Back to Articles

Cyber Essentials Certification: A UK Business Step-by-Step Guide to Passing First Time in 2026

Cyber Essentials Certification: A UK Business Step-by-Step Guide to Passing First Time in 2026

Cyber Essentials certification has quietly become a commercial requirement rather than a security badge. It is mandatory for most central government contracts involving personal data, it appears in an increasing share of private-sector procurement questionnaires, and it is now routinely demanded by larger customers of their suppliers — which means a UK business can find itself excluded from a tender not because its security is poor but because it has never formally evidenced it. The scheme is government-backed, delivered by the IASME Consortium on behalf of the NCSC, and it is achievable for a well-run small business inside a fortnight.

This guide leads with what the certification actually covers, because a large share of first-time failures come from businesses answering questions about a scope they never properly defined. From there it works through the five technical controls in the detail the assessor expects, the self-assessment questionnaire process end to end, the specific reasons applications fail on the first submission, and the decision about whether and when to step up to Cyber Essentials Plus. It is written for the owner, operations lead or IT manager who has been handed a procurement deadline and needs to know exactly what is required, what it costs, and how long it takes.

What is Cyber Essentials, and what does it actually cover?

Cyber Essentials is a UK government-backed certification scheme that verifies an organisation has five specific technical controls in place. It was created by the National Cyber Security Centre and has been delivered since April 2020 by the IASME Consortium, the sole Cyber Essentials Partner, working through a network of accredited Certification Bodies. The premise is deliberately narrow: the five controls address the commodity, untargeted attacks that make up the overwhelming majority of incidents affecting UK small businesses — the opportunistic scanning, the phishing that lands on an unpatched laptop, the credential stuffing against a cloud account with no second factor.

It is important to be clear about what the scheme is not. Cyber Essentials is not a risk assessment, not an information security management system, and not a substitute for ISO 27001. It does not examine your policies, your staff training, your supplier management or your incident response plan. It asks whether five specific technical controls are correctly implemented across everything in scope, and it certifies for twelve months. That narrowness is the point: it produces a consistent, verifiable baseline that a procurement team can rely on without commissioning an audit, which is precisely why it has spread through UK supply chains so quickly.

There are two levels. Cyber Essentials is a self-assessment: you complete a question set in the IASME portal, a senior person at board level or equivalent signs it off, and a Certification Body assessor marks it. Cyber Essentials Plus covers the same five controls and the same scope, but adds a hands-on technical audit — an assessor tests a sample of your devices and cloud services rather than taking your word for it. Plus cannot be taken on its own; it must be completed within three months of passing the self-assessment, and the scope of the two must match.

Pro Tip

Before you touch the question set, write down your scope in one paragraph: which legal entity, which locations, which devices including home and personal ones used for work, and which cloud services. Roughly half the remedial work in a failed first submission traces back to a scope that was never defined in writing, and the question set gives you nowhere to hide it — every answer has to be true for everything in scope.

Cyber Essentials in numbers — the UK picture

The figures below give a sense of the scheme’s scale and the practical parameters that shape a certification project. Fee figures are the published IASME tiers exclusive of VAT and are reviewed periodically, so confirm the current rate with your Certification Body before budgeting.

5
Technical controls covering firewalls, configuration, updates, access and malware
14 days
Maximum window to apply high-severity and critical security updates
£320
Published fee for a micro organisation of 0–9 people, excluding VAT
12 months
Certificate validity before recertification is required

The 14-day patching window is the control most likely to catch out a business that considers itself well managed. It applies to updates the vendor marks as critical or high severity, measured from the vendor’s release date rather than from when your update tool happened to notice, and it applies to every device in scope including the laptop belonging to the director who was on holiday. It also applies to firmware on routers and firewalls, and to applications, not just operating systems. If your patching is currently “monthly, when someone gets round to it”, that is the first thing to change — and it needs changing before you answer the question, not after.

Cyber Essentials versus Cyber Essentials Plus — which do you need?

The two levels certify identical controls across an identical scope. The difference is entirely in how the evidence is obtained, and therefore in what a customer can infer from the certificate. Self-assessment relies on your honest answers, verified by an assessor reading them; Plus relies on an assessor testing your estate directly. Procurement teams increasingly specify which one they will accept, so the decision is often made for you.

Cyber Essentials

Self-assessment, assessor-marked

Evidence basis Your written answers
Typical elapsed time 1–3 weeks including remediation
Published fee £320–£1,800 by headcount band
Board-level sign-off Required
Technical testing None
Accepted for Most private-sector supply chain requests
Free resubmission One, within two working days of a fail

Cyber Essentials Plus

Independently audited

Evidence basis Assessor tests a device sample
Typical elapsed time 4–10 weeks including remediation
Typical UK cost £1,500–£4,000+ on top of CE
Prerequisite CE passed within the previous three months
Technical testing Vulnerability scan, malware and MFA tests
Accepted for Central government and higher-assurance contracts
Free resubmission None — remediation and retest

The practical guidance is straightforward. If a specific contract requires Plus, do Plus — but plan the self-assessment first and treat it as the rehearsal, because the three-month window between the two is generous enough to fix what the self-assessment exposes and tight enough that you cannot drift. If no contract currently requires Plus, start with the self-assessment, then reassess at renewal. Many businesses find that the discipline of the first year makes Plus a modest step rather than a project.

