When Cyber Essentials was introduced in 2014, it was primarily a government procurement requirement. If you wanted to bid for contracts with central government or handle government data, you needed the certification. For businesses that didn't work with the public sector, it was easy to ignore.
That calculus has shifted significantly. In 2026, Cyber Essentials is being required or strongly encouraged by a much wider range of organisations — enterprise clients in financial services, healthcare, legal and manufacturing; cyber insurers setting minimum eligibility criteria; and supply chain frameworks across a growing number of industries. The businesses that treated it as a niche compliance tick-box are finding that it's becoming a commercial requirement they can no longer defer.
What Cyber Essentials Actually Is
Cyber Essentials is a UK government-backed certification scheme that tests whether an organisation has the basic technical controls in place to defend against the most common types of cyber attack. It was designed around the principle that the majority of successful cyber attacks exploit well-known vulnerabilities that could be prevented by a relatively small number of fundamental controls.
The certification covers five control areas:
- Firewalls — boundary firewalls and internet gateways that prevent unauthorised access to your network
- Secure configuration — ensuring software and devices are configured securely, with unnecessary features disabled and default passwords changed
- User access control — ensuring user accounts have only the privileges they need, and that admin accounts are used only for administrative tasks
- Malware protection — anti-malware tools configured to prevent, detect and remove malicious software
- Security update management — keeping software and devices patched and up to date to address known vulnerabilities
Cyber Essentials is the self-assessed version, verified by a certifying body. Cyber Essentials Plus involves independent technical testing by an assessor who verifies the controls are genuinely in place — it carries more weight and is increasingly required by clients who want assurance beyond a self-assessment.
Why It's Becoming a Commercial Requirement
The supply chain pressure around Cyber Essentials has increased markedly in the last two years. Several factors are driving this.
Insurance Prerequisites
The cyber insurance market hardened considerably between 2022 and 2024, following a significant increase in ransomware claims. Insurers responded by tightening underwriting criteria. An increasing number of insurers now require Cyber Essentials certification — or the equivalent controls — as a condition of providing cyber liability cover. Some policies that were previously available without it now require it at renewal.
For any business that holds cyber insurance — and if you hold client data or depend on your IT systems to trade, you should — this is a direct commercial driver for certification.
Enterprise and Corporate Client Requirements
Large enterprises, particularly those in regulated sectors, are increasingly requiring their suppliers to hold Cyber Essentials or demonstrate equivalent security posture. This is driven by the recognition that supply chain attacks — where criminals compromise a smaller supplier to gain access to a larger client's data or systems — are one of the most effective attack vectors in the current threat landscape.
We work with engineering and manufacturing businesses in Derby and the wider Midlands who are part of automotive and aerospace supply chains. Several have had Cyber Essentials made a contractual requirement by their tier-one clients within the last 18 months. The conversations are becoming more common across other sectors too.
Public Sector Contracts
The original driver hasn't gone away. Cyber Essentials remains a requirement for all central government contracts involving the handling of personal information or certain other types of sensitive data. For businesses that supply to NHS trusts, local authorities, or other public sector bodies, certification is non-negotiable.
What Cyber Essentials Actually Protects Against
The NCSC estimates that Cyber Essentials, properly implemented, protects against approximately 80% of the most common types of cyber attack. Specifically:
- Attacks that exploit unpatched software vulnerabilities — prevented by security update management
- Attacks that use malware delivered via web browsing or email — prevented by malware protection and boundary firewalls
- Attacks that exploit default or weak credentials — prevented by secure configuration and user access control
- Attacks that involve privilege escalation from a compromised user account — prevented by user access control
What it doesn't protect against — and what it's not designed to address — is the more sophisticated, targeted attack. For that, you need additional controls: email security filtering, EDR, security awareness training, and a properly monitored security environment. Cyber Essentials is the floor, not the ceiling.
Common misconception: Many businesses assume they'd fail Cyber Essentials because their IT is complex or they have remote workers. In practice, the vast majority of SMEs we work with — including those with hybrid teams, cloud infrastructure and BYOD policies — can achieve certification once the right controls are in place. The process is about demonstrating the controls exist, not about having a perfect IT environment.
What the Certification Process Looks Like
For most SMEs, achieving Cyber Essentials involves three stages:
Gap analysis: An assessment of your current environment against the five control areas, identifying what's already in place and what needs to change. This is where you find out how close you already are — and for businesses with a reasonably modern IT setup, the gaps are often smaller than expected.
Remediation: Addressing the gaps identified in the analysis. This might include updating patch management processes, reviewing user account privileges, reconfiguring firewall rules, or deploying additional malware protection. A good managed IT provider handles this as part of the service.
Assessment and certification: Completing the self-assessment questionnaire (for Cyber Essentials) or undergoing independent technical testing (for CE Plus), verified by an accredited certifying body. Certification is valid for 12 months and must be renewed annually.
For businesses in the East Midlands that we work with, the typical timeline from starting the process to receiving the certificate is three to four weeks. Annual renewal, once the controls are embedded, is faster — usually one to two weeks.
Should You Go for Cyber Essentials or Cyber Essentials Plus?
For most SMEs, Cyber Essentials is the right starting point. It's the most widely recognised version, it satisfies the majority of supply chain and insurance requirements, and it's significantly less expensive than CE Plus.
CE Plus makes sense if you're bidding for contracts that specifically require it, if you operate in a high-risk sector (healthcare, financial services, defence supply chain), or if you want the additional assurance of independent verification for commercial or reputational reasons. Some businesses also find that CE Plus is a useful internal exercise — having an assessor independently test your controls often surfaces issues that a self-assessment would miss.
If you're unsure which is right for you, the answer is usually to start with Cyber Essentials. The controls you need for CE are the same ones required for CE Plus — so achieving the base certification first, then upgrading when needed, is a logical path.
The important thing is to start. In 2026, the number of businesses that will be asked to demonstrate Cyber Essentials certification is going to increase, not decrease. Getting ahead of that requirement — rather than scrambling to meet it when a client or insurer demands it — is the pragmatic move.