- Cyber Essentials
- 11th Jun 2026
- 1 min read
What Is Cyber Essentials? A Guide for UK Businesses
- Written by
In Short..
- Cyber Essentials is the UK's baseline cyber security certification. Backed by the NCSC, it defines the minimum security controls recommended for UK organisations.
- There are two certification levels. Cyber Essentials is a self-assessment reviewed by an Assured Service Provider, while Cyber Essentials Plus adds independent technical testing.
- Certification is required for many government contracts. Organisations handling certain public-sector data or services often need a valid certificate to bid for or maintain contracts.
- The scheme is built around five core controls. Firewalls, secure configuration, access control, malware protection, and patch management apply at both certification levels.
Cyber Essentials provides a practical, widely recognised benchmark for cyber security. For many organisations it is the first step in a broader security programme, while for government suppliers and regulated businesses it is often a contractual requirement. Certification lasts 12 months and must be renewed annually to remain valid.
Expert View
Matt Davies Chief Product Officer, SureCloud |
What our experts say about CE vs CE+ in practice
"Cyber Essentials asks you to say your patches are current. CE+ checks whether they actually are. In eight years of auditing, that gap between the answer on the form and the state of the device is where almost every finding lives, and it's almost never malicious, just invisible." |
Key Facts
- Cyber Essentials was launched in June 2014 by the UK government, developed by the NCSC, and is administered by the IASME Consortium through a network of licensed Assured Service Providers.
- Two levels: standard Cyber Essentials (self-assessment questionnaire) and Cyber Essentials Plus (independent technical verification by an auditor testing your controls directly).
- Mandatory for government contracts: since April 2014, the Cabinet Office requires Cyber Essentials for contracts involving personal data handling or certain technical products and services.
- Five controls: boundary firewalls, secure configuration, user access control, malware protection, and patch management. All five apply to in-scope devices at both certification levels.
- Certificate valid for 12 months: renewal is required annually. A lapsed certificate does not satisfy live government contract requirements.
Why the Government Created Cyber Essentials
Cyber Essentials was launched by the UK government in June 2014 in response to a consistent pattern in cyber incident investigations. GCHQ had been examining attacks against large organisations and found that the techniques used were far from sophisticated. The analysis showed that one or more of just five key controls would have stopped the attacks progressing.
The government designed Cyber Essentials as a baseline: controls that protect against the most common attack techniques and are achievable by organisations of any size, including those with limited IT resource.
The scheme is administered by the IASME Consortium on behalf of the NCSC. IASME licenses Assured Service Providers (ASPs), the organisations that assess and certify companies against the standard. Since April 2014, the Cabinet Office has required Cyber Essentials certification for contracts involving the handling of personal information or the provision of certain technical products and services to government.
The evidence for the scheme's effectiveness is measurable. Organisations with Cyber Essentials controls in place are 92% less likely to make a claim on cyber insurance than those without, per NCSC published data.
he Two Levels of Cyber Essentials
Standard Cyber Essentials
Standard Cyber Essentials certification is based on a self-assessment questionnaire, the Montpellier question set published by IASME. An organisation answers questions about how each of the five controls is implemented across its in-scope IT estate, and the completed questionnaire is reviewed by a licensed Assured Service Provider who issues a certificate if the requirements are met.
The certificate is valid for 12 months and must be renewed annually. Standard Cyber Essentials is sufficient for most government contract requirements and is the starting point for organisations pursuing CE+.
Cyber Essentials Plus
Cyber Essentials Plus covers the same five controls but requires independent technical verification by an IASME-accredited certification body. An auditor tests your controls directly, running authenticated vulnerability scans, reviewing device configurations, and testing email and web browsing controls using the CE+ test specification published by NCSC.
CE+ provides a higher level of assurance because it does not rely on self-reported answers. It is required for some MoD supply chain contracts and for organisations handling more sensitive government data. Organisations have three months from their standard CE certificate date to complete CE+ verification.
The Five Cyber Essentials Controls
The five controls are consistent across both certification levels.
|
Control |
What It Requires |
|
Boundary firewalls and internet gateways |
A properly configured firewall or equivalent network device controlling what traffic can enter and leave your organisation. Default-deny inbound rules; unnecessary open ports closed. |
|
Secure configuration |
Devices and software configured securely: default passwords changed, unnecessary software removed, auto-run disabled, accounts set up with the minimum access required. |
|
User access control |
User accounts have only the access they need. Administrator accounts are used only for administrative tasks. Multi-factor authentication applied to internet-accessible accounts. |
|
Malware protection |
Protection against malicious software through anti-malware tools and, at gateway level, filtering of malicious email attachments and web content. |
|
Patch management |
Software and operating systems kept up to date. High-risk and critical patches applied within 14 days of release. End-of-life software removed from in-scope devices. |
Who Needs Cyber Essentials
Mandatory: Government Contracts
Since April 2014, UK government departments have required Cyber Essentials certification from suppliers bidding for contracts that involve handling personal information or providing certain technical products and services. This requirement is enforced through the Cabinet Office procurement framework and applies to contracts let by central government departments.
