire. You answer questions about your controls, a certification body reviews your responses, and if you meet the standard, you’re certified. Cyber Essentials Plus goes further: an accredited assessor tests your systems directly, checking that your controls actually work as described.

Both levels require annual renewal. If you’re unsure which tier applies to your contracts or risk profile, the specific requirements are usually spelled out in the tender or supplier onboarding documentation.

Who Needs Cyber Essentials and Is It Mandatory?

Cyber Essentials is required for all UK central government contracts that involve handling sensitive or personal data. If you’re bidding for that type of work, certification isn’t optional.

Beyond central government, the requirement is spreading through supply chains. Defence primes, critical national infrastructure operators, and many larger commercial organisations now ask their suppliers to hold Cyber Essentials as a baseline condition. So even if you’re not selling directly to government, your customers may already require it, and that requirement is only becoming more common.

For any organisation using internet-connected systems, the five controls Cyber Essentials covers are things you’d want in place regardless of what a contract says. Certification gives you a recognised way to demonstrate that—helping customers, partners and suppliers see that cyber security is something your organisation takes seriously.

How Much Does Cyber Essentials Cost?

For many organisations, Cyber Essentials is one of the most cost-effective ways to improve cyber security while demonstrating compliance. Certification starts at £320 +VAT for the smallest organisations, with pricing scaled by organisation size. Cyber Essentials Plus carries a higher cost because it involves an independent technical audit, and the final price depends on the scope of your systems and the certification body you work with.

Some insurers offer improved terms to organisations that hold Cyber Essentials certification. Over time, that can offset part of the certification cost.

What Cyber Essentials Doesn't Cover

Cyber Essentials can prevent over 80% of common cyber attacks. For most organisations, that’s a significant proportion of the threat they actually face day to day, and it’s why the scheme has real value as a starting point.

The scheme focuses on commodity threats: opportunistic attackers looking for easy targets. It doesn’t address sophisticated, targeted attacks, physical security, insider risk, or the governance and risk management processes that a full information security management system (ISMS) requires.

Organisations in regulated sectors, or those working in defence supply chains with broader compliance obligations, should look at ISO 27001 for that wider coverage.

For organisations managing IT and operational technology (OT) integration or cross-domain data transfer, Cyber Essentials is the verified foundation that more specialist controls build on. Getting it in place first means the harder conversations about architecture and accreditation start from a position of strength.

Cyber Essentials and Your Broader Security Posture

Getting certified is a practical, achievable step. The self-assessment process typically takes a few days to complete once your controls are configured correctly, and many organisations find the process itself useful for identifying gaps they weren’t aware of.

At 4Secure, Cyber Essentials is more than a certificate. It’s a practical step towards stronger cyber resilience, greater customer confidence and a more secure organisation. We work with organisations across government, defence, and critical national infrastructure. So, whether you’re preparing for your first assessment or building on an established security programme, we’re here to help make the journey straightforward.

Frequently Asked Questions About Cyber Essentials

How long does Cyber Essentials certification take?

Most organisations can complete the self-assessment within a few days once the required controls are in place. The certification body review usually takes a few working days after submission. Cyber Essentials Plus takes longer because it involves a scheduled technical audit.

Do I need Cyber Essentials to work with the government?

Yes, if the contract involves handling sensitive or personal data. UK central government contracts with that scope require Cyber Essentials as a minimum. Check the specific contract requirements, as some may ask for Cyber Essentials Plus.

What is the difference between Cyber Essentials and ISO 27001?

Cyber Essentials covers five specific technical controls and is designed as a minimum baseline. Whereas ISO 27001 is a full information security management standard covering governance, risk management, policies, and processes across the whole organisation. That said, they address different levels of maturity and work well together.

How much does Cyber Essentials cost for a small business?

Currently, certification starts at £320 +VAT for the smallest organisations. Pricing scales with organisation size, so larger businesses pay more. Cyber Essentials Plus costs more due to the independent technical audit involved.

Does Cyber Essentials certification expire?

Yes. Both Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months and must be renewed annually. The renewal process follows the same assessment approach as the initial certification.

What happens if I fail the Cyber Essentials assessment?

You’ll receive feedback on which controls didn’t meet the standard. Most certification bodies allow you to remediate and resubmit. The process is designed to help organisations improve their controls, not simply issue a verdict.