Cyber Essentials is one of the simplest and most cost-effective ways for a UK business to prove it takes security seriously. Backed by the UK Government and the National Cyber Security Centre (NCSC), it sets out a clear baseline of protections that stop the overwhelming majority of common cyber attacks. For a growing number of organisations, it is also becoming a requirement to win work.
This guide explains what Cyber Essentials is, why it matters, the five controls it covers, how much it costs, and exactly how to get certified – all without the jargon.
What is Cyber Essentials?
Cyber Essentials is a UK Government-backed certification scheme that helps organisations guard against the most common online threats. It focuses on five practical, technical controls that, when implemented properly, protect against around 80% of typical cyber attacks – the everyday, opportunistic attacks that make up the bulk of what businesses actually face.
There are two levels. Cyber Essentials is a self-assessment verified by a certification body, and Cyber Essentials Plus adds a hands-on technical audit for stronger assurance. Both cover the same five controls; the difference is how thoroughly your setup is checked.
Why Cyber Essentials matters for UK businesses
Certification is about far more than a badge on your website. Many UK public-sector contracts – and a growing number of private ones – now require Cyber Essentials before you can even bid. Central government contracts that involve handling certain personal or sensitive information have mandated it for years, and larger companies increasingly ask their suppliers to hold it too.
Beyond winning work, it demonstrates due diligence under the UK GDPR, can reduce your cyber insurance premiums, and reassures clients that their data is in safe hands. In short, it is a credible, recognised signal of trust that punches well above its modest cost.
The headline benefits for most businesses are:
- Win more work – meet a common tender and supplier requirement
- Reduce risk – block around 80% of common cyber attacks
- Support compliance – show due diligence under the UK GDPR
- Lower insurance costs – many insurers reward certification
- Build trust – reassure clients and partners with a recognised standard
The five Cyber Essentials controls

Every part of Cyber Essentials comes back to these five technical controls. Here is what each one means in practice for your business.
1. Firewalls
Firewalls protect the boundary between your network and the internet, only allowing through traffic you have approved. A properly configured, actively managed firewall is your first line of defence. Our managed firewall service keeps yours monitored, patched and correctly configured so it does its job around the clock.
2. Secure configuration
Devices and software often ship with insecure defaults – blank or well-known passwords, unnecessary features switched on, sample accounts left in place. Secure configuration means removing what you do not need and locking down what you do, so there is far less for an attacker to exploit.
3. User access control
People should have only the access their role requires, and administrator accounts must be tightly controlled and protected with strong authentication such as MFA. Good access control limits the damage a single compromised account can cause and makes it much harder for an attacker to move around your systems.
4. Malware protection
You need reliable anti-malware defences and a policy of only running trusted, approved software. Modern endpoint protection detects and blocks threats on laptops, desktops and servers before they can spread, and gives you visibility of anything suspicious.
5. Security update management
Unpatched software is one of the easiest ways in for attackers. Operating systems and applications must be kept up to date, with security patches applied promptly and unsupported software removed. Automating this through managed IT support is by far the most reliable approach.
Cyber Essentials vs Cyber Essentials Plus
Cyber Essentials is a verified self-assessment: you answer a questionnaire about how you meet the five controls, and a certification body reviews it. Cyber Essentials Plus covers exactly the same five controls but adds an independent technical audit, where a qualified assessor tests your systems directly to confirm the controls really are in place.
Plus offers stronger assurance and is sometimes required by larger clients or higher-risk contracts, but most businesses start with the standard certification and progress to Plus once the basics are embedded.
How much does it cost, and how long does it take?
Cyber Essentials is deliberately accessible. The certification fee for the standard level is modest and scaled to the size of your organisation, and Cyber Essentials Plus costs more because of the technical audit involved. The bigger investment is usually the time to close any gaps beforehand – but for most UK SMEs with a reasonably modern setup, the whole process takes just a few weeks.
How to get certified

The path to certification is refreshingly straightforward:
- Define your scope – agree which devices, cloud services and users are included.
- Close the gaps – review each of the five controls and fix anything that falls short.
- Complete the self-assessment – answer the official online questionnaire honestly and accurately.
- Get certified – pass the review, receive your certificate, and consider Cyber Essentials Plus.
Common pitfalls to avoid
- Forgetting to include home and mobile devices that access company data
- Leaving cloud services like Microsoft 365 out of scope
- Weak or missing multi-factor authentication on key accounts
- Unsupported software or operating systems still in everyday use
- Treating it as a one-off – certification must be renewed every year
Keeping your certification current
Cyber Essentials is valid for twelve months, so it is best treated as an ongoing standard rather than a one-off tick-box. New devices, new staff and new software can all quietly move you out of line with the controls. Building the five controls into your day-to-day IT – through managed support, patching and monitoring – means recertification each year is a formality rather than a scramble.
Who needs Cyber Essentials?
Any UK organisation that handles data, bids for contracts, or simply wants to reduce risk can benefit. It is especially relevant for businesses working with the public sector, professional-services firms handling client data such as accountancy, legal and recruitment, and any company that stores personal or financial information. If you are unsure whether it applies to you, the safe assumption is that it does – the five controls are good security hygiene for every business.
Cyber Essentials and the UK GDPR
The UK GDPR requires “appropriate technical and organisational measures” to protect personal data, but it deliberately does not spell out exactly what those measures should be. Cyber Essentials fills that gap with a concrete, recognised baseline. Achieving certification is a practical way to show the Information Commissioner’s Office (ICO), your clients and your insurers that you have taken security seriously. It will not, on its own, make you fully GDPR-compliant – that also involves policies, staff training and sound data handling – but it is a strong, verifiable foundation to build on.
Frequently asked questions
How long is Cyber Essentials valid?
Certification lasts twelve months, after which you renew to confirm your controls are still in place and effective.
Do we need Cyber Essentials Plus?
Not necessarily. Most businesses start with standard Cyber Essentials and only pursue Plus if a specific client or contract requires the additional independent technical audit.
Does it cover Microsoft 365 and cloud services?
Yes. Cloud services that hold your data, including Microsoft 365, should be in scope, and their security settings are assessed as part of the five controls.
Can we do it ourselves?
You can, but most SMEs find it faster and far less stressful to work with an IT partner who knows the requirements, closes the gaps and completes the assessment with you.
How Promax helps you get – and stay – certified
We take the guesswork out of Cyber Essentials. We assess your current setup against all five controls, fix the gaps across your firewall, endpoint protection and Microsoft 365, and guide you through the assessment from start to finish. With ongoing managed IT support, we keep you compliant year after year – not just on certification day.
Want to get certified without the headache? Get in touch for a free IT health check and we will map out your fastest route to Cyber Essentials.

Leave a Reply