Compliance

Cyber Essentials Certification Support for UK Businesses

The UK baseline that most customers, insurers and public sector buyers now ask for. We get you from "we probably fail" to certified, and fix the underlying issues rather than coaching you through the answers.

SCHEME OWNER
IASME, on behalf of NCSC
CONTROLS
Five Technical Control Themes
ASSESSMENT
Verified Self-Assessment Questionnaire
VALIDITY
Annual Renewal
In short

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme, delivered by IASME on behalf of the NCSC, that verifies an organisation has five fundamental technical controls in place: boundary firewalls, secure configuration, security update management, user access control and malware protection. Certification is renewed annually.

The five controls, in plain English

Cyber Essentials asks about five things. Firewalls: every device must sit behind a properly configured boundary firewall, or have a software firewall enabled, with no unnecessary services exposed to the internet. Secure configuration: default passwords changed, unnecessary software and accounts removed, auto-run disabled.

Security update management: everything must be supported by its vendor and patched within fourteen days for high-severity or critical fixes — this is the control that most often causes a failure, usually because of an unsupported operating system or an old phone still in use. User access control: individual accounts, administrative privileges granted only where needed and used only for administrative work, MFA on cloud services. Malware protection: anti-malware, application allow-listing or sandboxing on all in-scope devices.

  • Firewalls — boundary and host-based, with no unnecessary internet-facing services
  • Secure configuration — no default credentials, minimal installed software
  • Security update management — supported software, critical patches within 14 days
  • User access control — individual accounts, least privilege, MFA on cloud services
  • Malware protection — anti-malware or allow-listing on every in-scope device

Why businesses fail, and how we avoid it

The most common causes of failure are entirely predictable. An unsupported operating system somewhere in the estate — often one machine driving a piece of equipment. Mobile phones running Android or iOS versions no longer receiving security updates, which are in scope if they access organisational data. Multi-factor authentication missing on a cloud service. Everyday accounts holding local administrator rights. Routers still on default credentials.

We find those first. The gap review deliberately runs before you engage a certification body, because discovering an unsupported server halfway through an assessment is expensive and delays certification by weeks. Fix first, then apply.

  • Unsupported operating systems still in the scope boundary
  • Staff mobile devices past their vendor security update window
  • Cloud services without MFA enforced
  • Day-to-day accounts with local administrator rights
  • Network equipment on default or shared credentials
  • Home working devices nobody has considered

Getting the scope right

Scope is the most consequential decision in a Cyber Essentials application, and the one people get wrong. The default expectation is whole-organisation certification, covering every device and cloud service used for organisational work — including staff-owned phones that access work email, and home routers where people work remotely.

A narrower sub-scope is possible where a segregated part of the business can be properly separated, but it must be genuinely separated by network controls, not merely described that way. And a narrow certificate is worth less commercially: customers reading it will see what it excludes. We advise on the trade-off rather than defaulting to the cheapest route.

What certification is actually worth

Cyber Essentials is required for many central government contracts involving sensitive or personal information, and it is increasingly asked for by large private-sector customers running supplier due diligence. It frequently replaces a bespoke security questionnaire, which is a real saving of management time.

It also matters to insurers, and it is genuinely useful as a baseline — the five controls, properly implemented, block a large share of commodity attacks. What it is not is a comprehensive security programme. It says nothing about backups, staff training, incident response or supplier risk. Treat it as the floor.

  • Required for many UK central government and MOD contracts
  • Frequently accepted in place of a bespoke customer security questionnaire
  • Commonly requested by cyber insurers at application or renewal
  • Provides a demonstrable baseline for client and tender due diligence
What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Agreement Ready

Master Services Agreement (MSA)

The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.

UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified

Request This Agreement →
Frequently asked questions

Cyber Essentials — your questions answered

How much does Cyber Essentials cost?
The certification fee is set by IASME and banded by organisation size, payable to the certification body. Our preparation work is quoted separately and fixed in advance. We confirm both figures in writing before you commit, so there are no surprises.
How long does Cyber Essentials certification take?
For a well-prepared organisation the questionnaire itself is assessed within days. Realistically, allow two to six weeks end to end for a first certification, with most of that spent fixing the issues found in the gap review.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit by an assessor, including vulnerability scanning and testing of a sample of your devices. You must hold Cyber Essentials before taking Plus.
Do staff mobile phones count for Cyber Essentials?
Yes. Any device accessing organisational data or services is in scope, including personally owned phones used for work email. They must be running a vendor-supported version receiving security updates.
How often does Cyber Essentials need renewing?
Annually. The requirements are updated periodically by IASME, so a renewal is not simply a resubmission of last year's answers — we keep clients current between cycles so renewal stays straightforward.
Do we need Cyber Essentials to win government contracts?
It is a requirement for many UK central government contracts that involve handling sensitive or personal information, or providing certain technical products and services. Check the specific tender requirements, as thresholds vary by department.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about cyber essentials?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.