Skip to content
Resources

Guide

Cyber Essentials for SMEs: a practical walkthrough

Cyber Essentials is the UK government-backed baseline for cyber hygiene — and for many SMEs it is the first certificate a customer, insurer or framework contract will ask for. Here is what it actually involves, control by control.

8 min readLast reviewed July 2026

What Cyber Essentials is — and why it matters commercially

Cyber Essentials is a certification scheme operated by IASME on behalf of the UK National Cyber Security Centre (NCSC). It defines a minimum standard of technical controls that, applied properly, block the most common commodity attacks — phishing-delivered malware, credential stuffing, exploitation of unpatched software and misconfigured services.

The commercial pull is often stronger than the security one. Central government contracts involving certain kinds of personal or sensitive data require it, many larger enterprises now ask for it in supplier onboarding, and a growing number of cyber insurers either ask about it at proposal stage or price against it. For an SME, the certificate is frequently the cheapest single answer to the question “can you show us you take security seriously?”

The five controls

The scheme assesses five technical control themes. None of them require enterprise tooling — they are configuration and process discipline.

1. Firewalls and internet gateways

Every device and network boundary must be protected by a correctly configured firewall. In practice for an SME: the router firewall is on, default passwords are changed, and no administrative interfaces are exposed to the internet without good reason and strong authentication. Software firewalls must be enabled on laptops that leave the office network.

2. Secure configuration

Systems should run with only the services, software and accounts they need. Default and guessable passwords must be removed, autorun disabled, and device-unlock protection (PIN, password or biometrics) enforced. This control is about shrinking the attack surface you never meant to have.

3. Security update management

Supported software only, with high-severity and critical updates applied within 14 days of release. Unsupported operating systems and applications — the single most common audit failure — must be removed or isolated. If you still have a machine that “has to” run an end-of-life OS, expect to justify and segregate it.

4. User access control

Accounts are issued per person, access follows need, administrative privileges are separated from day-to-day accounts, and multi-factor authentication is required for cloud services. Leavers’ accounts must be disabled promptly — assessors increasingly probe joiner/leaver process, not just settings.

5. Malware protection

Every in-scope device needs an anti-malware mechanism: signature-based protection, application allow-listing, or sandboxing. Built-in options (Microsoft Defender, macOS Gatekeeper/XProtect) generally satisfy the requirement when correctly enabled — you do not need to buy a separate product to pass.

Cyber Essentials vs Cyber Essentials Plus

The two levels assess the same five controls; the difference is verification depth.

AspectCyber EssentialsCyber Essentials Plus
MethodSelf-assessment questionnaire, signed off by a board member and verified by an assessorEverything in Basic, plus a hands-on technical audit of a sample of your systems
TestingNoneVulnerability scans, malware-delivery tests, screen-lock and privilege checks on real devices
CredibilityGood baseline signalMaterially stronger for enterprise procurement and insurers

If a specific contract demands Plus, the decision is made for you. Otherwise a common path is Basic first (it is a prerequisite — Plus must be achieved within three months of the Basic certificate), then Plus when a commercial driver appears.

Cost and timeline

As of 2026, certification bodies typically charge a few hundred pounds for Basic — IASME’s pricing is tiered by organisation size, with micro businesses at the bottom of the range. Plus is more variable because auditor time scales with your device sample, but small organisations should generally budget in the low four figures. Treat any quote much beyond that, for a simple estate, with suspicion.

  • Preparation: for a cloud-first SME with managed laptops, typically one to four weeks of part-time effort. Estates with legacy servers or unmanaged personal devices take longer.
  • Basic assessment: the questionnaire itself takes hours, not days; turnaround from submission to certificate is commonly a few working days.
  • Plus audit: usually booked within weeks; the audit itself is typically a day or two depending on estate size.
  • Renewal: annual. Budget for the recertification fee and a shorter preparation cycle each year.

What assessors actually check

The questionnaire asks you to declare your scope: every device that accesses organisational data or services, including home workers’ machines and mobile devices. The most consequential decisions happen here — an honest, complete scope makes the rest straightforward; a quietly narrowed one invalidates the certificate and, potentially, any insurance answer that relied on it.

  • Operating system versions and support status across the declared estate.
  • MFA enforcement on cloud services — for admins and, increasingly, all users.
  • Patch cadence evidence: can you show the 14-day window is actually met?
  • Separation of admin accounts from everyday accounts.
  • For Plus: real tests against a device sample — attempted malware downloads, email attachment execution, browser and client vulnerability scans.

Where SMEs fail — and how to avoid it

  • Unsupported software discovered late: one forgotten Windows machine in a warehouse, an old NAS, a legacy line-of-business app. Inventory first, before you book anything.
  • Scope surprises: directors’ personal laptops used for email are in scope. Decide the estate deliberately — mobile device management or a clear BYOD policy — rather than discovering it in the questionnaire.
  • MFA gaps on “minor” cloud tools that still hold organisational data.
  • Paper answers that don’t match reality. Plus audits, and insurers’ claims investigations, test what is actually configured. Fix the estate, not the wording.

Beyond the certificate: continuous evidence

Cyber Essentials is a point-in-time declaration, renewed annually. The controls it checks are exactly the ones that drift: a patch window slips, a leaver’s account lingers, MFA gets disabled “temporarily”. The certificate does not notice; your customers and insurer will only notice at the worst possible moment.

That gap — between an annual snapshot and the continuous state of your estate — is the problem TrustQuant’s resilience rating is built to close. The same control themes Cyber Essentials assesses annually are measured continuously from read-only telemetry, so you can see drift when it happens and show current evidence rather than a dated PDF. See how the rating works or read a sample report.

Reading is preparation. Measuring is proof — see where you stand in minutes, without installing anything.

Read a sample report

Turn this guide into a score

Run a free preview of your resilience rating, or apply for the Q3 2026 pilot cohort.