Guide · Security
The five controls, the questions that catch people out, and what to fix before you apply.
Cyber Essentials usually arrives in a small business the same way. A customer's procurement form has a box that says "Do you hold Cyber Essentials?", and nobody's quite sure what it is. Someone googles it, finds a lot of acronyms, and puts it on the pile.
It's less scary than it looks. Dev Partners holds it (here's our certificate), so this is written from the applicant's side of the table. Here's what it is, what it costs, where people trip up, and how to get through it first time.
Cyber Essentials is the UK government's baseline cyber security certificate, backed by the National Cyber Security Centre (NCSC). It's designed to stop the common, unsophisticated attacks that hit small businesses every day: phishing, guessed passwords, and people scanning the internet for out-of-date software.
It isn't a deep audit and it doesn't make you hack-proof. It checks that you've done the basics properly. The basics happen to stop most of the attacks that actually happen to small firms, which is the whole point.
Certification is run by IASME, the NCSC's delivery partner, through a network of certification bodies who do the assessing. A certificate lasts 12 months, then you renew.
Every device that connects to the internet sits behind a firewall that's set up properly: default admin passwords changed, no ports open that don't need to be, and the admin page not reachable from the internet. Laptops used at home or on the move need their own software firewall switched on.
Computers, phones, servers and cloud services are set up sensibly rather than left on factory settings. Unused software and accounts removed. Auto-run turned off. Devices locked with a PIN or password. Default passwords changed everywhere.
People only have the access they need. Admin accounts are separate from everyday accounts and only used for admin. Leavers' accounts are shut off. Two-factor login (also called multi-factor authentication, or MFA) is on wherever it's offered, and always on cloud services.
Anti-malware is running and up to date on devices that need it, or devices are locked down so only approved apps can be installed. The built-in protection in modern Windows and macOS usually counts if it's switched on and updating.
All software is licensed and still supported by its maker, and critical and high-risk security updates are installed within 14 days of release. This is the one that catches the most people out.
Fix these before you apply and you're most of the way there.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| How it's checked | Online questionnaire, reviewed by an assessor | The same controls, plus a hands-on technical audit |
| What the assessor does | Reads your answers | Scans your systems, tests a sample of devices, and tries test malware and phishing-style files |
| Order | Comes first | Done within three months of passing the basic certificate |
| Who asks for it | Most supplier questionnaires | Larger customers, and some public-sector and defence work |
Start with the basic certificate. Only go for Plus if a customer asks for it, or you want the reassurance of someone actually testing your setup.
The basic certificate fee is set by IASME and depends on the size of your organisation. At the time of writing it's £320 for micro organisations (up to 9 staff), £440 for small (10 to 49), £500 for medium (50 to 249) and £600 for large, all plus VAT (IASME). Cyber Essentials Plus is quoted by the certification body, because it involves an assessor's time and depends on how big your network is.
The fee is the cheap bit. The real cost is the work to get compliant: replacing unsupported machines, setting up two-factor login, sorting out admin accounts and putting updates on a proper footing. That's a one-off effort, then a bit of upkeep to stay compliant for the renewal.
Download the question set and go through it honestly with whoever looks after your systems. Make a list of every "no". Then fix them in this order: two-factor login on every cloud account, updates switched on everywhere, unsupported kit replaced or removed, and admin rights taken off everyday accounts. Only then apply.
Plenty of businesses do this themselves with a free afternoon and the question set, and that's a perfectly good way to go. But if the list of "no"s is long, it's rarely a Cyber Essentials problem. It's a sign nobody owns technology across the business, so the same gaps will be back by next year's renewal.
That's the gap we fill, so take this with a pinch of salt. Getting ready for Cyber Essentials, and staying ready, is part of how we look after servers and systems: patching on a schedule, access checked, and our own in-house scanning tools run against what we look after. We'd also recommend an independent penetration test once a year for most businesses, or every quarter if you hold a lot of sensitive data, and we'll help you choose a tester. The certification fee is paid direct to the certification body.
The assessment itself usually takes a few working days. The preparation is what takes time: a few days for a tidy small office, a few weeks if you need to replace old equipment or set up two-factor login across the business.
At the time of writing, the basic certificate costs £320 plus VAT for micro organisations (up to 9 staff), £440 for small (10 to 49), £500 for medium (50 to 249) and £600 for large. Cyber Essentials Plus is quoted separately by the certification body, because an assessor tests your systems.
Security updates. Critical and high-risk updates must be installed within 14 days, on every device and piece of software in scope. Missing two-factor login on cloud services and running unsupported software such as Windows 10 are close behind.
Cyber Essentials is a self-assessment questionnaire checked by an assessor. Cyber Essentials Plus covers the same controls, but an assessor also tests your systems directly, for example by scanning for vulnerabilities and checking a sample of devices. Plus comes after the basic certificate.
No. But many government contracts that handle personal data require it, and a growing number of private-sector customers ask for it from their suppliers.
How many people and devices you have, what cloud services you use, and whether a customer is asking for the certificate by a particular date.
What we will cover:
Rather talk now? Book a call or ring 01474 639 089.
We reply within one working day.