Cyber Essentials is a UK government-backed certification that proves your business has five basic technical controls in place to stop the most common cyber attacks. It’s run by the National Cyber Security Centre (NCSC) and delivered on their behalf by the IASME Consortium. For a small business or sole trader, it’s usually the single most cost-effective way to win client trust, qualify for government contracts, and cut your real-world risk of a breach.
What Is Cyber Essentials (And Why Does Your Small Business Need It?)
Cyber Essentials certifies that your business meets five baseline security controls, verified through a self-assessment questionnaire (SAQ) that’s reviewed by an independent assessor. The NCSC estimates that these five controls alone can block the large majority of common cyber attacks — things like phishing, password guessing, and unpatched software exploits, which is how most small businesses actually get hit.
You don’t need a server room or an IT manager to qualify. The questionnaire is the same whether you’re a 400-person company or a sole trader working from a laptop; only the price changes.
Government Tenders, Supply Chains, and Client Expectations
Since February 2025, Procurement Policy Note 014 (PPN 014) has made Cyber Essentials or Cyber Essentials Plus a binding requirement for many central government contracts involving personal data or certain IT services. That requirement cascades down supply chains too — so if you’re a subcontractor to a company bidding on government work, you may need certification even without a direct government contract. It’s also increasingly common as a baseline expectation from private-sector clients doing their own supplier due diligence, and it’s a stated requirement across most G-Cloud procurement.
If cyber compliance is a new area for your business, it’s worth reading up on the wider legal requirements UK small businesses need to meet before you start scoping your assessment.
Free Cyber Liability Insurance for Small UK Businesses
Certify your whole organisation, and if you’re a UK-domiciled business with turnover under £20 million, IASME bundles in £25,000 of cyber liability insurance at no extra cost. It’s a genuinely useful benefit for a micro business that couldn’t otherwise justify a standalone cyber policy. It’s worth checking how this sits alongside your existing business insurance UK small business owners typically need, since it won’t replace broader cover.
Cyber Essentials vs. Cyber Essentials Plus: Key Differences
Cyber Essentials is a self-assessment, verified by a reviewer. Cyber Essentials Plus adds an independent technical audit — vulnerability scans and hands-on testing of a sample of your devices — to confirm the controls genuinely work, not just that you’ve said they do.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assessment type | Self-assessment questionnaire, reviewed by an assessor | Self-assessment plus independent technical audit |
| Testing | None — answers are checked, not tested | External vulnerability scans and internal device sampling |
| Typical cost (2026) | £320–£600 + VAT (IASME fee) | Set independently by the certification body, commonly £1,500+ |
| Prerequisite | None | Must hold a valid Cyber Essentials certificate first |
| Best for | Most small businesses and first-time applicants | Businesses needing higher assurance, or where a client/contract requires it |
Cyber Essentials (Verified Self-Assessment)
This is where nearly every small business starts. You complete the questionnaire, a qualified assessor reviews your answers, and you get a pass/fail verdict — with one free resubmission if you fail, usually within 48 hours of the result.
Cyber Essentials Plus (The Technical Audit)
Plus is a genuine hands-on test. An assessor scans your external-facing systems and checks a sample of your devices to confirm the controls actually work day to day, not just on paper. Some clients and tenders specifically require Plus rather than the base certificate, so it’s worth checking your contract terms before you assume the basic level is enough.
The 5 Core Technical Controls of Cyber Essentials Explained
The five controls, in short:
- Firewalls and routers — control what traffic can reach your network and devices.
- Secure configuration — remove default passwords and unnecessary software or accounts.
- User access control — give people the minimum access they need, with multi-factor authentication (MFA) on accounts.
- Malware protection — anti-malware software or app-store-only restrictions on every device.
- Security update management — apply patches quickly, especially critical and high-severity ones.
1. Firewalls and Routers (Securing Your Network Boundary)
Every device connecting to the internet needs a properly configured boundary firewall — that includes the router your ISP gave you for a home office, not just an office-grade appliance. Default admin passwords have to be changed, and any rules that aren’t needed should be removed.
2. Secure Configuration (Hardening System Settings)
This covers turning off features you don’t use, removing unused accounts, and making sure devices aren’t shipped or left running on manufacturer defaults. A brand-new laptop straight out of the box will usually fail this control until it’s set up properly.
3. User Access Control (Principle of Least Privilege and MFA)
Nobody should have administrator rights unless their job genuinely requires it, and every account — email, cloud storage, accounting software — needs multi-factor authentication switched on wherever it’s offered. If you haven’t set this up yet, our guide to two-factor authentication for UK small businesses is a good place to start, since this is now one of the most common reasons businesses fail.
4. Malware Protection (Defending Endpoints)
Every device in scope needs anti-malware software, application allow-listing, or a locked-down app-store-only configuration (common on tablets and phones). If you’re not sure what to run, see our roundup of the best antivirus software for UK small businesses for options that satisfy this control without a big budget.
5. Security Update Management (The 14-Day Patching Window)
This is the control that trips up more businesses than any other. Critical and high-severity security updates must be applied within 14 days of release — not “when convenient.” Under the scheme’s newest question set, missing this deadline on even one in-scope device is now grounds for automatic failure. Set your devices to auto-update wherever possible; manual patching is the most common way small teams fall behind without noticing.
