Cyber Essentials certification is the UK government’s minimum standard for cyber security, and it is deliberately small. Five technical controls, a self-assessment questionnaire, and an annual cycle. That is the whole scheme.
The size is the point. Most attacks are, in the NCSC’s own words, “the digital equivalent of a thief trying your front door to see if it’s unlocked”. Cyber Essentials is about locking the door — not about building a management system.
What Cyber Essentials certification is
Cyber Essentials was developed by the National Cyber Security Centre and is delivered by IASME, the NCSC’s official Delivery Partner. It comes in two forms:
- Cyber Essentials — a self-assessment questionnaire, verified by a certification body.
- Cyber Essentials Plus — the same five controls, but with a hands-on technical audit of your systems by an assessor.
Plus is not a higher standard. It is the same standard, independently tested. That distinction matters when a customer asks which one you hold and why.
The five Cyber Essentials certification controls

| Control | What it does |
|---|---|
| Firewalls | Create a security filter between the internet and your network |
| Secure configuration | Set up computers securely to minimise ways that a cyber-criminal can find a way in |
| Security update management | Prevent cyber criminals using vulnerabilities they find in software as an access point to your systems |
| User access control | Control who can access your data and services and what level of access they have |
| Malware protection | Identify and immobilise viruses or other malicious software before it has a chance to cause harm |
Those descriptions are the NCSC’s. What they do not tell you is where organisations actually fail, which is almost never the control itself and almost always the scope.
Scope is what makes Cyber Essentials certification hard
The five controls are simple to state. Deciding what they apply to is not, and a scope drawn carelessly is the most common cause of a failed or worthless certificate.
Home and remote workers. If staff work from home, their devices are in scope. Depending on the setup, so is the boundary their traffic crosses. A certificate that quietly excluded half the workforce is a certificate that describes a network nobody uses.
Bring your own device. Personally owned devices used for organisational work are generally in scope. Organisations often discover this after buying the assessment.
Cloud services. Cloud is in scope, and responsibility does not transfer to the provider simply because the infrastructure does. The user access control and secure configuration questions still land on you.
Whole organisation or a subset. You may certify a defined subset, but the certificate says so — and a customer reading it will notice which part of your business is not covered.
Decide scope first, honestly, and write it down. Every question in the assessment is answered against it.
Where Cyber Essentials certification assessments fail
Four failure modes account for most of it, and none of them requires new technology to fix:
- Unsupported software. Anything past end of support fails, because it cannot receive security updates. This is the single most common cause, and it is usually one forgotten server or an old operating system on a handful of machines.
- Updates not applied in time. The scheme expects high-risk and critical updates to be applied within a defined window. “We patch monthly” is often not enough.
- Administrator accounts used for everyday work. Separate accounts for administrative tasks is a control people agree with and then do not implement.
- Default credentials and unnecessary services. New devices arrive insecure by default; secure configuration means changing that before deployment, not after an assessor asks.
Notice that three of the four are hygiene rather than architecture. Cyber Essentials certification does not usually fail because an organisation lacks tooling — it fails because nobody owns the routine.
Why organisations get certified
Three reasons, in roughly the order they appear in practice.
A contract requires it. A growing number of organisations require suppliers to be certified in order to bid, and it is mandatory for many UK central government contracts involving certain personal or sensitive information. That is usually what starts the conversation.
It is proportionate. For a small organisation, Cyber Essentials is achievable in weeks. ISO 27001 is a management system taking months. Starting with the wrong one wastes a year.
It demonstrates diligence. Not a defence in itself, but evidence that the basics were addressed deliberately rather than by accident.
IASME prices the assessment in four bands by organisation size — micro, small, medium and large — so cost scales with headcount rather than complexity.
Cyber Essentials certification against other frameworks
| Framework | How it relates |
|---|---|
| ISO 27001 | A full management system: risk-based, certifiable, far broader. Cyber Essentials is a controls baseline. Holding ISO 27001 does not automatically pass Cyber Essentials, because the five controls are tested specifically |
| NIST CSF | A governance framework, not a certification. Useful for structuring a programme around the five controls rather than replacing them |
| UK GDPR | Requires appropriate technical measures without naming them. Cyber Essentials is a defensible answer to what “appropriate” meant for the basics |
How to approach it
- Define the scope — whole organisation or a named subset, including home workers, BYOD and cloud services.
- Inventory what is in it. You cannot patch or configure what you have not listed, and unsupported software hides in inventories nobody maintains.
- Fix the four common failures before you answer a single question.
- Complete the self-assessment honestly. The questions are specific and answering optimistically simply moves the failure later.
- Decide on Plus — if a customer will eventually require it, going straight there avoids paying twice.
- Diarise the renewal. Certification is annual, and lapsed certificates get noticed at exactly the wrong moment.
This guide reflects the scheme as published by the NCSC and IASME at 15 August 2026. The question set is revised periodically, so confirm the current version with your certification body before you start.
The Cyber Essentials UK Toolkit provides 24 editable documents covering the scope definition, the five control policies, the asset inventory and the evidence records an assessor asks for — the parts that turn a set of good intentions into an answerable questionnaire.