Table of Contents

Cyber Essentials Scheme: All you need to know

Reviewed & Written by:

|

Published:

|

Updated:

September 28, 2026
What is Cyber Essentials: the UK government-backed cyber security certification
Table of Contents

Key takeaways

  • Cyber Essentials is the UK government-backed scheme that certifies an organisation has five basic technical security controls in place against the most common cyber attacks. The NCSC calls it the minimum standard of cyber security for organisations of all sizes.
  • It is owned by the National Cyber Security Centre (NCSC) and delivered by IASME, which licenses the certification bodies that assess organisations and issue certificates.
  • There are two certification levels: Cyber Essentials, a verified self-assessment, and Cyber Essentials Plus, which adds independent technical testing.
  • Certificates last 12 months and come with free cyber insurance for eligible UK organisations. The current requirements are version 3.3, assessed through the Danzell question set since 27 April 2026.
  • It is required for many UK government contracts and increasingly asked for by NHS, defence and private-sector buyers.

Cyber Essentials is the UK’s baseline cyber security certification. It confirms that an organisation has five technical controls in place that together defend against the most common cyber attacks from the internet: malware, phishing that leads to account takeover, and cyber criminals scanning for unpatched systems. Many UK buyers require Cyber Essentials from their suppliers, and it is often called Cyber Essentials accreditation.

This guide is for business owners, IT managers and anyone who has been asked for Cyber Essentials in a tender or a supplier cyber security questionnaire. It explains who runs the scheme, what the five controls are, the two certification levels, what Cyber Essentials certification costs, how long it takes and how to achieve it.

It matters because a Cyber Essentials certificate is now a routine condition of doing business with UK government, NHS and defence buyers, and because the controls it checks are the ones that stop most real attacks on small and medium organisations.

The UK government launched the scheme in June 2014, initially for small organisations that had never assessed their own security. It has since become the standard benchmark for UK organisations in the public sector, private companies and charities alike, and organisations outside the UK certify too.

Who runs the Cyber Essentials scheme?

The scheme is owned by the National Cyber Security Centre (NCSC) and has been delivered by IASME, as the NCSC’s sole Cyber Essentials delivery partner, since 1 April 2020. IASME licenses the certification bodies that assess organisations and issue certificates, and it maintains the public register of certified organisations. The requirements sit in a single NCSC document, Cyber Essentials: Requirements for IT Infrastructure, currently version 3.3.

What is the Cyber Essentials Scheme?

Cyber Essentials (CE) certification is a verified self-assessment. You answer IASME’s online self-assessment questionnaire about your IT infrastructure, a director or equivalent signs a declaration that the answers are true, and an IASME-licensed assessor marks it against the five technical controls. This level is often called standard Cyber Essentials, or basic Cyber Essentials, to distinguish it from Cyber Essentials Plus.

Think of the controls as a checkpoint: if any one is missing, your organisation is exposed to the kind of attack the scheme exists to stop. Where an answer does not meet the requirement, the assessor tells you what needs to change before a certificate can be issued.

Cyber essentials

It is a good first step on the security maturity ladder because it gives every organisation, whatever its sector or size, one benchmark for basic cyber hygiene. The annual renewal is what stops complacency: the controls have to stay in place, not be set up once for the certificate.

The main advantages for your business are:

  • It demonstrates a commitment to cyber security to customers and to the supply chains you sit in.
  • You and your team get a clear picture of your organisation’s security maturity.
  • Your controls are validated against the most common cyber attacks.
  • It is a requirement for many public sector and government contracts, and many private organisations ask for it as an assurance factor.
  • It can help win new business, because buyers use the public register of certified organisations to check suppliers.

Is it Cyber Essentials accreditation or certification?

You will see both words, and tenders and supplier questionnaires use them interchangeably. Strictly:

  • Organisations are certified. When you pass, you receive a Cyber Essentials or Cyber Essentials Plus certificate.
  • Certification bodies are licensed. IASME licenses the certification bodies that assess organisations and issue certificates.

“Cyber Essentials accreditation” is the everyday term many buyers use for the same thing. If a tender asks whether you are “Cyber Essentials accredited”, it is asking whether you hold a current certificate, and your certificate and register entry are the evidence.

Who needs Cyber Essentials?

