01
What it is, and what it isn't
Cyber Essentials is a self-assessment questionnaire, reviewed by a certifying body, covering five control areas. Cyber Essentials Plus is the same scope with a technical audit: someone independently checks that what you said is true.
It's worth being clear about the limits. Certification says your basic controls are in place on the day you were assessed. It doesn't mean you're secure, and it doesn't replace backup testing, staff awareness or an incident plan. What it does do is give you a defensible answer when a client, insurer or funder asks how you manage security.
If tenders, grant applications or insurance renewals have started asking security questions, certification usually pays for itself in avoided back-and-forth.
02
The five control areas
Boundary firewalls and internet gateways
Something sits between your network and the internet, it's configured deliberately, and default passwords have been changed. Home workers count, which surprises people.
Secure configuration
Devices and services are set up with unnecessary features off and default accounts removed. In practice this is mostly about not leaving things as they came out of the box.
User access control
People have their own accounts, administrator rights are limited and justified, multi-factor authentication is on for cloud services, and leavers lose access promptly. This is where most organisations have work to do.
Malware protection
Every device has protection that updates itself. The built-in tooling in modern Windows and macOS is usually acceptable, properly configured.
Security update management
Supported software, with high-risk updates applied within fourteen days. This is the control that most often fails, and almost always because of one forgotten machine or an application nobody patches.
03
What trips organisations up
- Unsupported operating systems still in use, often on one machine attached to a piece of equipment.
- Personal devices used for work email without being in scope or managed.
- Administrator rights handed out broadly, with no record of who has them.
- MFA missing on one service - the finance system, or the old webmail nobody retired.
- Patching that happens but isn't evidenced, so you can't show the fourteen-day window is met.
- Scope drawn too widely or too vaguely at the start, which makes everything harder.
Agree the scope before you answer a single question. "The whole organisation" is the cleanest answer, but only if you know what that includes.
04
How long it takes and what it costs in effort
For an organisation with reasonable foundations, the questionnaire is a day's work and certification follows within a week or two. For an organisation starting cold, expect six to twelve weeks - not because the paperwork is slow, but because you'll find genuine gaps that need fixing first.
- Weeks one and two: define scope, list every device and service, identify obvious gaps.
- Weeks three to eight: remediation - MFA, admin rights, unsupported machines, patching evidence.
- Week nine: complete the questionnaire with evidence to hand.
- Week ten onwards: submission, any queries, then certification.
- If you're going for Plus, allow additional time for the technical audit and remediation of anything it finds.
Certification lasts twelve months. Treat the annual renewal as a scheduled check rather than a scramble, and it stays a half-day exercise.
05
Is it worth doing?
It's clearly worth it if clients ask for it, if you bid for public sector work, or if your insurer offers better terms with it. It's also worth it as a structure - it gives an organisation with no security plan a sensible, finite list of things to do.
It's less useful if you're already mature and nobody's asking, or if it would become a paper exercise that distracts from bigger risks like untested backups. Certification is a floor, not a finish line.