What Cyber Essentials actually is
Cyber Essentials is a government-backed certification scheme run through the National Cyber Security Centre. It exists for a straightforward reason: the majority of attacks against small businesses are not sophisticated, zero-day, nation-state operations — they are opportunistic, automated, and aimed at the same handful of basic weaknesses year after year. Cyber Essentials sets a baseline against exactly those common, internet-borne attacks.
It is deliberately a floor, not a ceiling. It does not certify that your security is excellent; it certifies that the fundamentals are in place. That is precisely why it is useful as a common standard — it is cheap to assess, consistent to interpret, and it rules out the most embarrassing failure modes. It is also increasingly a prerequisite: central government and many local-authority contracts require it, and an increasing number of insurers and prime contractors ask for it as part of supplier due diligence.
The five controls in plain English
The whole scheme rests on five technical controls. They sound obvious, and they are — but the number of businesses that cannot honestly evidence all five is striking.
Firewalls. Every device that connects to the internet sits behind a properly configured firewall, with default passwords changed, unnecessary services disabled, and rules documented. A consumer router with its default admin password does not count.
Secure configuration. Devices ship with defaults designed for convenience, not safety — guest accounts, sample data, open ports. Secure configuration means those defaults are removed or locked down on every device you actually use, and there is a record of it.
User access control. People do their day-to-day work with the least privilege they need — which means standard users are not local administrators, accounts are issued per person rather than shared, and unused accounts are removed promptly. The shared 'admin' password written on the server room whiteboard is exactly what this control exists to kill.
Malware protection. Anti-malware is present, running, and updating on every endpoint that could reasonably support it. The control is about coverage and currency, not a specific product — so whatever you run, it needs to be on everything and kept current.
Security update management. Software and operating systems are licensed, supported, and patched within a reasonable window of a release. This is the control that catches people out: an out-of-support operating system cannot pass, no matter how well the other four are done.
Cyber Essentials versus Cyber Essentials Plus
Cyber Essentials is a self-assessment. You answer a set of questions about your environment, signed off by a responsible person in the business, and a certifying body reviews the answers. It is inexpensive and fast, and it is the right starting point for most small businesses.
Cyber Essentials Plus adds an external assessment. An assessor runs a vulnerability scan against your public-facing services and, more importantly, performs a hands-on test on a sample of your workstations and servers — checking that the controls you claimed are actually in place and enforced. Plus is what larger contracts and more mature customers tend to ask for, because it verifies rather than simply takes your word. For most of our clients we start with the self-assessment to get the baseline right, then move to Plus once the environment will genuinely pass an external test.
What it actually takes to pass
Passing cleanly the first time is a matter of a handful of practical decisions. These are the things an assessor will look for, and the ones we most often find missing when a client comes to us having failed a self-assessment.
No local admin for daily use. Standard user accounts for everyday work, with a separate admin account used only when needed. This is the single most common gap, and the hardest to change culturally — people resist it until they have had a ransomware incident.
Supported, patched software. Every operating system and application still within vendor support. Windows 10 reached end of support in October 2025, so any remaining Windows 10 machine is an automatic fail. Third-party apps — browsers, PDF readers, Java — need patching too, not just Windows.
Enforced multi-factor authentication. MFA on every remotely accessible service that supports it, with a documented account-lockout policy where it does not. The scheme expects you to have thought about brute force, not just malware.
Documented firewall rules. A current list of what is allowed in and out, with a justification for each rule. The assessor does not need a fortress; they need evidence that the rules are deliberate rather than accumulated.
Controlled removable media and mobile devices. A policy on USB storage and on devices that connect to the network — auto-running disabled, malware scanning in place, and ideally restricted to approved devices. The point is that a stranger's USB stick does not get to run code on your estate by default.
Why we see it asked for more often
Procurement teams have worked out that Cyber Essentials is a cheap, standardised way to filter suppliers. If you cannot produce a current certificate, you often do not get past the first stage of a tender, regardless of how good your actual security is. Insurers have reached the same conclusion: a Cyber Essentials-certified business is statistically less likely to claim, and some policies now either require it or price without it at a premium.
There is also a governance variant, IASME Cyber Assurance, which goes a little further and includes elements of GDPR and risk management. For businesses that want a single certificate that covers more ground, it is worth considering alongside Cyber Essentials rather than instead of it.
How we help you through it
Our approach is to treat Cyber Essentials as a useful discipline rather than a paperwork exercise. We scope your environment against the five controls, identify the gaps honestly — and there are always some, even in well-run estates — then remediate them before you submit anything. We complete the self-assessment with you, hold the evidence so renewal is straightforward, and advise on whether Plus is worth pursuing for your specific contract pipeline.
Certification lasts twelve months and needs renewing annually. Because we hold the documentation and the baseline, renewal is usually a check that nothing has drifted rather than a fresh scramble. The real value is not the certificate; it is that the fundamentals it forces into place are the same fundamentals that stop the boring, common attacks from landing.