Cyber Essentials is not a legal requirement, but many buyers require Cyber Essentials before they will contract with you:

  • Central government contracts that involve handling personal information or supplying certain ICT services, under Procurement Policy Note 014 (PPN 014 on gov.uk).
  • NHS Supply Chain, which asks in-scope suppliers for Cyber Essentials Plus.
  • The defence supply chain, where Cyber Essentials is the foundation of Defence Cyber Certification and the MOD has asked industry partners to reach DCC Level 0 by 31 December 2026.
  • The education sector, where the College Financial Handbook expects colleges to hold Cyber Essentials and renew it every year.
  • Private-sector buyers, increasingly through supplier security questionnaires.
  • Insurers and brokers, some of whom ask about it when pricing cover.

It is also common in recruitment, legal services and manufacturing, where firms hold sensitive data or sit in larger supply chains. See our guide to who requires Cyber Essentials and why for each requirement and its source, and our DCC Level 0 guide for defence suppliers.

How does the Cyber Essentials certification process work?

The certification process runs in the same way for every organisation, whatever its size:

  1. The NCSC sets the requirements in its Requirements for IT Infrastructure document.
  2. IASME turns them into a question set. The current set is called Danzell and has applied to new assessments since 27 April 2026. It replaced Willow; basic Willow assessments still in progress must be submitted by 26 October 2026. Our Danzell changes guide explains what changed.
  3. You choose an IASME-licensed certification body and agree your scope with it: the whole organisation, or a clearly separated part of it.
  4. You answer the questions and a director signs the declaration. The answers are your organisation’s responsibility; the assessor checks them, but does not write them.
  5. An assessor marks your answers. Pass, and you are certified and listed on the public register for 12 months. For Cyber Essentials Plus, an assessor then tests a sample of your devices and every cloud service.

Why was Cyber Essentials created?

Most of the cyber attacks we see against UK organisations are not sophisticated. The argument that only big companies are targets does not hold up: cyber criminals look for insecure installations, misconfigured applications, exposed endpoints, open databases and any stepping stone to a higher level of access, whoever owns them.

The government created Cyber Essentials to give organisations a clear, affordable cyber security standard that closes exactly those gaps, and to give buyers a simple way to check that suppliers have done so.

Which common online threats does Cyber Essentials protect against?

The scheme targets the most common cyber attacks: the ones that need little skill, are run at scale, and hit organisations of every size. Each of the five controls maps to one or more of the most common cyber threats below.

  • Phishing: emails that trick staff into handing over passwords or opening a malicious attachment. MFA and malware protection limit the damage when someone clicks.
  • Malware and ransomware: malicious software that runs on a device to encrypt or steal data. Malware protection and secure configuration are the main defences.
  • Password attacks: guessing weak passwords or reusing stolen ones against your accounts. User access control, with MFA and the lockout rules under secure configuration, addresses this.
  • Exploiting unpatched software: cyber criminals scan the internet for known vulnerabilities in out-of-date software. Security update management closes that window within 14 days.
  • Exposed services: remote access, admin panels or databases reachable from the internet when they never needed to be. A properly configured firewall keeps them off the internet.

Cyber Essentials does not address targeted attacks by a determined adversary, insider threats or weaknesses in software you have built yourself. That is by design; the section on its limits below explains what sits outside it.

What are the five Cyber Essentials controls?

The same five controls apply at both levels. The names below are the NCSC’s current names; older articles call them “boundary firewalls and internet gateways” and “patch management”.

  1. Firewalls: a properly configured firewall at the boundary between your internal network and the internet, and on every device, limiting the services accessible from the internet to those that are secure and necessary.
  2. Secure configuration: unnecessary accounts and software removed, no default passwords, and devices that lock after repeated wrong guesses.
  3. Security update management: supported software only, with high and critical updates applied within 14 days of release.
  4. User access control: approved accounts, separate administrator accounts, and multi-factor authentication (MFA) on every cloud service.
  5. Malware protection: anti-malware tools or application allow listing active on every in-scope device, so malicious software cannot run.

Under the Danzell question set, three areas carry stricter marking criteria and are automatic fails: unsupported software, a cloud service without MFA, and high or critical updates not applied within 14 days. Our guide to the five controls explains each one and what assessors look for.

cyber-essentials-controls

 

Achieving Cyber Essentials certification: the process step by step

Whether you are going for a tender, meeting a procurement prerequisite or simply want a baseline, the route to achieving certification is the same. It also prompts your team to act on controls that might otherwise drift.