One point that surprises people: Plus is not a higher standard of security, it is a higher standard of proof. The controls are the same. An organisation that passes the self-assessment honestly and completely would pass Plus on the same estate. The gap between the two, when it appears, is almost always a gap between what the business believed was true and what was actually configured — which is a good argument for the audit, and a poor argument for delaying it.

Why applications fail first time

Most first-time failures are not caused by weak security. They are caused by a specific technical detail the applicant did not know was in the question set, or by a scope decision made too casually. The distribution below reflects the recurring causes we see when a UK SME submits without preparation, expressed as the approximate share of first-submission failures attributable to each.

Unsupported operating systems or software in scope
24%
MFA missing on one or more cloud services
21%
Security updates outside the 14-day window
17%
Scope errors — devices or services omitted
15%
Administrator accounts used for daily work
10%
Incomplete or contradictory answers
8%
Default credentials or unchanged device passwords
5%

Unsupported software is the largest single cause and, in 2026, it has an obvious driver: Windows 10 reached end of mainstream support on 14 October 2025. A device running an operating system the vendor no longer issues security updates for cannot pass, full stop. Businesses on the paid Extended Security Updates programme are in a more nuanced position and should confirm the treatment with their Certification Body before submitting rather than assuming it will be accepted. The same rule catches unsupported server operating systems, end-of-life network appliances, old database engines, and mobile devices that have stopped receiving vendor security patches — a common issue with Android handsets more than three or four years old.

Missing MFA on cloud services is the second, and it is usually a discovery problem rather than a refusal. Businesses enable multi-factor authentication on Microsoft 365 and consider the job done, then the question set asks about every cloud service in scope: the accounting platform, the CRM, the file sharing tool, the marketing suite, the code repository, the domain registrar. Every one of them counts, and administrator accounts on every one of them must have MFA enabled. Build the list before you start — a straightforward way is to export the expenses ledger and highlight every recurring software subscription.

The good news in the failure data is that a first submission which falls short is not the end of the process. IASME allows one free resubmission provided you correct and resubmit within two working days of the result. That window is tight, which is an argument for having your remediation capacity available on the day you submit rather than booking the work afterwards.

The five technical controls in the detail the assessor expects

Everything in Cyber Essentials reduces to these five controls, applied consistently to everything in scope. The descriptions below go beyond the headline into the specific implementation details that determine a pass or a fail, which is where most preparation guides stop short.

1. Firewalls and internet gateways

Every device in scope must be protected by a correctly configured firewall at the boundary between your network and the internet. For an office, that is normally the boundary firewall or router. For a laptop used from home, a hotel or a client site, the requirement is met by a properly configured software firewall on the device itself — the domestic router at an employee’s home is out of scope, which surprises people, but the device firewall is not optional in that scenario.

The specifics the assessor cares about: the administrative password on the firewall must have been changed from the default and must be strong; the administrative interface must not be accessible from the internet unless there is a documented business need protected by multi-factor authentication or an IP allow list; every inbound rule must have a documented business justification and be removed when no longer needed; and unauthenticated inbound connections must be blocked by default. Where a business has more complex requirements, this is also the point at which internal segmentation becomes relevant — not required by the scheme itself, but frequently the cleanest way to reduce what falls in scope, as covered in our guide to network segmentation for UK SMEs.

2. Secure configuration

Devices and software must be configured to reduce unnecessary exposure. In practice that means removing or disabling user accounts that are not needed, removing software that is not used, disabling auto-run for external media, and changing every default or vendor-supplied password on every device and service.

Password policy sits here and it is precisely specified. You must implement one of three approaches for every account: multi-factor authentication combined with a minimum password length of eight characters; automatic blocking of common passwords through a deny list, again with a minimum of eight characters; or a minimum password length of twelve characters with no maximum below 64. You must also have a process to change passwords promptly when you know or suspect compromise, and you must give staff guidance on choosing unique, hard-to-guess passwords. Enforced routine expiry is not required and is no longer recommended practice.

Device unlocking credentials — the PIN or biometric on a phone or laptop — are treated separately: a minimum six-character PIN or biometric, combined with a protection against brute force such as a lockout after a set number of failed attempts.

3. Security update management

All software in scope must be licensed and supported, removed from devices when no longer supported, and updated within 14 days of the vendor releasing an update that fixes a vulnerability the vendor describes as critical or high risk. Where the vendor does not use those words, the scheme falls back to a CVSS v3 base score of 7 or above.

Three details matter more than the headline. First, the clock starts at the vendor’s release, not at your discovery, so a fortnightly review cycle is already cutting it fine and a monthly one will fail. Second, it applies to everything — operating systems, applications, browsers, plugins, firmware on routers and firewalls, and mobile devices. Third, automatic updates are the practical answer for most SMEs; if you defer updates for testing, you need to evidence that high-risk fixes still land inside the window. This is also where the discipline overlaps with resilience more generally: patching cadence and a tested recovery position are the two habits that most reliably reduce ransomware impact, which is the subject of our guide to the 3-2-1 backup rule.

