Skip to main content
01543 524594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeBlog › Cyber Security

Cyber Essentials, demystified: the UK small business guide

What it is, what it actually costs, why your insurer keeps asking about it, and exactly how to pass it the first time round.

Andy Price · Founder1 May 2026 · 7 min read

Cyber Essentials. You’ve heard the phrase a dozen times in the last 18 months, probably from your insurance broker, a panel client, or a public-sector tender. And yet most UK small business owners still aren’t quite sure what it is, what it costs, or whether it’s worth doing.

This guide fixes that. By the time you’ve read it, you’ll know exactly what Cyber Essentials means, why insurers and customers are asking about it, the five controls you’ll be tested on, and the realistic path to passing on your first attempt.

In short: Cyber Essentials is a UK government-backed certification covering five basic controls that block the most common attacks, and most small firms can achieve it in a few weeks. Here is what it involves and how to pass first time.

Key takeaways

  • Cyber Essentials is a UK government-backed certification covering five technical controls every business should have.
  • The basic certification is a self-assessment, not an audit. Cyber Essentials Plus adds an external technical test.
  • Costs start at £320 for businesses under 10 staff, scaling up by headcount.
  • Around 80% of UK insurers now ask about it on cyber-policy renewal.
  • Most failures come from the same three issues: missing MFA, unsupported software, and weak admin separation.
Key takeaways on Cyber Essentials certification for UK small businesses

What is Cyber Essentials?

Cyber Essentials is a certification scheme created by the National Cyber Security Centre (NCSC) and run by IASME. It’s a baseline of five technical security controls that, if implemented properly, protect against around 80% of common internet-based cyber attacks.

The clue is in the name. It’s the essentials. It’s the floor, not the ceiling. Larger or more sensitive organisations layer on additional standards (ISO 27001, SOC 2, NIST CSF), but Cyber Essentials is the agreed UK starting point for businesses of any size.

There are two levels. Cyber Essentials is a self-assessment questionnaire that you complete, sign, and submit. Cyber Essentials Plus is the same controls, but they’re verified by an external technical assessor running tests on your environment. Plus is harder, costs more, and carries more weight with insurers and tenders.

Why is everyone suddenly asking about it?

Three forces have made Cyber Essentials something you actually need to deal with.

1. Cyber insurance underwriting has tightened

UK insurers have been hammered by ransomware payouts. The market is now considerably stricter. Most renewal questionnaires explicitly ask about MFA enforcement, endpoint protection, patching cadence, and admin separation, the same controls Cyber Essentials covers. If you can answer “yes, we’re Cyber Essentials certified,” you’ve answered most of the questionnaire in one line.

2. Public sector and large-corporate procurement now demand it

Government contracts handling personal or sensitive information require Cyber Essentials as a minimum. Many large corporates have followed suit, particularly in financial services, legal and healthcare. If you bid for tier-one client work or any public-sector tender, expect to be asked.

3. SRA, FCA and ICO expectations have hardened

If you’re regulated, your regulator’s cyber expectations now align closely with the Cyber Essentials controls. The Solicitors Regulation Authority’s cyber security guidance, the FCA’s operational resilience expectations, and the ICO’s data protection standards all map back to the same five control families.

The five Cyber Essentials controls, in plain English

1. Firewalls and routers

Every device that connects to the internet, your office router, every laptop, every server, must have a properly configured firewall. Default admin passwords on routers must be changed. Inbound traffic should be blocked by default and only opened where necessary.

2. Secure configuration

Devices should be set up to minimise vulnerabilities. That means removing software you don’t use, disabling guest accounts, requiring strong passwords or PINs, and turning off auto-run for removable media. New laptops out of the box are typically not configured securely. They need hardening.

3. Security update management (patching)

Operating systems and applications must receive security updates within 14 days of release. Software that’s no longer supported by its vendor (think Windows 7, old versions of Office, ancient line-of-business apps) cannot be in scope. Patching has to be enforced, not optional.

4. Team member access control

Each team member has their own account. Administrator accounts are separate from day-to-day accounts. Multi-factor authentication is enabled on cloud services. Old accounts are removed promptly when staff leave. Privileged access is reviewed regularly.

5. Malware protection

Every device has anti-malware (in 2026, that’s typically Microsoft Defender or a dedicated EDR product). Real-time protection is on. Definitions update automatically. Devices scan downloaded content before staff open it.

What does it actually cost?

The certification fee itself is set by IASME and depends on your headcount.

  • Micro (under 10 staff): £320 for Cyber Essentials, £1,800-£2,400 for Plus.
  • Small (10-49 staff): £400 for Cyber Essentials, £2,400-£3,600 for Plus.
  • Medium (50-249 staff): £450 for Cyber Essentials, £3,600-£6,000 for Plus.
  • Large (250+ staff): £600 for Cyber Essentials, scoped quote for Plus.

If your environment isn’t already aligned to the controls, factor in the work to bring it up to standard. For most SMBs that’s MFA rollout, patching automation, endpoint protection upgrades, admin separation and documentation. With us, that work is included as part of your managed service.

The three things most businesses fail on

From years of running clients through certification, the same three issues come up repeatedly.

“We pass everything except the MFA bit. Surely that’s enough?” No. MFA being mandatory means a single failure here is a fail overall.

Missing MFA on cloud services. Most failures come from MFA not being enforced for every team member (especially admins) on Microsoft 365, Google Workspace, your finance system and your CRM. Self-attestation that “staff have been encouraged to enable it” doesn’t pass.

Unsupported software still in scope. Old versions of Windows, ancient line-of-business apps, that one Mac running macOS 10.13. Anything no longer receiving security updates is an automatic fail unless it’s segmented off the network and explicitly out of scope.

Admin and staff accounts not separated. If a director’s daily-use email account also has Microsoft 365 Global Admin, that’s a fail. Admin work needs to happen from a separate, named admin account.

How to pass on the first attempt

  1. Run a gap analysis against the five control families before applying. Don’t submit the questionnaire and hope.
  2. Fix the gaps before booking the certification. Most issues take days, not weeks, to remediate if you have a competent provider.
  3. Document everything. The assessor wants evidence: screenshots of MFA enforcement policies, patching reports, asset inventories, account separation. Half of certification is producing the evidence pack.
  4. Use the IASME readiness toolkit to self-check your answers before submission.
  5. Apply through a Cyber Essentials Certification Body. They review your answers before sending to IASME, catching common mistakes early.

Frequently asked questions

Is Cyber Essentials the same as ISO 27001?

No. ISO 27001 is a much broader information security management standard covering policy, governance, risk management, training, supplier management and a long list of organisational controls. Cyber Essentials is just the technical baseline. Most SMBs do Cyber Essentials first; ISO 27001 is generally a 6-12 month project with significantly higher cost.

How long does certification take?

If your environment is already aligned, the basic Cyber Essentials assessment can be completed in about a week. Cyber Essentials Plus adds a technical assessment on top, which usually takes another 1-2 weeks to schedule and complete.

How long is the certification valid?

One year. You re-certify annually.

Can I do it without an MSP?

Yes, you can self-certify directly through IASME’s portal. Most SMBs find that the gap-fixing work (MFA rollout, patching, hardening) is what they actually need help with, and an MSP handles that as part of normal managed-IT scope.

Does Cyber Essentials cover staff training?

Not directly. The Cyber Essentials controls are technical. Training is best practice but not part of the certification. (Though it’s part of any decent managed IT package, including ours.)

Initial IT runs Cyber Essentials and Cyber Essentials Plus certification for businesses across Lichfield, Staffordshire and the West Midlands. We’ve helped over 50 SMBs pass on first attempt.