Cyber Essentials: What UK Small Businesses Actually Need to Do
Cyber Essentials is five technical controls and one badly understood scoping decision. Here is what each control actually requires, and the handful of issues that cause most first-time failures.
What are the five Cyber Essentials controls?
Boundary firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. All five must be in place across everything in scope, and the certification is renewed annually through an IASME-accredited certification body.
Cyber Essentials is a UK government-backed scheme run by IASME on behalf of the NCSC.
It certifies that an organisation has five fundamental technical controls in place. It is not a
comprehensive security programme, and anyone selling it as one is overselling. It is a floor — and
a floor that is now required for many government contracts and asked for by a growing number of
private customers and insurers.
The five controls, plainly
1. Firewalls
Every in-scope device must sit behind a properly configured boundary firewall or have a host firewall
enabled. Nothing should be exposed to the internet without a documented business need, and default
administrative passwords on the firewall itself must be changed.
2. Secure configuration
Default passwords changed, unnecessary software and user accounts removed, auto-run disabled, and
devices configured to reduce the attack surface rather than left as they came out of the box.
3. Security update management
Everything must be supported by its vendor and receiving security updates, with high-severity and
critical updates applied within fourteen days of release. This is the control that fails people.
4. User access control
Individual accounts for each user, administrative privileges granted only where genuinely needed and
used only for administrative tasks, and multi-factor authentication on cloud services.
5. Malware protection
Anti-malware software, application allow-listing, or sandboxing on every in-scope device, kept
current.
The scoping decision nobody thinks about hard enough
Scope is the most consequential choice in a Cyber Essentials application. The default expectation is
whole-organisation certification: every device and cloud service used for organisational work. That
includes personally owned phones if they access work email, and home routers where staff work
remotely.
A narrower sub-scope is possible, but only where the excluded part of the business is genuinely
separated by network controls — not merely described as separate. And a narrow certificate is worth
less commercially, because the customer reading it can see what it excludes.
Why businesses fail
The failures are predictable and almost always the same handful of issues:
- An unsupported operating system somewhere in the estate, often driving a specific piece of equipment
- Staff mobile phones running Android or iOS versions past their vendor security update window
- Multi-factor authentication missing on one cloud service everyone forgot about
- Everyday user accounts holding local administrator rights
- Network equipment still on default or shared credentials
- Home working devices that nobody included in the scope conversation
Every one of those is findable in advance. That is the entire argument for running a gap review
before you engage a certification body — discovering an unsupported server halfway through an
assessment costs weeks.
Cyber Essentials or Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus covers the same
five controls but adds a hands-on technical audit: an assessor runs authenticated vulnerability
scans against a sample of your devices, tests that malware protection actually blocks test files,
and verifies account separation and MFA directly.
Plus must be completed within three months of your Cyber Essentials certificate. Miss that window
and you recertify at the basic level first, which costs time and money for no benefit.
If a customer requires Plus, get Plus — it carries materially more weight precisely because it is
independently verified. If nobody is asking for it, basic Cyber Essentials plus a vulnerability
assessment usually delivers more security per pound.
What it is worth
Cyber Essentials is required for many UK central government contracts involving sensitive or
personal information. It is increasingly requested in private-sector supplier due diligence, where it
frequently replaces a bespoke security questionnaire — which is a real saving in management time. And
insurers ask about it.
What it does not cover is worth stating: backups, staff training, incident response, supplier risk,
data protection. None of the five controls mention any of them. Treat certification as evidence of a
baseline, not as the destination.