4. User access control

Accounts must be created through an approval process, assigned to a named individual, and removed promptly when someone leaves or changes role. Special access — administrator rights — must be granted only where there is a documented need, reviewed regularly, and used only for administrative tasks.

The rule that catches most businesses is the separation requirement: an administrator must have a separate standard account for everyday work, and the administrative account must not be used for email or web browsing. If your IT manager reads email on the same account they use to manage the domain, that is a fail. Multi-factor authentication is required on all administrative accounts on cloud services, and on all user accounts on cloud services — not just the ones you consider sensitive.

5. Malware protection

Every device in scope must be protected by one of the permitted mechanisms. The mainstream route is anti-malware software that is kept updated, configured to scan files on access, and configured to prevent connections to known malicious websites. The alternative is allow listing, where only approved applications can execute and the approval list is actively maintained — more work to run, but a strong control in a tightly managed estate.

Mobile devices that only run applications from an official vendor store, with the platform’s own protections intact, are generally treated as meeting this control. A jailbroken or rooted device is not, and should be removed from the estate rather than argued about.

Readiness by control — where UK SMEs typically stand

Score your own organisation honestly against the rows below before you open the question set. High risk means it will fail the assessment as things stand today; medium means it needs evidence or tightening; refinement means it is likely fine but worth confirming.

Boundary and configuration
Firewall admin password changed from default High risk
No inbound rules without documented justification High risk
Software firewall enabled on all mobile devices Medium
Unused accounts and software removed Medium
Password policy meets one of the three permitted models High risk
Device unlock PIN of six characters or more Refinement
Updates and supportability
Every OS in scope still receiving vendor security updates High risk
Critical and high updates applied within 14 days High risk
Router and firewall firmware current Medium
Mobile handsets within vendor support life Medium
Complete asset inventory of devices and software High risk
Automatic updates enabled where practical Refinement
Access and malware
MFA on every cloud service, all users High risk
Separate admin accounts, not used for email or browsing High risk
Leavers removed within a defined timeframe Medium
Anti-malware updated and scanning on access Medium
Malicious website blocking in place Refinement
Admin rights reviewed in the last twelve months Refinement

The pattern is consistent: the high-risk rows are concentrated in things that are administratively awkward rather than technically difficult. Nobody finds it hard to enable multi-factor authentication on a CRM; they find it hard to produce the complete list of cloud services the business uses. Nobody objects to separate administrator accounts; they object to changing a working habit. That is why preparation time is dominated by discovery and negotiation rather than by configuration.

What Cyber Essentials costs in the UK

The certification fee itself is fixed and published by IASME, banded by the number of people in the organisation — not by turnover, complexity or device count. What varies enormously is everything around it: remediation, any support you buy to prepare, and the Plus audit if you need it. The table below sets out the shape of a realistic budget. Certification fees are exclusive of VAT and are reviewed periodically, so confirm the current figure before committing.

Organisation size CE certification fee Typical preparation support Indicative CE Plus audit Common remediation cost
Micro — 0 to 9 people £320 £0 – £750 £1,500 – £2,200 £0 – £1,500
Small — 10 to 49 people £620 £500 – £1,500 £1,800 – £3,000 £500 – £6,000
Medium — 50 to 249 people £1,200 £1,500 – £4,000 £2,500 – £5,000 £2,000 – £20,000
Large — 250+ people £1,800 £4,000+ £4,000 – £9,000+ Highly estate-specific

Remediation is the line that ruins budgets, and it is almost entirely predictable in advance. The dominant costs are hardware replacement where devices cannot run a supported operating system, licence uplifts where multi-factor authentication sits behind a higher subscription tier, and the labour of building an asset inventory in a business that has never had one. A gap analysis before you commit to a submission date is inexpensive relative to those numbers and turns an unknown into a quotable figure.

There is one financial benefit worth knowing about. UK-domiciled organisations with an annual turnover under £20 million that certify to Cyber Essentials are eligible to opt in to the scheme’s included cyber liability insurance, which provides a modest level of cover as part of the certification. It is not a substitute for a properly specified commercial policy, and the eligibility conditions are specific, so read the terms rather than assuming coverage. Whether to rely on it at all is exactly the kind of question that benefits from senior technology input, whether in-house or through the sort of fractional CIO arrangement many UK SMEs now use.

On who does the work: a business with a competent internal IT function can prepare and submit without external help, and the question set is written to be answerable by a non-specialist with access to the facts. Where support earns its cost is in businesses without dedicated IT, in estates with legacy systems that need a scoping strategy rather than a purchase order, and where a contract deadline removes the option of learning as you go. The trade-offs are the same ones covered in our comparison of in-house versus outsourced IT support.

Defining scope — the decision that determines everything else

Scope is the single most consequential decision in the whole process, and it is made before you answer a single question. The default and strongly preferred position is whole-organisation scope: every device, every user, every cloud service in the legal entity being certified. This is what most customers assume your certificate covers, and a scoped-down certificate can be challenged in procurement if the exclusion covers the part of the business that would deliver their contract.

What is in scope. All end-user devices used by anyone in the organisation to access organisational data or services: desktops, laptops, tablets, and mobile phones — including personally owned devices, if they are used for work beyond calls and text messages. All servers, physical or virtual, and all networking equipment you control. And all cloud services in use, across infrastructure, platform and software categories — the organisation remains responsible for the controls even where the provider implements them.

