Explainer
What is Cyber Essentials, and does your business actually need it?
It is the UK government-backed security baseline: five controls, self-assessed, from £320 plus VAT. You need it if a client or insurer asks for it - and it is a sensible checklist even if nobody has.
By Claire Donnelly · Last reviewed 11 August 2026 · 4 min read
The short version
- Five technical controls, self-assessed and independently reviewed, from £320 plus VAT
- Certification usually includes cyber insurance for UK firms turning over under £20m
- Only about 5% of UK businesses hold it, so not having it is still the norm
- The real trigger is a tender or an insurer asking, rather than the risk itself
- Cyber Essentials Plus is the same five controls, checked by an assessor not by you
What it actually is
Cyber Essentials is the minimum standard of cyber security recommended by the UK government, developed by the National Cyber Security Centre. It covers five technical controls aimed at the common, untargeted attacks that make up most of what a small business will ever face.
You complete a self-assessment questionnaire about how your systems are set up, and it is reviewed independently before certification is granted. It is not an audit of your business, an inspection of your premises, or a judgement of your policies. It asks whether five specific things are done properly.
That narrowness is the point. It is deliberately a floor rather than a ceiling, and it is achievable for a business with no security specialist of its own.
The five controls, in plain terms
- Firewalls - a filter between the internet and your network, configured rather than just present
- Secure configuration - devices set up properly, with default passwords and unused features removed
- Security update management - software patched, and unsupported software removed
- User access control - people have only the access they need, and admin accounts are controlled
- Malware protection - something in place to identify and stop malicious software
What it costs and what comes with it
Certification starts at £320 plus VAT and is priced in bands by organisation size, so a business of six pays considerably less than one of two hundred. Cyber Essentials Plus is quoted separately, according to the size and complexity of your network, because it involves an assessor doing real testing.
The part people miss is the insurance. UK organisations with a turnover under £20 million that certify their whole organisation are automatically entitled to cyber liability insurance arranged through the scheme, with incident response support included. For a small business that alone can justify the certification fee – though you should read what the cover actually provides rather than assuming it replaces a proper policy.
The certification fee is rarely the whole cost. If the assessment finds unsupported software, unpatched machines or admin rights handed out freely, fixing those is the real expense – and it is the part that genuinely improves your security.
So does your business actually need it?
The honest answer is that most UK businesses do not have it. Government figures put certification at around 5% of businesses overall – about 12% of small businesses and 35% of large ones. Not having it is still normal, and any provider implying you are unusually exposed without it is overstating things.
There are three situations where it stops being optional.
Somebody is asking for it. Public sector tenders, NHS work, defence supply chains and a growing number of private clients require it before you can bid. This is far and away the most common reason businesses certify, and it turns a nice-to-have into a revenue question.
Your insurer is asking. Cyber cover questions increasingly overlap with the five controls, and certification makes those forms much easier to answer honestly.
You want an outside check. If nobody in the business can say with confidence that patching is current and admin rights are controlled, the assessment will tell you. Plenty of businesses certify mainly to find out.
If none of those apply, it is reasonable to treat the five controls as a checklist to work through and certify later, when somebody asks. What is not reasonable is assuming you already meet them.
Signs you should certify this year
- A tender or contract you want has asked for it, or is likely to
- Your cyber insurance is due for renewal and the questions are getting harder
- You handle client data that would embarrass you if it leaked
- Nobody can confirm every machine is patched and supported
- Administrator rights have been handed out and never reviewed
- You have grown past the point where one person knows every device
Common questions
How long does certification take?
The assessment itself is a questionnaire that a prepared business can complete in a day or two. The variable is remediation: if there is unsupported software or unmanaged devices, expect weeks rather than days, because the fixing takes the time rather than the paperwork.
How long does it last?
Certification runs for a year, then you recertify. That annual rhythm is arguably the most useful part, because it forces someone to check the five controls are still true rather than assuming they are.
Will it stop us being attacked?
It closes the common, opportunistic routes in, which is most of what a small business encounters. It is not designed to stop a determined, targeted attacker, and no certification would. Treat it as the floor it was designed to be.
We use Microsoft 365 and everyone works from home. Does it still apply?
Yes, and the controls adapt to that - home working, personal devices and cloud services are all in scope under the current requirements. If anything it is more useful in that setup, because there is no office network doing quiet work on your behalf.
Can we do it ourselves?
Yes. The self-assessment is designed to be completed by a business rather than a consultant, and a capable in-house person can do it. Most small businesses use their IT provider because the questions assume you can see how everything is configured.
Written by Claire Donnelly
Been asked for Cyber Essentials by a client?
Send us the requirement and we'll tell you what you would need to change, roughly what it would cost, and whether the deadline is realistic. If you would pass today, we'll say that too.
Ask us where you stand