Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

Cyber Essentials Explained for UK Small Businesses

A plain-English guide to the UK's Cyber Essentials scheme — what it is, the five technical controls it asks for, and why the certificate is worth having even if nobody's forcing you.

What is Cyber Essentials, and does my business need it?

Cyber Essentials is a UK government-backed certification scheme that shows your business has five basic security controls in place. It’s designed to protect you against the common, opportunistic attacks that make up the vast majority of cyber incidents — not sophisticated, targeted hacking, but the everyday scanning and phishing that hits any business with an internet connection.

Whether you strictly need it depends on who you work with. Plenty of small businesses have no legal obligation to hold it. But if you bid for public-sector contracts, handle sensitive client data, or want a straightforward answer when a customer asks “how do you keep our information safe?”, the certificate is a clear, recognised way to prove you take the basics seriously.

The five controls, in plain English

Cyber Essentials doesn’t ask for anything exotic. It asks you to do five sensible things properly and consistently. That “consistently” is the hard part — most businesses do some of these, few do all of them everywhere.

1. Firewalls. Every device that connects to the internet should sit behind a properly configured firewall. That means the boundary between your network and the outside world is controlled, default passwords on routers and firewalls are changed, and nothing is left open that doesn’t need to be.

2. Secure configuration. Devices and software should be set up to reduce risk, not left on factory defaults. That covers removing unused accounts and software, disabling features you don’t need, and making sure default passwords are gone. Kit out of the box is built for convenience, not safety.

3. Access control. People should have only the access they actually need to do their jobs. Administrator accounts are restricted and used only when required, staff have their own logins, and leavers are removed promptly. Multi-factor authentication is now expected on cloud services and accounts that support it — a stolen password alone shouldn’t get anyone in.

4. Malware protection. Every device needs a defence against malicious software, whether that’s built-in protection like Microsoft Defender, a dedicated anti-malware product, or restricting machines to approved applications only. The point is that something is actively watching for and blocking known threats.

5. Security update management. Software and operating systems must be kept up to date, and anything the vendor no longer supports has to go. Unpatched, out-of-date software is one of the most common ways attackers get in, because the holes are public knowledge. Updates need to be applied promptly — the scheme expects critical fixes within a set window.

None of these are dramatic. Together they close off the routes most attackers rely on.

Why it actually matters

The honest case for Cyber Essentials isn’t the certificate on your website. It’s that the five controls, done properly, block the overwhelming majority of real-world attacks a small business faces. The National Cyber Security Centre built the scheme around exactly this: get the fundamentals right and you remove yourself from the “easy target” pile that opportunistic attacks depend on.

There are practical benefits too. Many public-sector and larger private contracts now require Cyber Essentials before you can even bid. Some cyber-insurance policies ask about it, and having it can make cover easier to arrange. And it gives you a plain answer to the security questions clients increasingly put in their supplier checks — instead of a vague reassurance, you have an independent certificate.

It also forces a useful stocktake. Going through the assessment surfaces the things that quietly drift — the old laptop still on an unsupported Windows version, the shared admin password nobody’s changed, the ex-employee account still active. Our approach to cyber security treats those controls as an ongoing baseline rather than a one-off exercise, which is really the spirit of the scheme.

The caveats worth knowing

Cyber Essentials is a floor, not a ceiling. It proves you’ve got the basics covered; it doesn’t make you unbreakable, and it won’t stop a determined, targeted attack on its own. Treat it as the foundation you build on, not the finish line.

It also has to reflect reality. The base certificate is self-assessed, so it only means as much as your answers are honest. Certifying on paper while your actual setup tells a different story helps no one — least of all you, when something goes wrong. And because it renews annually, it’s a commitment to keep the controls in place, not a badge you earn once.

One more thing: the controls lean on good habits you should have anyway. Reliable backup and continuity isn’t strictly one of the five, but it’s the safety net that means a ransomware hit or a lost laptop is an inconvenience rather than a disaster. Certification and solid backups belong together.

Getting there without the headache

If reading the five controls made you wince slightly — unsure whether your firewalls are configured right, whether multi-factor authentication is on everywhere, whether every machine is still getting updates — that’s normal, and it’s fixable. The gap between “we probably do most of this” and “we can prove we do all of it” is usually a few weeks of tidying up, not a rebuild.

We can walk your setup through the five controls, fix what needs fixing, and get you certification-ready as part of ongoing managed IT support — so the baseline stays in place after the certificate arrives, not just on assessment day. If Cyber Essentials is on your list this year, get in touch and we’ll tell you honestly where you stand and what it’ll take.

Frequently asked questions

What's the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment — you answer a structured questionnaire and a certifying body reviews your answers. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit, where an assessor tests your machines and systems to confirm the controls are genuinely in place. Plus carries more weight with clients and insurers, but most businesses start with the base certificate and move up when a contract requires it.

How long does Cyber Essentials take to get?

The assessment itself can be completed in a few days once your systems are in order. The honest answer is that the timeline depends on how much tidying up is needed first — if you've unsupported Windows versions, no multi-factor authentication or patchy device settings, fixing those is the real work. A clean, well-managed setup can certify quickly; a neglected one needs remediation before it will pass.

Do we need to re-certify every year?

Yes. Cyber Essentials is valid for twelve months, then you reassess. That's deliberate — threats and software change, so a one-off tick means little. Annual renewal keeps the five controls honest and gives clients confidence the certificate still reflects reality.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.