What is out of scope. Devices used only for voice calls and SMS, and devices that only access data through a genuinely isolated mechanism. An employee’s home router is out of scope. Third-party devices such as a customer’s or partner’s equipment on your guest network is out of scope provided that network is properly separated. Internet of Things and operational technology equipment sits in a more nuanced position and should be discussed with your Certification Body rather than assumed either way.

Sub-scoping is permitted but must be genuine. If you certify only part of the organisation, that part must be separated from the rest by a firewall or equivalent network segregation — an organisational boundary drawn on a chart is not sufficient. The certificate then names the scope explicitly, and any customer reading it will see the limitation. In practice, sub-scoping makes sense where a business runs a legacy production environment that cannot meet the controls and cannot be replaced this year; it makes poor sense as a way of avoiding work on the main estate, because you will do that work at the next renewal anyway with a year less runway.

Bring-your-own-device deserves specific attention because it is where scope is most often quietly wrong. If a member of staff reads work email on a personal phone, that phone is in scope for the five controls: supported operating system, current security updates, screen lock, and malware protection. Businesses have two honest options — bring those devices under management and evidence the controls, or stop the access technically rather than by policy. Writing a policy that says personal devices must not be used, while the mail server happily accepts connections from them, is a fail waiting to happen.

Certification readiness — scoring where you stand today

Count the high-risk and medium rows from the readiness grid earlier that you can answer yes to today, express that as a percentage of the eighteen rows, and compare it with the benchmark below — the median position of UK SMEs at the point they first ask about certification.

61/100
Median Cyber Essentials readiness at first enquiry, UK SMEs

Interpretation. Below 50 means you are looking at a genuine project rather than a form-filling exercise: expect four to eight weeks, expect hardware or licence spend, and do a gap analysis before booking a submission date. 50 to 75 is where most SMEs sit, and it usually means two or three specific defects — commonly an unsupported device, a cloud service without MFA, and a patching cadence outside 14 days — that can each be fixed in days once identified. Above 75 means you are close enough to submit within a fortnight, and the remaining work is evidence-gathering rather than change.

Whatever the score, one action is worth taking on day one regardless: build the asset inventory. Every device, every operating system version, every cloud service, every administrator account. It is the artefact the whole assessment rests on, it is the thing nobody has, and it is the reason a certification that should take a fortnight takes two months.

The certification timeline — what a realistic run looks like

A prepared organisation can complete the self-assessment in under a fortnight. An unprepared one should plan for six to eight weeks, and the difference is almost entirely in how long discovery and remediation take. The sequence below assumes a small business starting from a standing start with a contract deadline in the near distance.

Week 1 — Scope and inventory
Write the scope statement. Build the asset inventory: every device with its operating system version, every server, every network device with firmware version, every cloud service with its administrator list. Export the expenses ledger to catch the subscriptions nobody remembers.
Week 1 — Gap analysis against the five controls
Walk the inventory against each control and record every gap with an owner and an estimated cost. Unsupported operating systems and missing MFA surface here, and they are the two items with the longest lead time, so identifying them on day three rather than day thirty is the whole point of this step.
Weeks 2–3 — Remediate the blockers
Replace or upgrade unsupported devices. Enable multi-factor authentication across every cloud service, starting with administrator accounts. Separate administrative accounts from daily-use accounts. Change any remaining default credentials on network equipment.
Weeks 3–4 — Fix the patching cadence
Move to automatic updates where practical and put a named owner and a weekly check against everything else, including firmware and mobile devices. This is a process change rather than a task, and the assessor will ask how it works, not whether you did it once.
Week 4 — Register and read the question set
Choose a Certification Body, register through the IASME portal, and read the entire question set before answering anything. Question sets are revised roughly annually each April, so confirm which version you are answering and download the matching guidance.
Week 5 — Complete and internally review
Answer everything, then have a second person check each answer against the inventory. Contradictions between answers are a recurring cause of failure and are trivially avoidable with one review pass.
Week 5 — Board sign-off and submission
A person at board level or equivalent must confirm the answers are accurate. Submit only when your remediation capacity is available, because the free resubmission window after a fail is two working days.
Week 5–6 — Result and certificate
Marking is typically returned within one to two working days. On a pass, the certificate and the badge for your website follow, and your listing can appear on the IASME certified-organisation search that procurement teams use to verify claims.
Months 3, 6, 9 — Maintain, then recertify
Quarterly inventory review, ongoing patch discipline, and a diary entry two months before expiry. Certification lapses at twelve months, and a lapsed certificate in the middle of a tender is an avoidable, expensive mistake.

If Cyber Essentials Plus is the goal, add four to six weeks after the self-assessment result for scheduling and conducting the audit, and remember the three-month deadline: the Plus assessment must be completed within three months of the date on the self-assessment certificate, or you start again. Assessors book up, particularly towards the end of a financial quarter, so make the booking at the point you submit the self-assessment rather than at the point you pass it.

The self-assessment process, step by step

The mechanics are straightforward once you know the shape of them, and knowing the shape removes most of the anxiety attached to a first application.

