Cyber Essentials Certification: A UK Small Business Guide

Cyber Essentials Certification: A UK Small Business Guide

Direct answer: Cyber Essentials is a UK government-backed certification scheme that checks five baseline security controls. A small business completes a verified self-assessment for the standard certificate, or adds an independent technical assessment for Cyber Essentials Plus. Certification helps manage common threats and may be required for relevant government or supply-chain contracts.

Cyber Essentials turns basic security into evidence

Cyber Essentials is designed to show that an organisation has a defined minimum set of technical protections. The scheme is backed by the UK government, associated with the National Cyber Security Centre (NCSC) and delivered through IASME and licensed certification bodies. It is suitable for organisations of any size and sector. For a small business, its practical value is structure: the assessment makes the company identify internet-connected devices, remove unsafe defaults, control user privileges, protect against malware and keep supported software updated. A certificate does not prove that a business cannot be breached. It shows that the organisation has addressed the scheme’s baseline at the time of assessment. Security work must continue after certification.

The five technical controls in plain English

1. Firewalls

Firewalls control traffic between devices and untrusted networks. The business should know which services are exposed to the internet, remove unnecessary access and protect administrative interfaces. Home routers used by remote workers also matter when they form part of the assessed environment.

2. Secure configuration

New devices and software often arrive with features, accounts or settings that are not needed. Secure configuration means removing or disabling unnecessary functions, changing default credentials and applying settings that reduce avoidable exposure.

3. User access control

People should receive only the access needed for their work. Administrator rights should be limited, reviewed and separated from ordinary daily use. Leavers’ accounts need prompt removal, while joiners and role changes need documented access decisions.

4. Malware protection

The organisation must use suitable measures to prevent malicious software from running. Depending on the device and platform, that can involve approved applications, anti-malware tools, app-store restrictions and controls that limit untrusted code.

5. Security updates

Supported operating systems, applications, browsers, plugins, routers and firmware need security updates within the scheme’s required timescales. Unsupported software is a common readiness problem because the supplier no longer fixes newly discovered weaknesses.

Cyber Essentials or Cyber Essentials Plus?

AreaCyber EssentialsCyber Essentials Plus
MethodVerified self-assessmentIndependent technical audit
ControlsSame five controlsSame five controls
EvidenceQuestionnaire responsesHands-on verification
EffortLowerHigher
Best fitBaseline assuranceStronger client assurance

Plus is not a different security framework. It verifies the same control set more directly. Choose it when a customer or tender requires it, when stronger assurance has commercial value, or when independent testing can prove confidence in the implementation.

The 2026 assessment fee tiers are £320 for a micro organisation, £440 for a small organisation, £500 for a medium organisation and £600 for a large organisation, plus VAT. These figures cover the assessment fee only. Consultancy, remediation, software, hardware and Cyber Essentials Plus testing can add further cost.

Fees and organisation-size definitions can change, so verify the current amount with IASME or a licensed certification body before ordering. A small business that is already well managed may need little outside help. A business with unsupported devices, unmanaged home-working equipment or unclear scope may need technical work first.

Organisation tierReported feeExcludes
Micro£320 + VATRemediation/support
Small£440 + VATRemediation/support
Medium£500 + VATRemediation/support
Large£600 + VATRemediation/support

How long certification takes

A ready-to-go small business may complete the self-assessment route in one to five working days. A more typical project can take one to four weeks when staff must identify devices, update software, remove unsafe configurations and gather accurate answers. Cyber Essentials Plus may take roughly two to eight weeks because technical testing must be scheduled and any issues resolved. These are planning ranges, not guaranteed service times. The biggest variable is readiness. Buying the assessment before understanding the scope can create unnecessary pressure.

Remote workers are part of the scope decision

Remote work does not sit outside the organisation merely because devices are used at home. Company laptops, personally owned devices allowed to access organisational data, cloud services, routers and remote-access arrangements can affect the assessment. List how staff connect, which devices they use, who manages updates and whether unsupported equipment can reach business information. Avoid writing a narrow scope that looks convenient but fails to represent the services the organisation actually provides.

