Cyber Essentials: What UK Small Businesses Actually Need to Do

Cyber Essentials is five technical controls and one badly understood scoping decision. Here is what each control actually requires, and the handful of issues that cause most first-time failures.

In short

What are the five Cyber Essentials controls?

Boundary firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. All five must be in place across everything in scope, and the certification is renewed annually through an IASME-accredited certification body.

Cyber Essentials is a UK government-backed scheme run by IASME on behalf of the NCSC.

It certifies that an organisation has five fundamental technical controls in place. It is not a

comprehensive security programme, and anyone selling it as one is overselling. It is a floor — and

a floor that is now required for many government contracts and asked for by a growing number of

private customers and insurers.

The five controls, plainly

1. Firewalls

Every in-scope device must sit behind a properly configured boundary firewall or have a host firewall

enabled. Nothing should be exposed to the internet without a documented business need, and default

administrative passwords on the firewall itself must be changed.

2. Secure configuration

Default passwords changed, unnecessary software and user accounts removed, auto-run disabled, and

devices configured to reduce the attack surface rather than left as they came out of the box.

3. Security update management

Everything must be supported by its vendor and receiving security updates, with high-severity and

critical updates applied within fourteen days of release. This is the control that fails people.

4. User access control

Individual accounts for each user, administrative privileges granted only where genuinely needed and

used only for administrative tasks, and multi-factor authentication on cloud services.

5. Malware protection

Anti-malware software, application allow-listing, or sandboxing on every in-scope device, kept

current.

The scoping decision nobody thinks about hard enough

Scope is the most consequential choice in a Cyber Essentials application. The default expectation is

whole-organisation certification: every device and cloud service used for organisational work. That

includes personally owned phones if they access work email, and home routers where staff work

remotely.

A narrower sub-scope is possible, but only where the excluded part of the business is genuinely

separated by network controls — not merely described as separate. And a narrow certificate is worth

less commercially, because the customer reading it can see what it excludes.

Why businesses fail

The failures are predictable and almost always the same handful of issues:

  • An unsupported operating system somewhere in the estate, often driving a specific piece of equipment
  • Staff mobile phones running Android or iOS versions past their vendor security update window
  • Multi-factor authentication missing on one cloud service everyone forgot about
  • Everyday user accounts holding local administrator rights
  • Network equipment still on default or shared credentials
  • Home working devices that nobody included in the scope conversation

Every one of those is findable in advance. That is the entire argument for running a gap review

before you engage a certification body — discovering an unsupported server halfway through an

assessment costs weeks.

Cyber Essentials or Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus covers the same

five controls but adds a hands-on technical audit: an assessor runs authenticated vulnerability

scans against a sample of your devices, tests that malware protection actually blocks test files,

and verifies account separation and MFA directly.

Plus must be completed within three months of your Cyber Essentials certificate. Miss that window

and you recertify at the basic level first, which costs time and money for no benefit.

If a customer requires Plus, get Plus — it carries materially more weight precisely because it is
independently verified. If nobody is asking for it, basic Cyber Essentials plus a vulnerability
assessment usually delivers more security per pound.

What it is worth

Cyber Essentials is required for many UK central government contracts involving sensitive or

personal information. It is increasingly requested in private-sector supplier due diligence, where it

frequently replaces a bespoke security questionnaire — which is a real saving in management time. And

insurers ask about it.

What it does not cover is worth stating: backups, staff training, incident response, supplier risk,

data protection. None of the five controls mention any of them. Treat certification as evidence of a

baseline, not as the destination.

Written by Cipher Knights Security Team , Security Consultant at CIPHER KNIGHTS LTD (company number 16141995), Leicester, United Kingdom. General guidance rather than advice for your specific circumstances — call +44 7424 967568 to discuss your own situation.