Choose a Certification Body. IASME is the sole Cyber Essentials Partner and works through a network of accredited Certification Bodies. You buy through one of them, and they mark your submission. They are all assessing against the same question set with the same marking rules, so the differentiator is the support offered alongside — some will review your answers before submission, some will not. Ask that question specifically when you compare quotes, because a pre-submission review is worth more than a small difference in price.

Register and receive portal access. You will be issued access to the IASME assessment platform, where the question set is completed online. You can save and return; you do not have to complete it in one sitting, and it is normal for the questions to send you off to check facts.

Answer the question set. The current set, Willow, has been in use since April 2025; IASME revises the question set periodically, usually in April, so verify which version is live when you apply and use the matching guidance document. Answers are free text as well as yes or no, and the free text matters: “yes” with a clear sentence explaining how the control is implemented gives an assessor something to mark, whereas a bare “yes” invites a clarification request. Where a question does not apply, say so and explain why rather than leaving it blank.

Have a second person review it. This step is not required and it is the highest-value hour in the process. The reviewer should check each answer against the asset inventory, and specifically look for answers that contradict each other — a common example being a declaration that all devices run supported software alongside a device list containing an operating system that reached end of life.

Obtain board-level sign-off. A director, trustee, partner or equivalent must confirm that the answers are accurate to the best of the organisation’s knowledge. This is a genuine accountability step: the certificate rests on that declaration, and a knowingly false answer is a serious matter, not a technicality.

Submit, then be ready to act. Marking normally returns within one to two working days. A pass produces the certificate and the right to display the Cyber Essentials badge. A fail comes with a report identifying the non-compliant answers, and you may correct and resubmit once at no additional cost provided you do so within two working days. Miss that window and a resubmission carries a further fee, which is why the resource to fix small issues should be lined up before you press submit rather than sourced afterwards.

What good looks like — benchmark positions

The rows below describe the operating position of an organisation that certifies without drama and recertifies each year without a project. They are not scheme requirements; they are the practices that make the requirements easy to meet continuously rather than in a panic each spring.

Operating benchmarks for continuous certification readiness

Devices on a supported operating system
100%
Cloud services with MFA enforced
100%
Critical patches applied within 14 days
98%
Assets recorded in a maintained inventory
95%
Admin accounts separated from daily-use accounts
100%
Leavers deprovisioned within one working day
90%
Personal devices either managed or blocked
100%
Network firmware within one release of current
85%
Admin rights reviewed at least annually
80%
Recertification started 60 days before expiry
75%

Two of these carry more weight than the rest. Leaver deprovisioning is where an otherwise tidy organisation accumulates risk fastest, because a departed employee’s account on a cloud service nobody owns is invisible until it is used. Recertification lead time is the one that causes commercial damage: certificates expire on a date, procurement portals check that date, and an organisation that starts its renewal in the final fortnight has no room to remediate anything the renewal exposes.

The scope question that decides most outcomes

If there is one number that predicts whether a first submission passes, it is the proportion of the estate the applicant could actually account for when they started. An organisation that can list every device and every cloud service on day one is usually certified within a fortnight. An organisation that cannot is usually six weeks away, whatever the state of its security, because it has to do the discovery before it can answer honestly.

73%
Of UK SMEs starting certification who discover at least one cloud service in use that IT did not know about

Shadow IT is not a discipline problem, it is a procurement one. A department buys a project management tool on a company card, a designer subscribes to a file transfer service, a developer opens a repository account, and none of it passes through a review because none of it felt like buying software. Each of those services holds organisational data, each is in scope, and each needs multi-factor authentication and a named administrator before you can answer the question set truthfully.

The discovery method that works best for a small business is unglamorous: export twelve months of card and bank transactions, filter for anything recurring, and list every software vendor. Cross-reference that against your identity provider’s list of applications with sign-in activity, and against browser-saved-password reports if your estate is managed. Between them, those three sources catch the overwhelming majority of what a manual survey misses, and the exercise usually pays for itself in cancelled duplicate subscriptions before it delivers any security benefit at all.

Real-world example — a Bristol engineering consultancy

A 31-person structural engineering consultancy in Bristol was told by a tier-one construction client that Cyber Essentials would be a condition of remaining on the approved supplier list from the following quarter. The firm considered itself well run: managed Microsoft 365, a decent firewall, anti-malware on everything, an external IT provider on a support contract. The gap analysis found four blockers, none of which anyone had considered a security issue.

Six machines in the drawing office ran Windows 10 and could not be upgraded because the specialist analysis software was validated only on that platform. Multi-factor authentication was enforced on Microsoft 365 but absent from four other cloud services, including the document management platform holding every client drawing. Two directors used administrator accounts for daily email. And patching ran on a monthly cycle by design, which the firm had believed was best practice and which sat outside the 14-day requirement for high-severity updates.

The resolution took five weeks and cost less than expected. The drawing office machines were moved behind a segregated network boundary and excluded from scope, with a documented plan to migrate the application within the year — a legitimate use of sub-scoping because the separation was technical rather than notional. MFA was enabled across the remaining services in an afternoon once the list existed. The directors were given standard accounts, which took one uncomfortable conversation and no technical effort. Patching moved to automatic with a weekly exception check. The submission passed first time.

