What Cyber Essentials is — and why it matters commercially
Cyber Essentials is a certification scheme operated by IASME on behalf of the UK National Cyber Security Centre (NCSC). It defines a minimum standard of technical controls that, applied properly, block the most common commodity attacks — phishing-delivered malware, credential stuffing, exploitation of unpatched software and misconfigured services.
The commercial pull is often stronger than the security one. Central government contracts involving certain kinds of personal or sensitive data require it, many larger enterprises now ask for it in supplier onboarding, and a growing number of cyber insurers either ask about it at proposal stage or price against it. For an SME, the certificate is frequently the cheapest single answer to the question “can you show us you take security seriously?”
The five controls
The scheme assesses five technical control themes. None of them require enterprise tooling — they are configuration and process discipline.
1. Firewalls and internet gateways
Every device and network boundary must be protected by a correctly configured firewall. In practice for an SME: the router firewall is on, default passwords are changed, and no administrative interfaces are exposed to the internet without good reason and strong authentication. Software firewalls must be enabled on laptops that leave the office network.
2. Secure configuration
Systems should run with only the services, software and accounts they need. Default and guessable passwords must be removed, autorun disabled, and device-unlock protection (PIN, password or biometrics) enforced. This control is about shrinking the attack surface you never meant to have.
3. Security update management
Supported software only, with high-severity and critical updates applied within 14 days of release. Unsupported operating systems and applications — the single most common audit failure — must be removed or isolated. If you still have a machine that “has to” run an end-of-life OS, expect to justify and segregate it.
4. User access control
Accounts are issued per person, access follows need, administrative privileges are separated from day-to-day accounts, and multi-factor authentication is required for cloud services. Leavers’ accounts must be disabled promptly — assessors increasingly probe joiner/leaver process, not just settings.
5. Malware protection
Every in-scope device needs an anti-malware mechanism: signature-based protection, application allow-listing, or sandboxing. Built-in options (Microsoft Defender, macOS Gatekeeper/XProtect) generally satisfy the requirement when correctly enabled — you do not need to buy a separate product to pass.
Cyber Essentials vs Cyber Essentials Plus
The two levels assess the same five controls; the difference is verification depth.
| Aspect | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Method | Self-assessment questionnaire, signed off by a board member and verified by an assessor | Everything in Basic, plus a hands-on technical audit of a sample of your systems |
| Testing | None | Vulnerability scans, malware-delivery tests, screen-lock and privilege checks on real devices |
| Credibility | Good baseline signal | Materially stronger for enterprise procurement and insurers |
If a specific contract demands Plus, the decision is made for you. Otherwise a common path is Basic first (it is a prerequisite — Plus must be achieved within three months of the Basic certificate), then Plus when a commercial driver appears.
Cost and timeline
As of 2026, certification bodies typically charge a few hundred pounds for Basic — IASME’s pricing is tiered by organisation size, with micro businesses at the bottom of the range. Plus is more variable because auditor time scales with your device sample, but small organisations should generally budget in the low four figures. Treat any quote much beyond that, for a simple estate, with suspicion.
- Preparation: for a cloud-first SME with managed laptops, typically one to four weeks of part-time effort. Estates with legacy servers or unmanaged personal devices take longer.
- Basic assessment: the questionnaire itself takes hours, not days; turnaround from submission to certificate is commonly a few working days.
- Plus audit: usually booked within weeks; the audit itself is typically a day or two depending on estate size.
- Renewal: annual. Budget for the recertification fee and a shorter preparation cycle each year.
What assessors actually check
The questionnaire asks you to declare your scope: every device that accesses organisational data or services, including home workers’ machines and mobile devices. The most consequential decisions happen here — an honest, complete scope makes the rest straightforward; a quietly narrowed one invalidates the certificate and, potentially, any insurance answer that relied on it.
- Operating system versions and support status across the declared estate.
- MFA enforcement on cloud services — for admins and, increasingly, all users.
- Patch cadence evidence: can you show the 14-day window is actually met?
- Separation of admin accounts from everyday accounts.
- For Plus: real tests against a device sample — attempted malware downloads, email attachment execution, browser and client vulnerability scans.
Where SMEs fail — and how to avoid it
- Unsupported software discovered late: one forgotten Windows machine in a warehouse, an old NAS, a legacy line-of-business app. Inventory first, before you book anything.
- Scope surprises: directors’ personal laptops used for email are in scope. Decide the estate deliberately — mobile device management or a clear BYOD policy — rather than discovering it in the questionnaire.
- MFA gaps on “minor” cloud tools that still hold organisational data.
- Paper answers that don’t match reality. Plus audits, and insurers’ claims investigations, test what is actually configured. Fix the estate, not the wording.
Beyond the certificate: continuous evidence
Cyber Essentials is a point-in-time declaration, renewed annually. The controls it checks are exactly the ones that drift: a patch window slips, a leaver’s account lingers, MFA gets disabled “temporarily”. The certificate does not notice; your customers and insurer will only notice at the worst possible moment.
That gap — between an annual snapshot and the continuous state of your estate — is the problem TrustQuant’s resilience rating is built to close. The same control themes Cyber Essentials assesses annually are measured continuously from read-only telemetry, so you can see drift when it happens and show current evidence rather than a dated PDF. See how the rating works or read a sample report.