What is Cyber Essentials?
Cyber Essentials is a certification scheme launched by the UK government in 2014, overseen by the NCSC (National Cyber Security Centre) and operated by the IASME Consortium as the sole certification partner. The scheme aims to protect organisations against the most common, commodity internet-based attacks — those exploiting unpatched systems, weak passwords and misconfigurations rather than advanced techniques.
The scheme defines five technical control themes: firewalls, secure configuration, user access control, malware protection, and security update management. The requirements are updated regularly — the current version of the standard ("Willow") clarifies, among other things, the rules for remote working, cloud services, MFA and passwordless authentication.
Who is it for?
Any organisation can obtain Cyber Essentials, regardless of size, industry or country of registration — certified organisations range from sole traders to multinational corporations. For companies outside the UK, the certificate is most often needed when selling to UK customers or participating in UK supply chains.
Since 2014 Cyber Essentials has been mandatory for suppliers bidding for certain UK central government contracts — particularly those involving the handling of personal information and the provision of certain ICT services. It is increasingly required by large commercial buyers, insurers (IASME certification includes cyber insurance for eligible small UK organisations), and bodies such as the Ministry of Defence, which requires Cyber Essentials throughout its supply chain.
The five controls
The scheme’s strength is its simplicity: instead of hundreds of requirements, five control themes that according to the NCSC stop the large majority of commodity internet attacks. The scope covers all devices and services with access to organisational data, including personally owned devices (BYOD) and cloud services.
- Firewalls — a boundary firewall on every network and software firewalls on devices; default passwords changed; inbound traffic blocked by default with every rule approved and documented.
- Secure configuration — unnecessary software, services and accounts removed; auto-run disabled; device locking (PIN or biometrics); no default passwords anywhere.
- User access control — named accounts with an approval process, least privilege, separate administrative accounts, MFA for cloud services, passwords of at least 12 characters (8 with MFA) with brute-force protection.
- Malware protection — anti-malware with real-time scanning and malicious website blocking, or application allow-listing; mobile devices restricted to approved app stores.
- Security update management — only vendor-supported software; critical and high severity patches (CVSS 7+) installed within 14 days; automatic updates enabled wherever possible.
Cyber Essentials vs Cyber Essentials Plus
The scheme has two levels based on the same five controls — they differ in how compliance is verified. Basic Cyber Essentials is a verified self-assessment: the organisation completes a questionnaire (several dozen questions about its environment), a board member signs the declaration, and a licensed certification body assesses the answers. The certificate can be obtained within days.
Cyber Essentials Plus covers the same requirements but adds an independent technical audit: an assessor performs an external vulnerability scan of your IP addresses, an authenticated scan of a sample of workstations and servers, browser and email file-download tests (checking that malicious files are blocked) and configuration verification. The CE Plus audit must be completed within 3 months of the basic certification it builds on. For customers and buyers, CE Plus provides materially stronger assurance because the controls have been tested in practice, not merely declared.
How long does it take and what does it cost?
Cyber Essentials is the fastest of the popular security certifications to obtain. An organisation with well-managed IT can complete the self-assessment in 1-2 weeks; preparing from scratch (rolling out MFA, cleaning up admin accounts, replacing unsupported software) typically takes 1-3 months. The certificate is valid for 12 months and requires annual recertification.
Basic Cyber Essentials has a fixed fee based on organisation size — from £320 to £600 plus VAT per year (micro businesses pay the least). Cyber Essentials Plus is priced individually by certification bodies depending on the size and complexity of the environment — for small companies it starts around £1,400-2,000. The biggest real investment is usually bringing the environment into compliance: replacing unsupported systems and consistently enforcing MFA and the 14-day patching window.
How does Guardiso help?
Guardiso turns the Cyber Essentials requirements into concrete, measurable controls and keeps them on track all year — so annual recertification becomes a formality.
- Controls for all five scheme themes seeded automatically when you enable the standard — with descriptions, statuses and owners.
- A maturity self-assessment that surfaces gaps against the scheme requirements before you complete the official questionnaire.
- Evidence collected in one place: device and software inventory, MFA confirmations, patching reports.
- Recurring tasks that police the 14-day update window and administrative account reviews.
- Policies (passwords, devices, BYOD) generated from templates and tailored to your organisation.
- Cross-mapping to ISO 27001 and NIS 2 — Cyber Essentials controls count towards overlapping requirements of the bigger frameworks and vice versa.
- A growth path: after Cyber Essentials the natural next step is ISO 27001 — the work done in Guardiso carries over.
