Cyber Essentials has quietly become the thing UK businesses are asked about rather than the thing they consider. Larger clients ask for it during procurement, insurers ask about it and the government's April 2026 open letter urged organisations to certify and to push it through their supply chains.
The good news is that it is achievable for a small business in a few weeks. Here is what it involves and where applications actually fail.
What it is
A government-backed scheme administered by IASME on behalf of the National Cyber Security Centre, covering five technical control areas. It is deliberately basic — the claim is that it addresses the commodity attacks that make up the overwhelming majority of incidents, not sophisticated targeted ones.
Two levels:
- Cyber Essentials — a self-assessment questionnaire, verified by an assessor.
- Cyber Essentials Plus — the same controls plus an independent technical audit, including vulnerability scanning and hands-on testing of a sample of devices.
Certification lasts twelve months. Fees are banded by organisation size and start at a few hundred pounds plus VAT for a micro business. Plus costs considerably more.
The five controls
1. Firewalls
Boundary firewalls between your network and the internet, configured to block unnecessary inbound connections, with default administrative passwords changed. Software firewalls enabled on devices used outside the office.
Straightforward for most businesses. The usual gap is home workers whose device firewalls have been switched off at some point.
2. Secure configuration
Remove or disable what you do not need. No default passwords anywhere. No unnecessary user accounts. Auto-run disabled.
The item most often missed is default credentials on network equipment — the router in the corner installed years ago, the network printer, the access point. Assessors ask specifically.
3. Security update management
Two requirements and they are strict.
Everything must be supported. No operating system or application past its end of support date. This is where most failures occur.
Critical and high-risk updates within 14 days. For operating systems, applications, firmware and browsers.
Fourteen days is tighter than most small businesses realise, and meeting it consistently needs managed patching rather than hoping people click the prompt.
4. User access control
Accounts created through an approved process, removed promptly when people leave, with only the access their role requires. Administrator accounts used only for administrative tasks — never for daily work such as email and browsing. Multi-factor authentication on all cloud services.
This is the second most common failure area, and the specific cause is usually administrator accounts being used for everyday work.
5. Malware protection
Anti-malware on all devices, kept updated, or application allow-listing. For most businesses this means Microsoft Defender properly configured, which is included and adequate.
The five reasons applications fail
In rough order of frequency:
- Unsupported software still in use. An old operating system on one machine, an out-of-support server, an application whose vendor stopped issuing updates. One device fails the whole application.
- Multi-factor authentication gaps. Enabled for most people but not for the director, the shared account or the service account.
- Patching outside 14 days. Especially for third-party applications and firmware, which nobody was tracking.
- Administrator accounts used daily. The person who set everything up works from an admin account because it is convenient.
- Personal devices with no controls. Staff reading work email on unmanaged phones, which is in scope and needs device management.
Every one of those five is findable in an afternoon before you apply. Applications fail because businesses submit first and audit afterwards.
How to get there in four weeks
Week 1 — inventory. Every device, every operating system version, every cloud service, every account. You cannot pass without knowing what you have, and the inventory itself usually surfaces two or three problems.
Week 2 — the obvious gaps. Replace or isolate unsupported systems. Turn on multi-factor authentication everywhere without exception. Separate administrator accounts from daily-use ones.
Week 3 — patching and configuration. Get automated patching running against the 14-day requirement. Change default credentials on network equipment. Bring personal devices under management.
Week 4 — the questionnaire. Answer honestly. Assessors are generally helpful about clarifications, and an honest answer that needs remediation is far better than an optimistic one that fails.
If you are on Microsoft 365
Business Premium covers most of the technical requirements comfortably — Intune for device management, conditional access and multi-factor authentication through Entra ID, Defender for malware protection, and automated patching through Intune policies.
That is a substantial part of why Premium is worth the step for businesses that need certification, as set out in the Business Premium article. The licence is frequently already there and unconfigured.
Should you get Plus?
If clients ask specifically, yes. If you are pursuing government work involving personal data, likely yes. Otherwise start with the base certification and consider Plus at renewal.
The base certification is a genuine improvement in security posture. Plus is the same posture with independent verification, which is a commercial benefit rather than a security one.
What it is not
Cyber Essentials is a baseline, not a security strategy. It says nothing about backup, incident response, staff training or supplier risk — all of which matter more than some of what it does cover.
Treat it as the floor. It is a good floor and it is the one your clients are increasingly asking about.
Our security solutions team takes UK businesses through Cyber Essentials from gap analysis to certification, and the gap analysis alone is worth doing whether or not you go on to certify. Get in touch.








