Back to articles

What is Cyber Essentials? A plain-English guide

By , founder and reviewer at BrightCertPublished Reviewed

Short answer

Cyber Essentials is a UK Government-backed certification scheme, created by the National Cyber Security Centre (NCSC) and delivered through IASME, that checks your business against five basic technical controls: firewalls, secure configuration, patching, user access, and malware protection. Most businesses complete it as a self-assessment questionnaire reviewed by a Certification Body. In 2026, the official fee is £320–£600 + VATbased on organisation size. It’s the baseline standard UK government contracts and increasingly clients and insurers ask for as proof you’ve got the fundamentals covered.

Everything below is the plain-English version, no jargon, and links to deeper detail on cost, the free preparation tools, and Cyber Essentials Plus where you want it.

Who’s actually behind it

Cyber Essentials was created by the NCSC, the UK Government’s National Cyber Security Centre, and describes itself as “the minimum standard of cyber security recommended by the Government for organisations of all sizes.” Day-to-day delivery is handled by IASME, the NCSC’s official Cyber Essentials Delivery Partner, which licenses a network of Certification Bodies across the UK to carry out assessments.

That matters because it means Cyber Essentials isn’t a product any one company sells. It’s a fixed, published standard. The same five controls, the same requirements, regardless of which Certification Body reviews you.

The current 2026 requirements

Cyber Essentials requirements v3.3 took effect on 27 April 2026 with the Danzell question set. If you apply now, use the current Danzell questions and v3.3 requirements rather than an older Willow checklist or saved answer set.

One practical point for SMEs is multi-factor authentication. Where a cloud service makes MFA available, v3.3 requires it to be enabled for users of that service. Scope also needs to account for cloud services, remote workers and personally owned devices that can access organisational data or services.

The five things it actually checks

Strip away the compliance language and Cyber Essentials asks five plain questions about your business:

01

Firewalls

Is there a boundary between your network and the internet, and has anyone changed the default password on it?

02

Secure configuration

Are your devices set up deliberately, with unnecessary accounts and software removed, or however they arrived out of the box?

03

Security update management

When a security patch is released for something you use, is it actually applied, and applied quickly?

04

User access control

Does everyone have their own login, with only the access they need? Does a leaver actually lose access?

05

Malware protection

Is something actively watching every device for viruses and other malicious software?

Answer all five with confidence and you’re closer than most businesses starting out. Answer “not sure” to a few of them and you’re completely normal. The gaps are usually fixable in days, not months.

Curious how your business would score? Three quick questions, no signup needed.

User Access Control

Question 1 of 3

Does everyone in your business have their own login account?

Takes 30 seconds. No signup needed.

How certification actually works

The path is the same for almost every UK small business:

  1. Find your gaps first. Most businesses don’t know where they stand before they start. A free readiness assessment (IASME’s own tool, or BrightCert’s scored version) tells you what to fix before you pay anything.
  2. Fix what’s missing. This is the actual security work: a properly configured firewall, MFA for cloud services where available, supported software and suitable malware protection. What it costs depends on your starting point.
  3. Complete the self-assessment and pay the IASME certification fee: £320–£600 + VAT depending on company size. A Certification Body reviews your answers and issues the certificate if they meet the requirements.
  4. Optionally, go further with Cyber Essentials Plus. An independent technical audit on top of standard certification, usually only needed if a specific contract or insurer asks for it by name.

Want the full breakdown on any one step? Three deeper guides:

Where BrightCert fits

BrightCert is a free readiness assessment built around these same five control areas: 60 plain-English questions, roughly two hours, and a readiness score you see before paying anything. The full scored report, with a prioritised fix list and a downloadable PDF, is £99 including VAT with code FOUNDING10 — a £100 founding discount from the standard £199 price, for the first 10 customers. BrightCert doesn’t issue the Cyber Essentials certificate (that always comes from an IASME-licensed Certification Body); it exists to make sure you walk into that step already knowing exactly where you stand.

Frequently asked questions

Is Cyber Essentials mandatory?

Not by law, but it's a required condition for many UK government contracts, and increasingly requested by larger clients, insurers, and supply chains as proof of baseline security.

How long does Cyber Essentials take to complete?

The self-assessment questionnaire itself typically takes a business a few hours once you know your answers. Getting from a standing start to certified, including finding your gaps and fixing them, usually takes days to a couple of weeks if your systems are already in reasonable shape.

Does Cyber Essentials expire?

Yes. Certification lasts 12 months, after which you need to reassess and pay the certification fee again.

Who actually needs Cyber Essentials?

Any UK business can get certified, but it matters most if you bid for government contracts, work in a supply chain that requires it, or want a straightforward way to demonstrate baseline security to clients and insurers.

What's the difference between Cyber Essentials and Cyber Essentials Plus?

Standard Cyber Essentials is a self-assessment reviewed by a Certification Body. Cyber Essentials Plus adds an independent technical audit of your systems. Standard fees are fixed by organisation size; Plus pricing is quoted by the provider for your scope.

What changed in Cyber Essentials v3.3?

Requirements v3.3 took effect on 27 April 2026 with the Danzell question set. It includes clearer scoping and cloud-service guidance, and requires multi-factor authentication for cloud services where the service makes MFA available.

BrightCert helps UK businesses prepare for Cyber Essentials by assessing readiness, identifying gaps, and producing a practical report. BrightCert does not issue the official Cyber Essentials certificate. That comes from an IASME-licensed Certification Body.

Sources: NCSC: Cyber Essentials overview · IASME: Cyber Essentials pricing FAQ · NCSC: Cyber Essentials v3.3 resources. Verified July 2026.

See where your business stands, free.

Start your assessment