Cyber Essentials: what it is and how to prepare
Cyber Essentials comes up more and more often in tenders, insurance forms, and client onboarding. If you have been asked whether you hold it and were not quite sure what it involved, this guide covers what the scheme is, the two levels, the five technical controls it checks, and a realistic view of what preparing for it takes.
Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre. It sets out a baseline of security controls that protect against the most common internet-based attacks, the kind that are opportunistic rather than highly targeted. The idea is deliberately practical: get the basics right and you shut the door on the large majority of everyday threats.
The two levels
There are two tiers, and it helps to know which one a client is actually asking for.
- Cyber Essentials: a self-assessment questionnaire that your organisation completes and a senior person signs off, then an accredited certification body reviews. It confirms you have the five core controls in place.
- Cyber Essentials Plus: covers the same five controls, but an external assessor independently tests and verifies them through a hands-on technical audit. It carries more weight because it is checked rather than declared.
Which do you need?
Many contracts accept the base Cyber Essentials level. Some public sector and larger private contracts specifically require Cyber Essentials Plus. Always check the exact wording of the requirement before you plan, because the effort and cost differ.
The five technical controls
Both levels assess the same five areas. None of them are exotic. They are the foundations any well-run IT environment should already have.
- Firewalls: your networks and devices are protected from untrusted networks by properly configured firewalls.
- Secure configuration: devices and software are set up to reduce vulnerabilities, with unnecessary features and default passwords removed.
- Security update management: operating systems and software are kept up to date and unsupported products are removed.
- User access control: accounts are given only the access each person needs, with administrator rights tightly controlled.
- Malware protection: devices are protected against malware through anti-malware software, allow-listing, or sandboxing.
Why it is worth having
Beyond the security benefit, which is real, Cyber Essentials increasingly acts as a commercial key. It is mandatory for certain UK government contracts that involve handling sensitive information. Many private clients now ask for it during procurement. Some cyber insurance policies offer better terms, or only offer cover at all, when it is in place. And it gives a short, credible answer to a whole section of the security questionnaires covered in our companion guide.
How to prepare
Preparation is mostly about closing the gap between where your environment is now and what the five controls require. A sensible sequence looks like this:
- Run a gap assessment against the five controls so you know exactly what needs to change.
- Enforce MFA, remove local administrator rights where they are not needed, and confirm every device is encrypted and patched.
- Retire any unsupported operating systems or software, which is one of the most common reasons for failure.
- Document your configuration so the answers are consistent and evidenced.
- For Cyber Essentials Plus, run a dry technical check before the assessor does, so there are no surprises on the day.
The usual reasons businesses fail
Unsupported software still in use, an old device that never got patched, and local administrator rights handed out too freely. All three are avoidable with a proper gap assessment before you apply.
The scheme is designed to be achievable for small businesses, and most well-managed environments are closer than they expect. The work is in the preparation, not the certificate itself. If you would like a clear picture of where you stand before committing, our security service includes Cyber Essentials readiness, and our free Microsoft 365 security assessment is a fast way to surface the obvious gaps.