Mandatory: MoD Supply Chain
Ministry of Defence suppliers are subject to the Defence Cyber Protection Partnership (DCPP) requirements, which include Cyber Essentials as a baseline. Suppliers handling more sensitive MoD information or working on contracts with a higher cyber risk profile may be required to hold Cyber Essentials Plus. Specific requirements are set out in DEFSTAN 05-138 and in individual contract terms.
Strongly Recommended: All Other Organisations
Beyond mandatory requirements, Cyber Essentials is the standard approach for any UK organisation that wants to demonstrate a credible baseline of cyber security to customers, partners, and insurers. Many large private sector organisations require Cyber Essentials from their supply chains as part of third-party risk management.
Cyber insurers increasingly reference CE as part of underwriting. Some offer premium reductions for certified organisations or require it as a condition of certain policy types. NCSC data shows 80% of certified organisations believe the scheme reduces their exposure to the financial cost of an unsophisticated cyber attack.
How Long Does Certification Take
Standard Cyber Essentials certification takes two to four weeks from starting the questionnaire process to receiving the certificate, assuming no significant remediation is required. The timeline depends on the size and complexity of your in-scope IT estate, whether your current configuration already meets the control requirements, and the turnaround time of your chosen Assured Service Provider.
Organisations that need to remediate gaps first, for example applying overdue patches, reconfiguring firewalls, or removing end-of-life software, should allow additional time. Submitting before remediation is complete results in a failed assessment, which adds time through the correction and resubmission process.
Cyber Essentials Plus adds further time: the technical audit itself, plus any remediation and retest if the first audit reveals failures. Allow at least four to six weeks for the full CE+ process from starting standard CE.
What You Get When You Certify
On successful certification, your organisation receives a Cyber Essentials certificate valid for 12 months from the date of issue. You're permitted to use the Cyber Essentials certification mark on your website, marketing materials, and tender documentation. Your organisation is listed on the IASME register of certified organisations, which customers and procurement teams can search to verify your certification status.
For qualifying organisations with turnover under £20 million, certification covering the whole organisation also includes a £25,000 cyber liability insurance benefit at no additional cost, arranged through IASME. Coverage includes data breach, ransomware, business interruption, and regulatory investigation costs.
Cyber Essentials vs ISO 27001
Cyber Essentials and ISO 27001:2022 are frequently discussed together but address different things. Cyber Essentials covers five specific technical controls. ISO 27001 requires an organisation to build and maintain a full information security management system, covering governance, risk management, policies, and a much broader set of controls, verified by an accredited third-party auditor.
|
Cyber Essentials |
ISO 27001:2022 |
|
|
Scope |
Five specific technical controls |
Full information security management system |
|
Approach |
Self-assessment or technical audit |
Third-party audit and certification |
|
Time to achieve |
Weeks |
Months to years |
|
Cost |
Low (hundreds of pounds) |
Higher (thousands to tens of thousands) |
|
UK government contracts |
Required for many contracts |
Not directly required, but recognised |
|
Suitable for |
All organisations as a baseline |
Organisations needing a full ISMS with governance and audit |
Cyber Essentials is the starting point for most UK organisations. ISO 27001 is the right standard for organisations that need to demonstrate full information security governance, handle sensitive data at scale, or operate in sectors where ISO 27001 is explicitly required.
Get Certified with SureCloud
FAQ’s
Is Cyber Essentials the same as ISO 27001?
No. Cyber Essentials is a technical baseline: five controls, verified by questionnaire or audit, renewable annually. ISO 27001 is a management system standard covering governance, risk treatment, policy, and continuous improvement across your whole organisation, verified by an accredited third-party auditor. They serve different purposes and can be held at the same time.
How much does Cyber Essentials cost?
The cost varies by Assured Service Provider. Standard Cyber Essentials certification starts at a few hundred pounds for smaller organisations. Cyber Essentials Plus, which involves a technical audit, costs more and varies based on the size of your IT estate and the scope of audit work required. See our Cyber Essentials cost guide for a full breakdown.
Does Cyber Essentials protect against all cyber attacks?
No, and it's important to understand what it does and doesn't cover. Cyber Essentials addresses the techniques that exploit basic security weaknesses: unpatched systems, default credentials, misconfigured network boundaries, and absence of malware filtering. It doesn't cover advanced persistent threats, social engineering, physical security, or insider threats. It's a baseline, not a complete security strategy.
Who certifies Cyber Essentials?
Certification is issued by licensed Assured Service Providers (ASPs) for standard Cyber Essentials, and by IASME-accredited certification bodies for CE+ technical audits. Neither NCSC nor the Cabinet Office issues certificates directly. IASME, which administers the scheme, maintains a public register of both ASPs and certification bodies.
How long is a Cyber Essentials certificate valid for?
12 months from the date of issue. Annual renewal is required to maintain active certification. A lapsed certificate doesn't satisfy government contract requirements, which specify a current valid certificate. Renewal is a fresh application and can be completed with any licensed Assured Service Provider, not necessarily the same one used previously.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.