← Back to Blog

Cyber Essentials Certification UK: Cost, Controls, and Process

Cyber Essentials is the security certification UK buyers ask for most often. It turns up in public sector procurement, in enterprise supplier questionnaires, and increasingly as a condition of cyber insurance. It is deliberately not a deep security standard — it is a baseline of five technical controls that block the large majority of commodity internet attacks, and it is achievable for a small company in a few weeks.

What it is and who actually needs it

Cyber Essentials is a UK government-backed scheme developed with the National Cyber Security Centre and delivered through the IASME Consortium and its network of certification bodies. Certification lasts twelve months, after which you recertify.

It became genuinely commercially necessary for a lot of UK suppliers because central government requires it for contracts involving the handling of personal or sensitive information and certain ICT services, and the requirement then cascades down supply chains. Defence suppliers meet it routinely. Beyond the public sector, large enterprises now include it in procurement questionnaires because it is a cheap, standardised signal, and insurers increasingly ask about the same controls when pricing cyber cover.

If you sell software or IT services to UK public bodies, or to enterprises with a mature procurement function, assume you will be asked for it. Getting certified before a tender lands is far less stressful than trying to compress it into a bid window.

The five controls, in plain terms

Firewalls. Every device must sit behind a correctly configured boundary or software firewall, with default administrative passwords changed and inbound services blocked unless there is a documented business need.

Secure configuration. Remove or disable what you do not use: unnecessary accounts, default accounts, preinstalled software, and any service you cannot justify. Default passwords must be changed everywhere, including on network equipment people forget exists.

User access control. Accounts are created through an approval process, users get the minimum privileges they need, administrative accounts are used only for administrative work rather than for daily email and browsing, and accounts are removed promptly when people leave. Multi-factor authentication is required on cloud services, and this is the single control most often found missing.

Malware protection. Anti-malware on in-scope devices, kept updated, or an approved alternative such as application allow-listing on tightly managed devices.

Security update management. All software must be supported by its vendor and licensed, and updates rated critical or high severity must be applied within fourteen days of release. Unsupported software has to be removed or moved out of scope behind proper segregation — this is what usually forces the retirement of an old server nobody wanted to touch.

Cyber Essentials versus Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
How it is assessedSelf-assessment questionnaire, reviewed by a certification bodyHands-on technical audit by an assessor
What is checkedYour written answers about the five controlsSampled devices, vulnerability scans, email and web tests
Typical effortDays of internal preparationThe above, plus an assessor engagement and remediation
Timing constraintStandaloneMust be completed within three months of passing Cyber Essentials
When you need itMost procurement questionnairesContracts that specifically demand Plus

Plus is not a different standard. It verifies the same five controls by testing rather than trusting your answers. If a tender does not explicitly require Plus, standard certification is usually the right starting point.

What it costs

ItemIndicative costTimeline
Cyber Essentials, micro organisation (under 10 staff)£300 – £400 +VAT1–3 weeks
Cyber Essentials, small organisation (10–49)£400 – £500 +VAT2–4 weeks
Cyber Essentials, medium or large (50+)£500 – £700 +VAT3–6 weeks
Cyber Essentials Plus audit£1,400 – £3,500+4–8 weeks after CE
Consultant-supported readiness and remediation£2,000 – £8,000Runs alongside

Certification fees are tiered by organisation size and are reviewed periodically, so confirm current figures with IASME or your certification body before budgeting. The fee is rarely the real cost anyway. The real cost is the remediation work the assessment surfaces: replacing unsupported machines, rolling out MFA, building a patching process, and untangling who has administrative access to what.

Where applications actually fail

The findings that most often cause a first attempt to fail:

Multi-factor authentication missing on cloud services, particularly on administrative accounts in Microsoft 365 or Google Workspace
Unsupported operating systems or software still in scope — an old Windows build, an end-of-life database, an unpatched router
Critical and high severity patches not applied within the fourteen day window, usually because nobody owns patching
Administrative accounts used for everyday email and web browsing rather than reserved for administrative tasks
Default credentials left in place on network equipment, printers, or a device installed years ago by a supplier
Personal devices used for work but excluded from scope without a defensible reason, which is not permitted
Scope drawn to conveniently exclude the awkward part of the network, which assessors are experienced at spotting

Scoping is where most confusion arises. The default expectation is that the whole organisation is in scope. You can certify a genuinely segregated sub-part of the business, but the segregation has to be real and demonstrable, not an organisational chart drawn around the difficult systems.

How to prepare

Start with an asset inventory, because you cannot certify what you have not listed: every device, every cloud service, every account with administrative rights. Most organisations find things here they had forgotten they were paying for.

Then run a gap assessment against the five controls and fix in order of what will fail you: unsupported software first, MFA second, patching process third. Do the questionnaire last, once the controls are genuinely in place. Answering optimistically and hoping it passes is a common and expensive mistake, particularly if you go on to Plus, where an assessor will test the claims directly.

Allow six to eight weeks end to end for a first certification if you have remediation to do, and less on recertification once the processes exist. Build the patching and access review into a recurring calendar commitment rather than an annual scramble, and next year takes days instead of weeks.

AyTech note: Certification is a point-in-time assessment against a baseline, not proof that you are secure. Treat it as the floor you build on, not the ceiling. If you handle sensitive customer data at scale, plan for penetration testing and a path toward ISO 27001 alongside it.

Need a practical technical plan?

AyTech can review your requirements, map the risks, and turn the idea into a scoped delivery plan.

Cybersecurity services
Muhammad Nouman
Muhammad Nouman
Founder & Lead Engineer, AyTech Solutions