  1. Agree your scope with a certification body: the whole organisation or, for complex organisations, a segregated part of it. Cloud services and end-user devices cannot be left out, and personal devices that access work data or services are in scope, with narrow exceptions (see our BYOD rules). See Cyber Essentials scope.
  2. Preview the questions using IASME’s free question set preview.
  3. Check the three automatic-fail areas first, because any one of them fails the assessment outright.
  4. Fix the gaps and gather evidence for each control.
  5. Complete the self-assessment in the IASME portal and submit it with a director’s signed declaration. Our self-assessment guide walks through it.
  6. An assessor marks it. Anything non-compliant can be corrected and resubmitted within two working days.
  7. Receive your Cyber Essentials certificate and register entry.
  8. For Cyber Essentials Plus, complete the remote audit within 90 days.
  9. Diarise renewal for 12 months’ time.

Our Cyber Essentials checklist turns these steps into a readiness list you can work through.

What is Cyber Essentials Plus?

Cyber Essentials Plus is the higher of the two certification levels. You complete the same questionnaire, and Cyber Essentials Plus adds independent technical testing: an assessor from your certification body tests whether the controls actually work on a sample of your in-scope devices and on every cloud service you use.

The scope is the same as your basic certificate; what changes is the evidence. The self-assessment tells the assessor what you believe is in place, and the audit shows what is actually there. Our Cyber Essentials Plus requirements guide covers each test.

What the Plus audit tests

The NCSC’s Cyber Essentials Plus Test Specification sets out five tests:

  1. External vulnerability scan of your internet-facing IP addresses, which the Test Specification calls the remote vulnerability assessment.
  2. Internal vulnerability scan of sampled devices, run with credentials, checking that high and critical updates were applied within 14 days.
  3. Malware tests by email and by web browser on sampled devices.
  4. MFA check on every cloud service, for a standard user and an administrator.
  5. Account separation check, confirming that standard users cannot run administrative tasks.

Cyphere delivers this as a remote audit: the user shares their screen and the assessor watches each test run. On-site testing happens only where it is genuinely needed and agreed with you in advance. If findings need fixing, you have 30 days to fix and retest them, and the whole audit must be completed within 90 days of the basic certificate.

Suggested read: Cyber Essentials Plus checklist. Free download: Cyber Essentials changes April 2026 (Willow to Danzell)  

cyber essentials vs cyber essentials plus

How long does it take, and how long does it last?

The question set takes a few hours for a prepared organisation; the preparation around it is the real work. A well-prepared organisation can achieve Cyber Essentials certification in one to two weeks; where technical baselines need putting in place first, treat it as a project of a couple of months. See how long Cyber Essentials takes.

Both certificates last 12 months. Renewal is a fresh assessment against the requirements current at the time, so the controls have to stay in place all year. See our renewal guide.

How much does Cyber Essentials cost?

Cyber Essentials pricing has two parts. Basic Cyber Essentials costs £320 to £600 + VAT; IASME sets the fee and bands it by organisation size, so it is the same whichever certification body you use.

Cyber Essentials Plus pricing is set by each certification body; with Cyphere it starts from £1,299 + VAT for organisations under 50 staff, covering both levels, the readiness check and the audit, and is £999 + VAT alongside a Cyphere security engagement.

Our cost guide has the full fee tables and the costs outside the fee.

Certification levels: Cyber Essentials or Cyber Essentials Plus?

 

Cyber Essentials

Cyber Essentials Plus

How it is assessed

Verified self-assessment: you answer the IASME question set, a director signs it, an assessor marks it

The same questionnaire, then an independent technical audit of sampled devices and every cloud service

Technical testing

None

External and internal vulnerability scans, malware tests, MFA and account separation checks

Timing

Days to weeks

Audit completed within 90 days of the basic certificate

Validity

12 months

12 months

Typical buyers

Most government contracts, basic supply chain questionnaires

MoD, NHS Supply Chain (DTAC requirements), higher-risk contracts, buyers wanting independent proof or customer assurances

Cyber Essentials Plus is right for your organisation if a buyer asks for it, or if you want independent proof that the controls work rather than a declaration that they do. Basic Cyber Essentials is the right starting point if no buyer is asking for Plus, or if your estate still has unsupported devices to replace.

Buying an audit you are likely to fail is poor value; certify at the basic level, fix the gaps, and move to Plus when a customer asks for it or you are ready. Our comparison of Cyber Essentials vs Cyber Essentials Plus goes into the choice in detail.

