Guide · Security

Cyber Essentials for small businesses: what it is, what it costs and how to pass

The five controls, the questions that catch people out, and what to fix before you apply.

Rob Sherwood, co-founder of Dev Partners
The short answer: Cyber Essentials is the UK government's basic cyber security certificate. You answer an online questionnaire on five controls and an assessor checks it. Most small businesses fail on the same few things (updates more than 14 days behind, no two-factor login on cloud services, and unsupported operating systems), so fix those first.

Cyber Essentials usually arrives in a small business the same way. A customer's procurement form has a box that says "Do you hold Cyber Essentials?", and nobody's quite sure what it is. Someone googles it, finds a lot of acronyms, and puts it on the pile.

It's less scary than it looks. Dev Partners holds it (here's our certificate), so this is written from the applicant's side of the table. Here's what it is, what it costs, where people trip up, and how to get through it first time.

What is Cyber Essentials?

Cyber Essentials is the UK government's baseline cyber security certificate, backed by the National Cyber Security Centre (NCSC). It's designed to stop the common, unsophisticated attacks that hit small businesses every day: phishing, guessed passwords, and people scanning the internet for out-of-date software.

It isn't a deep audit and it doesn't make you hack-proof. It checks that you've done the basics properly. The basics happen to stop most of the attacks that actually happen to small firms, which is the whole point.

Certification is run by IASME, the NCSC's delivery partner, through a network of certification bodies who do the assessing. A certificate lasts 12 months, then you renew.

Three reasons it's worth doing

  • Contracts. Many central government contracts that handle personal data require it, and a growing number of private-sector customers ask for it before you can bid.
  • Insurance. Any UK organisation with a turnover under £20 million that certifies its whole organisation is entitled to cyber liability insurance, with 24-hour incident response support (NCSC). If you already have cyber insurance, check how the two fit together.
  • It actually helps. Doing the work closes the holes most small-business breaches come through.

What the assessor checks, in plain English

1. Firewalls

Every device that connects to the internet sits behind a firewall that's set up properly: default admin passwords changed, no ports open that don't need to be, and the admin page not reachable from the internet. Laptops used at home or on the move need their own software firewall switched on.

2. Secure configuration

Computers, phones, servers and cloud services are set up sensibly rather than left on factory settings. Unused software and accounts removed. Auto-run turned off. Devices locked with a PIN or password. Default passwords changed everywhere.

3. User access control

People only have the access they need. Admin accounts are separate from everyday accounts and only used for admin. Leavers' accounts are shut off. Two-factor login (also called multi-factor authentication, or MFA) is on wherever it's offered, and always on cloud services.

4. Malware protection

Anti-malware is running and up to date on devices that need it, or devices are locked down so only approved apps can be installed. The built-in protection in modern Windows and macOS usually counts if it's switched on and updating.

5. Security update management

All software is licensed and still supported by its maker, and critical and high-risk security updates are installed within 14 days of release. This is the one that catches the most people out.

The same handful of things, every time

Fix these before you apply and you're most of the way there.

  • Updates more than 14 days behind. Not just Windows. Browsers, PDF readers, Office, phone operating systems, router firmware and the server in the cupboard. Turn on automatic updates everywhere you can, and check the things that don't update themselves. Under the question set in use since April 2026, leaving critical or high-risk updates uninstalled for more than 14 days is an automatic fail.
  • No two-factor login on cloud services. Microsoft 365, Google Workspace, Xero, your CRM, your website's admin panel. If it's in the cloud and offers two-factor login, it needs to be on for every user. For assessments started after 27 April 2026, missing this on any cloud service that offers it (free, bundled or paid extra) is an automatic fail (IASME).
  • Unsupported software. Windows 10 reached end of support in October 2025. Old versions of Office, old phones that no longer get updates, an ancient Windows Server: anything the maker no longer patches has to go, or be taken out of scope and cut off from the internet.
  • Everyday admin accounts. If staff log in as administrators to do their normal work, that's a fail. Give them standard accounts and keep admin accounts for admin.
  • Forgotten devices. Personal phones that get work email are in scope. So are home laptops used for work. People forget these. Assessors don't.
  • Default passwords. The broadband router, the printer, the NAS box. Change them.

Cyber Essentials or Cyber Essentials Plus?