What caught us out was not the security. It was that nobody could tell me, on the day we started, how many cloud services we were paying for. We found nine. IT knew about five. That gap was the whole project — everything else was an afternoon’s work once we knew what we were looking at.

The instructive detail is the sub-scoping decision. The firm could have delayed certification for a year while it replaced the analysis software, and would have lost the client. Instead it drew a genuine technical boundary, certified the rest of the business, and disclosed the exclusion openly to the client — who accepted it, because the excluded machines had no route to their data. Sub-scoping used honestly is a legitimate engineering answer to a legacy constraint. Used to hide an unwillingness to do the work, it is a problem deferred to next year at a worse moment.

The pre-submission checklist

Work through these before you open the question set. Each one either produces evidence a later question depends on, or removes a defect that would produce a fail. Two people, one working day, is a realistic estimate for a small business that has its inventory already.

  1. Write the scope statement. Name the legal entity, the locations, the device categories including personal devices, and the cloud services. If you intend to sub-scope, describe the technical separation, not the organisational one.
  2. Build the asset inventory. Every device with make, operating system and version; every server; every network device with firmware version; every mobile handset. This is the document the entire assessment rests on.
  3. List every cloud service. Use the expenses ledger, the identity provider’s application list and a departmental survey together — no single source is complete.
  4. Confirm every operating system is still supported. Flag anything at end of life, including mobile handsets no longer receiving vendor security updates, and decide now whether each one gets replaced or segregated.
  5. Enable MFA everywhere. Administrator accounts first, then all users, on every cloud service without exception. Record any service that cannot support it and plan its replacement.
  6. Separate administrative accounts. Every administrator gets a standard account for daily work, and the administrative account is used only for administrative tasks — no email, no browsing.
  7. Verify the patching window. Confirm that critical and high-severity updates reach every device within 14 days of vendor release, including firmware and applications, and that someone owns the exceptions.
  8. Change all default credentials. Firewalls, routers, wireless access points, printers, network video recorders, and any appliance installed by a third party years ago and never revisited.
  9. Check the firewall rule base. Every inbound rule should have a documented business reason; remove anything that no longer has one, and confirm the management interface is not reachable from the internet.
  10. Confirm the password model. Pick one of the three permitted approaches and confirm it is enforced technically rather than described in a policy document.
  11. Verify malware protection on every device, including that it is updating, scanning on access and blocking known malicious sites, and confirm no device in the estate is jailbroken or rooted.
  12. Run the leaver check. Review accounts across all services against your current staff list, and remove anything belonging to someone who has left or changed role.
Note

Keep the completed inventory and the answers you submitted. At recertification you will be asked the same questions against a changed estate, and having last year’s answers to compare against turns a fresh discovery exercise into a delta review — typically the difference between a two-day renewal and a two-week one.

Common mistakes that cause avoidable failures

Each of the patterns below is common, each is avoidable, and each has ended a first submission that would otherwise have passed.

  • Treating the questionnaire as paperwork. The question set is a technical audit conducted in writing. Answers are marked against the scheme requirements, not against intent, and an assessor who spots a contradiction will act on it.
  • Forgetting personal devices. A phone reading work email is in scope. The two honest options are to manage it and evidence the controls, or to block the access technically. A policy statement that staff must not use personal devices, unenforced by any control, is worse than useless because it puts an inaccurate answer on the record.
  • Assuming the cloud provider’s controls are yours. Responsibility for the five controls stays with your organisation across infrastructure, platform and software services. The provider’s certifications do not transfer to you, and their compliance page is not evidence of your configuration.
  • Answering yes to a control that is only partly implemented. “Most devices” is a no. The controls are assessed across the whole scope, and a single laptop outside the standard build is a defect, not a rounding error.
  • Leaving unsupported software in scope and hoping. This is the most common single cause of failure and there is no discretion in it. Replace it, upgrade it, or segregate it and scope it out with a genuine technical boundary.
  • Submitting without a second reader. Contradictory answers are frequent, obvious to an assessor, and eliminated entirely by one review pass against the inventory.
  • Booking the submission before the remediation capacity. The free resubmission window is two working days. If your IT support cannot respond inside that window, you have converted a free correction into a paid one.
  • Letting the certificate lapse. Certification runs for twelve months to the day. Procurement portals check the date automatically, and a lapse discovered during a tender cannot be fixed at the speed the tender moves.
Watch out

Cyber Essentials certifies a point in time. An organisation that certifies in March and adds three unmanaged cloud services in June is no longer meeting the controls it declared, even though the certificate remains valid on paper. Treat the five controls as an operating standard with a quarterly review, not as an annual event — the certificate is the evidence, not the objective.

When to step up to Cyber Essentials Plus

The decision usually makes itself. If a contract, framework or customer specifies Plus, you need Plus, and the only real question is scheduling. Where it is genuinely discretionary, three factors point towards taking it: you handle client data whose loss would be materially damaging to a third party; you are bidding into central government or defence supply chains where Plus is common and sometimes mandatory; or you want independent verification that what you declared is actually configured, which is a reasonable governance position for a board to take.

The Plus audit itself tests the same five controls on a sample of devices, sized by your estate and platform mix. Expect an authenticated vulnerability scan on the sampled devices, tests that malware protection blocks a harmless test file arriving by email and by web download, a check that unsupported software is genuinely absent, verification that multi-factor authentication is enforced on cloud services, and an inspection of account separation and patch levels. The assessor works from your submitted self-assessment, so any discrepancy between what you declared and what the sample shows is the fastest way to fail.