Navigating Special Cases: Single-Person & Micro-Businesses
If you’re a sole trader or a two-person team working from home, the scope question is usually the hardest part — not the technical controls themselves.
Deciding What Devices and Cloud Services Are “In Scope”
Scope includes anything that can access your business data or accounts: your laptop, your phone if it has business email on it, and every cloud service you use for work, including Microsoft 365, Google Workspace, your accounting software, and your CRM. If you’re weighing up your cloud setup before you assess, it’s worth reviewing how Microsoft 365 Copilot pricing fits your business, since every cloud tool you add needs to meet the same MFA and configuration standards.
Handling Home Networks and Personal Devices (BYOD)
You don’t need to certify your entire home network — only the business data and devices on it. A shared family laptop that occasionally opens work email still counts as in scope, though, so many sole traders find it simpler to keep a dedicated device for business use rather than trying to draw a line through a shared one. Our guide to setting up a productive UK small business home office covers some practical ways to separate business and personal use without extra hardware costs.
What Does Cyber Essentials Cost? (IASME Price Structure)
Tiered Pricing by Organisation Headcount
IASME sets the Cyber Essentials assessment fee centrally, based on employee headcount, exclusive of VAT:
| Organisation size | Employees | Cyber Essentials fee |
|---|---|---|
| Micro | 0–9 | £320 + VAT |
| Small | 10–49 | £440 + VAT |
| Medium | 50–249 | £500 + VAT |
| Large | 250+ | £600 + VAT |
Most sole traders and small businesses fall into the micro band. Individual certification bodies can add a small premium on top of the IASME fee, so it’s worth comparing two or three quotes — the certificate itself is identical regardless of which body issues it.
Hidden Costs and Cyber Essentials Plus Pricing
The IASME fee is only part of the real spend. Budget time (or a consultant’s fee) for closing any gaps the assessment reveals — MFA rollout, patch management, or removing old local admin accounts are the most common fixes needed before submission. Cyber Essentials Plus isn’t priced by IASME at all; each certification body quotes independently based on your device count and complexity, and Plus always requires a valid base certificate first.
Step-by-Step Process to Achieve Certification
- Define your scope and audit your assets. List every device, cloud service, and network that touches business data, including home routers and BYOD phones.
- Implement the controls. Close any gaps — enable MFA everywhere, patch outstanding updates, remove default passwords, and check malware protection is active on every device.
- Choose an IASME-licensed certification body. Any licensed body issues the same NCSC-backed certificate; compare their fees, turnaround time, and whether they offer pre-assessment support.
- Submit the self-assessment questionnaire. Answer honestly rather than aspirationally — assessors are trained to spot answers that don’t match a business’s actual setup, and inconsistent answers are a common cause of failure.
The Update: Willow to Danzell, and What Changed
From 27 April 2026, IASME replaced the “Willow” question set with a new version called “Danzell,” alongside an updated Requirements for IT Infrastructure document (version 3.3). The five controls themselves haven’t changed — but enforcement has got noticeably stricter, and this is the update most existing guides haven’t caught up with yet.
Two changes matter most for small businesses:
- MFA is now an automatic fail if missing. If a cloud service offers multi-factor authentication and you haven’t turned it on, the assessment fails outright rather than costing you points.
- The 14-day patch rule is now an automatic fail too. Missing a critical or high-severity update past the 14-day window on even one in-scope device can fail the whole assessment, not just flag a weakness.
If you already hold a certificate assessed under Willow, it stays valid until its normal expiry. Accounts opened before the cutoff had until 26 October 2026 to finish under the old rules; anything started after that uses Danzell. If you’re certifying for the first time now, prepare against Danzell and version 3.3 — don’t rely on older blog posts or checklists still describing Willow.
Common Mistakes That Cause Businesses to Fail
- Assuming home Wi-Fi routers don’t count. They’re boundary firewalls under the scheme and need the same default-password and configuration checks as office kit.
- Leaving one device unpatched. Under Danzell, a single device missing a critical update outside the 14-day window is enough to fail the whole assessment.
- Forgetting cloud services in scope. Accounting software, CRMs, and file storage all need MFA enabled — not just your email.
- Answering the questionnaire optimistically. Assessors cross-check answers against each other; inconsistencies between what you claim and what you actually run are one of the most common reasons for a first-attempt failure.
Frequently Asked Questions
How long does the certification last?
Cyber Essentials certification is valid for 12 months from the date you pass. You need to recertify annually, answering the full questionnaire again rather than just confirming nothing has changed.
What happens if my business fails the assessment?
You get one free resubmission, typically within 48 hours of the result, to correct the specific answers that caused the failure. If you don’t pass within that window, you’ll need to pay again to restart the process.
How do the latest IASME updates impact small businesses?
The move to the Danzell question set in April 2026 made MFA and 14-day patching automatic-fail criteria rather than just scored weaknesses. Small businesses relying on manual updates or partial MFA rollout are most exposed to failing under the new rules.
Can a sole trader get Cyber Essentials certified?
Yes. The scheme applies to organisations of any size, including sole traders. The main practical challenge is scoping — working out which parts of a shared home network and personal devices count as in scope for business use.
Do small businesses actually need Cyber Essentials?
It’s not legally required for most businesses, but it’s increasingly expected by clients, insurers, and government procurement, and the five controls address the attack methods small businesses are most commonly hit by.