Cyber EssentialsCyber Essentials Plus
How it's checkedOnline questionnaire, reviewed by an assessorThe same controls, plus a hands-on technical audit
What the assessor doesReads your answersScans your systems, tests a sample of devices, and tries test malware and phishing-style files
OrderComes firstDone within three months of passing the basic certificate
Who asks for itMost supplier questionnairesLarger customers, and some public-sector and defence work

Start with the basic certificate. Only go for Plus if a customer asks for it, or you want the reassurance of someone actually testing your setup.

The process, start to finish

  1. Decide the scope. Usually the whole business. You can certify part of it, but customers prefer whole-business certificates, and the insurance only comes with those.
  2. Get the questions early. The question set is published free on the IASME website. Read it before you buy anything. It changes every year or so, usually in April. The set in use since April 2026 is called Danzell, and goes with version 3.3 of the requirements.
  3. Fix the gaps. This is where the time goes. For a tidy ten-person office it might be a few days. For a business with old kit and no two-factor login, a few weeks.
  4. Apply and answer online. Through IASME or a certification body. A director or equivalent has to sign off that the answers are true.
  5. Assessment. An assessor reviews your answers, usually within a few working days. If something's wrong you normally get a short window to fix it and resubmit. Fail outright and you'll usually have to start again and pay again, so it's worth getting it right first time.
  6. Certificate. You're listed on the public register, and you renew every 12 months.

What does Cyber Essentials cost?

The basic certificate fee is set by IASME and depends on the size of your organisation. At the time of writing it's £320 for micro organisations (up to 9 staff), £440 for small (10 to 49), £500 for medium (50 to 249) and £600 for large, all plus VAT (IASME). Cyber Essentials Plus is quoted by the certification body, because it involves an assessor's time and depends on how big your network is.

The fee is the cheap bit. The real cost is the work to get compliant: replacing unsupported machines, setting up two-factor login, sorting out admin accounts and putting updates on a proper footing. That's a one-off effort, then a bit of upkeep to stay compliant for the renewal.

What we'd do in your shoes

Download the question set and go through it honestly with whoever looks after your systems. Make a list of every "no". Then fix them in this order: two-factor login on every cloud account, updates switched on everywhere, unsupported kit replaced or removed, and admin rights taken off everyday accounts. Only then apply.

Plenty of businesses do this themselves with a free afternoon and the question set, and that's a perfectly good way to go. But if the list of "no"s is long, it's rarely a Cyber Essentials problem. It's a sign nobody owns technology across the business, so the same gaps will be back by next year's renewal.

That's the gap we fill, so take this with a pinch of salt. Getting ready for Cyber Essentials, and staying ready, is part of how we look after servers and systems: patching on a schedule, access checked, and our own in-house scanning tools run against what we look after. We'd also recommend an independent penetration test once a year for most businesses, or every quarter if you hold a lot of sensitive data, and we'll help you choose a tester. The certification fee is paid direct to the certification body.

Want someone to own it?

We get businesses ready for Cyber Essentials as part of looking after their servers, security and backups, or as one part of Your tech department: one team that plans, builds, runs and secures the lot for one monthly fee.

Cyber Essentials questions

The assessment itself usually takes a few working days. The preparation is what takes time: a few days for a tidy small office, a few weeks if you need to replace old equipment or set up two-factor login across the business.

At the time of writing, the basic certificate costs £320 plus VAT for micro organisations (up to 9 staff), £440 for small (10 to 49), £500 for medium (50 to 249) and £600 for large. Cyber Essentials Plus is quoted separately by the certification body, because an assessor tests your systems.

Security updates. Critical and high-risk updates must be installed within 14 days, on every device and piece of software in scope. Missing two-factor login on cloud services and running unsupported software such as Windows 10 are close behind.

Cyber Essentials is a self-assessment questionnaire checked by an assessor. Cyber Essentials Plus covers the same controls, but an assessor also tests your systems directly, for example by scanning for vulnerabilities and checking a sample of devices. Plus comes after the basic certificate.

No. But many government contracts that handle personal data require it, and a growing number of private-sector customers ask for it from their suppliers.

Getting ready for Cyber Essentials?

Tell us where you are and we'll tell you what's likely to fail.

How many people and devices you have, what cloud services you use, and whether a customer is asking for the certificate by a particular date.

What we will cover:

  • What usually fails, and what to fix first
  • Whether Cyber Essentials Plus is worth it for you
  • Who keeps you compliant for the renewal

Rather talk now? Book a call or ring 01474 639 089.

We reply within one working day.

Get in touch