A step-by-step route to certification

Step 1: choose the required level

Start with the contract, customer requirement or business objective. Standard Cyber Essentials may satisfy baseline assurance. Plus may be necessary for a tender or a customer that needs tested controls.

Step 2: define the scope

Document the legal entity, networks, cloud services, devices, remote workers and internet-facing services included. If part of the environment is excluded, it needs a defensible technical separation, not just a sentence in the application.

Step 3: prepare the five controls

Inventory hardware and software. Remove unsupported products. Change defaults. Review firewall rules. Reduce administrator access. Confirm malware protection. Apply required security updates and document how these tasks continue.

Step 4: complete the self-assessment accurately

Answer for the environment as it exists, not as staff hope it works. Use the official question set and readiness resources. Where an answer is unclear, gather evidence or ask a licensed assessor before submitting.

Step 5: remediate and resubmit if needed

A failed answer is a useful finding. Correct the control, update the evidence and use the certification body’s process for reassessment. Do not hide unsupported systems or unmanaged devices.

Step 6: maintain the baseline

A Cyber Essentials certificate is valid for 12 months. Keep the asset list, patching, accounts and configuration under review throughout the year so renewal is a check of normal practice rather than an emergency project.

Who benefits most?

  • Government suppliers: an up-to-date certificate is required for certain contracts involving sensitive information or relevant technical services.
  • Supply-chain businesses: customers increasingly use certification as evidence during supplier due diligence.
  • Small teams without a framework: the five controls create a clear baseline and ownership checklist.
  • Businesses seeking trust signals: certification can support sales conversations when described accurately.

Do not market Cyber Essentials as proof that all systems are secure or that UK GDPR compliance is complete. It addresses a defined security baseline. Wider risk management, staff awareness, backups, incident response and data-protection obligations remain.

Common reasons small businesses struggle

  • Incomplete inventory: old laptops, routers, phones or cloud systems are forgotten.
  • Unsupported software: a product still works, but no longer receives security fixes.
  • Excess administrator access: everyday accounts retain powerful permissions.
  • Unclear remote-working controls: nobody owns updates or configuration on home-working devices.
  • Vague scope: the assessment does not match the real service or network.
  • Last-minute preparation: remediation begins after the assessment has been purchased.

A readiness checklist

  1. List all in-scope devices, operating systems, routers and cloud services.
  2. Confirm that every item is supported and receiving security updates.
  3. Change default passwords and remove unused accounts and services.
  4. Review firewall exposure and protect administration interfaces.
  5. Limit administrator rights and enable strong authentication.
  6. Confirm the chosen malware-protection approach for every device type.
  7. Document remote workers, personally owned devices and cloud access.
  8. Read the current assessment questions before purchasing.
  9. Assign an owner for evidence, remediation and annual renewal.

Frequently asked questions

How much does Cyber Essentials cost?

The 2026 assessment tiers range from £320 to £600 plus VAT, depending on organisation size.

How long does certification take?

A prepared small business may complete the self-assessment in one to five working days. One to four weeks is a more practical range when preparation is required.

What is the difference between Cyber Essentials and Plus?

Both use the same five controls. Standard certification is a verified self-assessment, while Plus adds an independent technical assessment.

Do remote workers affect the scope?

Yes. Devices, cloud access and networks used for business work must be considered when defining what the assessment covers.

How long does certification last?

The certificate lasts 12 months. Organisations must renew annually to maintain current certification.

Does Cyber Essentials make a business fully secure?

No. It reduces exposure to common attacks through a baseline set of controls. Wider security, backup, monitoring, incident response and staff training are still needed.

Conclusion

Cyber Essentials is most valuable when the certificate reflects ordinary working practices. Define the scope honestly, fix the five controls before applying and maintain them throughout the year. The result is more than a badge: it is a repeatable baseline that can support customer trust and contract eligibility.