What it is and who actually needs it
Cyber Essentials is a UK government-backed scheme developed with the National Cyber Security Centre and delivered through the IASME Consortium and its network of certification bodies. Certification lasts twelve months, after which you recertify.
It became genuinely commercially necessary for a lot of UK suppliers because central government requires it for contracts involving the handling of personal or sensitive information and certain ICT services, and the requirement then cascades down supply chains. Defence suppliers meet it routinely. Beyond the public sector, large enterprises now include it in procurement questionnaires because it is a cheap, standardised signal, and insurers increasingly ask about the same controls when pricing cyber cover.
If you sell software or IT services to UK public bodies, or to enterprises with a mature procurement function, assume you will be asked for it. Getting certified before a tender lands is far less stressful than trying to compress it into a bid window.
The five controls, in plain terms
Firewalls. Every device must sit behind a correctly configured boundary or software firewall, with default administrative passwords changed and inbound services blocked unless there is a documented business need.
Secure configuration. Remove or disable what you do not use: unnecessary accounts, default accounts, preinstalled software, and any service you cannot justify. Default passwords must be changed everywhere, including on network equipment people forget exists.
User access control. Accounts are created through an approval process, users get the minimum privileges they need, administrative accounts are used only for administrative work rather than for daily email and browsing, and accounts are removed promptly when people leave. Multi-factor authentication is required on cloud services, and this is the single control most often found missing.
Malware protection. Anti-malware on in-scope devices, kept updated, or an approved alternative such as application allow-listing on tightly managed devices.
Security update management. All software must be supported by its vendor and licensed, and updates rated critical or high severity must be applied within fourteen days of release. Unsupported software has to be removed or moved out of scope behind proper segregation — this is what usually forces the retirement of an old server nobody wanted to touch.
Cyber Essentials versus Cyber Essentials Plus
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| How it is assessed | Self-assessment questionnaire, reviewed by a certification body | Hands-on technical audit by an assessor |
| What is checked | Your written answers about the five controls | Sampled devices, vulnerability scans, email and web tests |
| Typical effort | Days of internal preparation | The above, plus an assessor engagement and remediation |
| Timing constraint | Standalone | Must be completed within three months of passing Cyber Essentials |
| When you need it | Most procurement questionnaires | Contracts that specifically demand Plus |
Plus is not a different standard. It verifies the same five controls by testing rather than trusting your answers. If a tender does not explicitly require Plus, standard certification is usually the right starting point.
What it costs
| Item | Indicative cost | Timeline |
|---|---|---|
| Cyber Essentials, micro organisation (under 10 staff) | £300 – £400 +VAT | 1–3 weeks |
| Cyber Essentials, small organisation (10–49) | £400 – £500 +VAT | 2–4 weeks |
| Cyber Essentials, medium or large (50+) | £500 – £700 +VAT | 3–6 weeks |
| Cyber Essentials Plus audit | £1,400 – £3,500+ | 4–8 weeks after CE |
| Consultant-supported readiness and remediation | £2,000 – £8,000 | Runs alongside |
Certification fees are tiered by organisation size and are reviewed periodically, so confirm current figures with IASME or your certification body before budgeting. The fee is rarely the real cost anyway. The real cost is the remediation work the assessment surfaces: replacing unsupported machines, rolling out MFA, building a patching process, and untangling who has administrative access to what.
Where applications actually fail
The findings that most often cause a first attempt to fail:
Scoping is where most confusion arises. The default expectation is that the whole organisation is in scope. You can certify a genuinely segregated sub-part of the business, but the segregation has to be real and demonstrable, not an organisational chart drawn around the difficult systems.
How to prepare
Start with an asset inventory, because you cannot certify what you have not listed: every device, every cloud service, every account with administrative rights. Most organisations find things here they had forgotten they were paying for.
Then run a gap assessment against the five controls and fix in order of what will fail you: unsupported software first, MFA second, patching process third. Do the questionnaire last, once the controls are genuinely in place. Answering optimistically and hoping it passes is a common and expensive mistake, particularly if you go on to Plus, where an assessor will test the claims directly.
Allow six to eight weeks end to end for a first certification if you have remediation to do, and less on recertification once the processes exist. Build the patching and access review into a recurring calendar commitment rather than an annual scramble, and next year takes days instead of weeks.
AyTech note: Certification is a point-in-time assessment against a baseline, not proof that you are secure. Treat it as the floor you build on, not the ceiling. If you handle sensitive customer data at scale, plan for penetration testing and a path toward ISO 27001 alongside it.
Need a practical technical plan?
AyTech can review your requirements, map the risks, and turn the idea into a scoped delivery plan.
Cybersecurity services