All guides

Cyber Essentials, explained

Cyber Essentials is a UK government-backed scheme covering five areas of basic technical security. It isn't a deep audit and it won't stop a determined attacker, but it does confirm you've closed the doors most attacks walk through - and increasingly, someone will ask you for it. This guide explains what's involved without the compliance language.

Security11 min readUpdated 30 July 2026

Who this is for

Organisations being asked about certification by clients, funders or insurers, and anyone using it as a structure for getting the basics right.

01

What it is, and what it isn't

Cyber Essentials is a self-assessment questionnaire, reviewed by a certifying body, covering five control areas. Cyber Essentials Plus is the same scope with a technical audit: someone independently checks that what you said is true.

It's worth being clear about the limits. Certification says your basic controls are in place on the day you were assessed. It doesn't mean you're secure, and it doesn't replace backup testing, staff awareness or an incident plan. What it does do is give you a defensible answer when a client, insurer or funder asks how you manage security.

If tenders, grant applications or insurance renewals have started asking security questions, certification usually pays for itself in avoided back-and-forth.

02

The five control areas

Boundary firewalls and internet gateways

Something sits between your network and the internet, it's configured deliberately, and default passwords have been changed. Home workers count, which surprises people.

Secure configuration

Devices and services are set up with unnecessary features off and default accounts removed. In practice this is mostly about not leaving things as they came out of the box.

User access control

People have their own accounts, administrator rights are limited and justified, multi-factor authentication is on for cloud services, and leavers lose access promptly. This is where most organisations have work to do.

Malware protection

Every device has protection that updates itself. The built-in tooling in modern Windows and macOS is usually acceptable, properly configured.

Security update management

Supported software, with high-risk updates applied within fourteen days. This is the control that most often fails, and almost always because of one forgotten machine or an application nobody patches.

03

What trips organisations up

  • Unsupported operating systems still in use, often on one machine attached to a piece of equipment.
  • Personal devices used for work email without being in scope or managed.
  • Administrator rights handed out broadly, with no record of who has them.
  • MFA missing on one service - the finance system, or the old webmail nobody retired.
  • Patching that happens but isn't evidenced, so you can't show the fourteen-day window is met.
  • Scope drawn too widely or too vaguely at the start, which makes everything harder.

Agree the scope before you answer a single question. "The whole organisation" is the cleanest answer, but only if you know what that includes.

04

How long it takes and what it costs in effort

For an organisation with reasonable foundations, the questionnaire is a day's work and certification follows within a week or two. For an organisation starting cold, expect six to twelve weeks - not because the paperwork is slow, but because you'll find genuine gaps that need fixing first.

  • Weeks one and two: define scope, list every device and service, identify obvious gaps.
  • Weeks three to eight: remediation - MFA, admin rights, unsupported machines, patching evidence.
  • Week nine: complete the questionnaire with evidence to hand.
  • Week ten onwards: submission, any queries, then certification.
  • If you're going for Plus, allow additional time for the technical audit and remediation of anything it finds.

Certification lasts twelve months. Treat the annual renewal as a scheduled check rather than a scramble, and it stays a half-day exercise.

05

Is it worth doing?

It's clearly worth it if clients ask for it, if you bid for public sector work, or if your insurer offers better terms with it. It's also worth it as a structure - it gives an organisation with no security plan a sensible, finite list of things to do.

It's less useful if you're already mature and nobody's asking, or if it would become a paper exercise that distracts from bigger risks like untested backups. Certification is a floor, not a finish line.

The short checklist

  • Decide the scope before answering anything.
  • List every device, including home workers' and shared machines.
  • Find anything running unsupported software and plan to retire it.
  • Turn MFA on for every cloud service, without exceptions.
  • Record who has administrator rights and why.
  • Be able to evidence that updates land within fourteen days.
  • Confirm leavers lose access promptly and you can show it.
  • Diary the renewal eleven months out.

Want a second opinion on where you've got to?

Get an IT health check that reviews your support, security and Microsoft setup, then gives you a short, prioritised list of what's worth doing.