What do you get with a Cyber Essentials certificate?

After successful certification you receive:

  • A Cyber Essentials certificate valid for 12 months, at the level you achieved.
  • An entry on IASME’s public register of certified organisations, which buyers use to check suppliers (see our certificate check guide).
  • The right to display the Cyber Essentials badge on your website and marketing materials.
  • Free cyber insurance: organisations domiciled in the UK or Crown Dependencies with annual turnover under £20 million that certify the whole organisation can opt in to £25,000 of cyber liability insurance at no extra cost, including a 24-hour incident response helpline (IASME).

Whether that adds up for your organisation is covered in is Cyber Essentials worth it?

Free resources before you pay

  • The question set preview: IASME publishes the full question set
  • The readiness tool: IASME’s free online tool turns your answers into an action plan.
  • The Cyber Essentials Knowledge Hub: IASME’s guidance on each control, operating systems and scope.
  • Cyber Advisors: advisers working for NCSC Assured Service Providers under the Cyber Advisor scheme, who give small organisations practical support to put the controls in place.
  • The NCSC’s requirements document, free to download.

Does Cyber Essentials protect against all cyber attacks?

No, and it does not claim to. It is built to stop common, opportunistic cyber attacks from the internet. It does not test your web applications, detect a targeted attacker, or cover backups, incident response or wider risk management.

For organisations that need governance and data protection evidence as well, IASME Cyber Assurance builds on the Cyber Essentials certificate; Cyphere certifies both of its levels. Our framework comparison sets out the options.

Cyber Essentials and UK GDPR

Cyber Essentials is not a GDPR requirement, and certification does not make an organisation GDPR compliant. It does evidence appropriate technical cyber security measures, which is part of what UK GDPR expects from any organisation handling personal data.

How Cyphere delivers Cyber Essentials certification

From the Cyber Essentials assessors’ desk

We are an IASME-licensed certification body with our own assessors, so the assessors who are essentially cyber security professionals help you prepare understand exactly how submissions are marked. An engagement runs from a scoping conversation, through a readiness check against the three automatic-fail areas, to submission, marking and, where needed, the Plus audit, delivered remotely.We publish our prices and answer questions throughout, because Cyber Essentials should be a straightforward baseline, not a mystery.

– Harman Singh, IASME-licensed Cyber Essentials assessor, Cyphere

Talk to an IASME-licensed assessor

What is Cyber Essentials? FAQs

What is Cyber Essentials in plain English?

A UK government-backed certificate showing your organisation has five basic security controls in place: firewalls, secure configuration, security updates, user access control and malware protection. It is assessed by an IASME-licensed certification body and lasts 12 months.

Is Cyber Essentials mandatory?

No, not by law. It is required by many government contracts, asked for by NHS Supply Chain and defence buyers, and increasingly by private-sector customers. See which buyers require it and why.

Who certifies Cyber Essentials?

IASME-licensed certification bodies, on behalf of the NCSC. You can check a certification body’s licence in IASME’s directory. See our certification body guide.

Is Cyber Essentials the same as ISO 27001?

No. Cyber Essentials covers five technical controls; ISO 27001 is an international standard for a full information security management system. See Cyber Essentials vs ISO 27001.

Is “Cyber Security Essentials” the same thing?

Usually, yes. People often search for “Cyber Security Essentials” when they mean the government’s Cyber Essentials scheme. The official name is Cyber Essentials, and that is the name to use in tenders and on your website.

Can organisations outside the UK get Cyber Essentials?

Yes. Organisations outside the UK certify in the same way, and IASME publishes guidance for them. Its value depends on whether your customers are in the UK supply chain, because UK buyers are the ones who recognise it.

Explore the Cyber Essentials guides

Requirements and assessment

Planning and cost

Comparisons and choices

Sector and supply chain

After certification

Achieve Cyber Essentials Certification With Confidence

We handle the technical assessment, identify control gaps, and provide audit-ready evidence so you meet certification deadlines for a first-time pass.

Trusted by 150+ UK orgs

Related Reads

Join 1000+ subscribers getting the best tips on cybersecurity, security management, and more!

You may opt-out at any time. Read our privacy policy.

Request a Consultation

No obligations. Free retests included. Call us directly 0333 050 9002. View our privacy policy.

How "Defensible" is your firm compared to UK peers?

Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.