Preparation for Plus is largely a matter of making the sample representative of a genuinely uniform estate. The failures we see are almost always the odd machine — the contractor’s laptop, the machine in the back office nobody manages, the director’s second device — that sits outside the standard build. Before the audit, pick five devices at random yourself and check them against the controls as though you were the assessor. If any of them fails, the estate is not uniform yet and the audit will find it.

Budget four to six weeks between the self-assessment result and the Plus audit, book the assessor early, and remember the hard three-month limit. On cost, expect the audit to be several times the self-assessment fee, driven by the size of the sample and the number of platforms. A single-platform estate of managed Windows laptops is quick to test; a mixed estate of Windows, macOS, iOS, Android and a couple of Linux servers takes considerably longer, which is another reason estate consistency pays for itself. The underlying network design matters here too — the cleaner your boundary architecture, the smaller and simpler the audit, which is part of the practical case made in our guide to choosing the right network architecture.

At-a-glance summary

The key facts, figures and deadlines from this guide in one place.

Item Detail
Scheme owner and deliveryNCSC-backed; delivered by the IASME Consortium through accredited Certification Bodies
LevelsCyber Essentials (self-assessment) and Cyber Essentials Plus (independent technical audit)
Five controlsFirewalls, secure configuration, security update management, user access control, malware protection
Patching requirementCritical and high-severity updates within 14 days of vendor release
Password optionsMFA plus 8 characters, deny list plus 8 characters, or 12 characters minimum
MFA requirementAll cloud services, administrator and standard user accounts
Admin account ruleSeparate accounts; no email or web browsing from an administrative account
Scope defaultWhole organisation; sub-scoping requires genuine network separation
Personal devicesIn scope if used for work beyond calls and text messages
Certification fee£320 / £620 / £1,200 / £1,800 plus VAT by headcount band
Certificate validity12 months from the date of issue
Resubmission after a failOne free resubmission within two working days of the result
CE Plus deadlineMust be completed within three months of the self-assessment certificate
Included insuranceOptional for UK-domiciled organisations with turnover under £20m; check the terms
Question setWillow, live since April 2025; revised periodically, so confirm the current version

How Cloudswitched supports Cyber Essentials certification

Cloudswitched works with UK businesses on both the preparation and the ongoing operating standard behind Cyber Essentials: building the asset and cloud service inventory, running the gap analysis against the five controls, handling the remediation — multi-factor authentication rollout, patch management, account separation, device replacement or segregation — and reviewing the completed question set before submission. Because the same team manages the underlying infrastructure for many of our clients, the controls stay in place between certifications rather than being rebuilt each year in the fortnight before renewal.

Get certified without the guesswork

A gap analysis against the five controls, a costed remediation plan, and support through submission or the Plus audit.

Talk to a Cyber Essentials Specialist

Frequently Asked Questions

How long does Cyber Essentials certification take?

A prepared organisation with a complete asset inventory and the five controls already in place can complete the self-assessment in one to two weeks, most of which is answering the question set carefully and having it reviewed. An organisation starting from scratch should plan six to eight weeks, because the time is dominated by discovery and remediation rather than by the assessment itself. The two items with the longest lead time are replacing devices running unsupported operating systems and enabling multi-factor authentication across cloud services nobody had listed. Marking is normally returned within one to two working days of submission. Cyber Essentials Plus adds a further four to six weeks for scheduling and conducting the audit.

How much does Cyber Essentials cost?

The certification fee is published by IASME and banded by headcount: approximately £320 for organisations of 0 to 9 people, £620 for 10 to 49, £1,200 for 50 to 249 and £1,800 for 250 and above, all excluding VAT. Fees are reviewed periodically, so confirm the current rate with your Certification Body. The larger variable is remediation, which commonly ranges from nothing to several thousand pounds depending on whether you need to replace devices or upgrade licences to obtain multi-factor authentication. Cyber Essentials Plus typically adds £1,500 to £4,000 or more, driven by the size of the device sample and the number of platforms in the estate.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

They certify identical controls across an identical scope. Cyber Essentials is a self-assessment: you answer the question set, a board-level person signs it off, and an assessor marks your answers. Cyber Essentials Plus adds a hands-on technical audit in which an assessor tests a sample of your devices and cloud services directly — vulnerability scanning, malware protection tests, multi-factor authentication verification and patch level checks. Plus is a higher standard of proof rather than a higher standard of security, and it cannot be taken on its own: it must be completed within three months of passing the self-assessment, with matching scope.

Are personal devices in scope for Cyber Essentials?

Yes, if they are used to access organisational data or services beyond voice calls and text messages. A personal phone reading work email is in scope and must meet the controls: a supported operating system, security updates applied within 14 days, a screen lock of at least six characters or biometric with brute-force protection, and malware protection. Organisations have two honest options — bring those devices under management and evidence the controls, or block the access technically. A written policy prohibiting personal device use, with no technical control enforcing it, does not remove those devices from scope and will produce an inaccurate answer on the record.

Can I certify only part of my organisation?

Yes, but the separation must be technical rather than organisational. Sub-scoping requires that the certified part is segregated from the rest by a firewall or equivalent network separation, and the certificate names the scope explicitly, so any customer reading it will see the limitation. This is a legitimate answer to a genuine legacy constraint — a production environment running validated software that cannot yet be upgraded, for instance. It is a poor answer to an unwillingness to do the work on the main estate, because the work does not go away and you will face it at renewal with less time. Whole-organisation scope is the default and what most procurement teams assume.

What happens if my Cyber Essentials application fails?

You receive a report identifying which answers did not meet the requirements, and you may correct and resubmit once at no additional cost provided you do so within two working days of the result. Beyond that window a resubmission carries a further fee. This is why it is worth submitting only when the people who can make small technical changes are available — a missing multi-factor authentication setting or an unchanged default password can often be fixed the same day, but not if the person who administers that system is away for a week. A failed application is not recorded publicly and carries no penalty beyond the delay.

Does Cyber Essentials cover cloud services like Microsoft 365?

Yes. All cloud services in use are in scope — infrastructure, platform and software services alike — and your organisation remains responsible for the five controls even where the provider implements the underlying technology. In practice that means multi-factor authentication on every service for every user, administrator accounts identified and separated, unused accounts removed, and no default credentials. The provider’s own certifications do not transfer to you and their compliance documentation is not evidence of how your tenancy is configured. Building a complete list of cloud services is usually the single most time-consuming part of preparation.

Is Cyber Essentials mandatory in the UK?

Not for businesses in general, but it is a requirement for many central government contracts, particularly those involving the handling of personal information or the provision of certain technical products and services, and it appears in Ministry of Defence supplier requirements. Beyond the public sector it is increasingly demanded contractually by larger organisations of their suppliers, which is why many businesses first encounter it as a procurement condition rather than a security initiative. The practical position for most UK SMEs is that it is not legally mandatory but is becoming commercially unavoidable in any sector with a formal supply chain.

Does Cyber Essentials satisfy UK GDPR or replace ISO 27001?

No to both, though it helps with the first. UK GDPR requires appropriate technical and organisational measures, and the ICO has recognised Cyber Essentials as evidence of a baseline of technical measures — but the regulation covers a much wider set of obligations including lawful basis, data subject rights, retention and breach notification, none of which the scheme addresses. ISO 27001 is a management system standard covering risk assessment, governance, policy and continual improvement across the whole organisation. Cyber Essentials is a technical baseline verified annually. They complement each other and neither substitutes for the other.

How often do I need to recertify?

Annually. Certification is valid for twelve months from the date of issue and there is no grace period, so the certificate simply expires. Start the renewal around 60 days before expiry, because it is a fresh assessment against a changed estate and may expose new issues — a device that has fallen out of support, a cloud service added during the year, an administrator account created for a project. Keeping last year’s inventory and submitted answers turns the renewal into a delta review rather than a repeat of the original discovery exercise, which is usually the difference between two days and two weeks of effort.

What is the current Cyber Essentials question set?

The Willow question set has been in use since April 2025. IASME revises the question set periodically, generally in April, so confirm which version is live at the point you apply and download the guidance document that matches it — answering against a superseded version is a straightforward way to give answers that no longer meet the requirements. Your Certification Body will confirm the current version, and the requirements document for the applicable version is published for free, which makes it the best possible preparation reading before you register.

Do we get anything besides the certificate?

You receive the certificate itself, the right to display the Cyber Essentials badge, and a listing that procurement teams can check to verify your claim. UK-domiciled organisations with an annual turnover below £20 million are also eligible to opt in to the scheme’s included cyber liability insurance, which provides a modest level of cover — useful, but not a replacement for a properly specified commercial policy, and subject to conditions worth reading in full. The more substantial benefit for most businesses is the discipline: the inventory, the patching cadence and the access controls built during preparation are the things that actually reduce risk.

Turn certification into an operating standard

Cloudswitched helps UK businesses prepare for Cyber Essentials and Cyber Essentials Plus — scoping the estate, closing the gaps against the five controls, reviewing the submission, and keeping the controls in place between renewals so recertification is a review rather than a rebuild.

Talk to a Cyber Essentials Specialist
Tags:Cyber Security
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Cyber Essentials Certification

End-to-end Cyber Essentials Plus certification and ongoing security services

Learn More
CloudSwitchedCyber Essentials Certification
Explore Service

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

22
  • Google Ads & PPC

Google Ads Budget Waste: A UK Business Guide to Cutting Wasted PPC Spend in 2026

22 Aug, 2026

Google Ads wasted spend is the single most recoverable line item in most UK SME marketing budgets. It is not a strategy problem and it is rarely a creative...

Read more
21
  • Cyber Security

Cyber Essentials Certification: A UK Business Step-by-Step Guide to Passing First Time in 2026

21 Aug, 2026

Cyber Essentials certification has quietly become a commercial requirement rather than a security badge. It is mandatory for most central government contracts...

Read more
20
  • SEO

Local SEO for UK Businesses: A Practical Guide to Ranking in Google's Local Pack in 2026

20 Aug, 2026

Local SEO is the practice of making a business visible to the people searching for its services nearby the plumber a homeowner in Leeds needs today, the...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.