If you run a business in the UK - particularly one that handles client data, operates in the public sector supply chain, or bids for government contracts - you've probably heard the term Cyber Essentials. But what actually is it, and does your business genuinely need it?
The short answer: yes, almost certainly. Here's the full picture.
What Is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme designed to help organisations protect themselves against the most common cyber threats. It was developed by the National Cyber Security Centre (NCSC) and launched in 2014, and it remains the most widely recognised baseline cybersecurity standard for UK businesses.
There are two levels of certification:
- Cyber Essentials - a self-assessed questionnaire, verified by an approved certifying body. Covers the five key technical controls (see below). Costs from around £300–£500 depending on your organisation size.
- Cyber Essentials Plus - everything in Cyber Essentials, plus an independent technical audit of your systems by an accredited assessor. More rigorous, more credible, and increasingly required by larger clients and insurers.
Important: Since 2014, all companies bidding for UK government contracts involving the handling of personal data or sensitive information are required to hold Cyber Essentials certification. NHS supply chain requirements have expanded this further.
The Five Technical Controls
Cyber Essentials covers five core areas that the NCSC has identified as preventing the vast majority of common cyberattacks:
1. Firewalls
A properly configured firewall at the boundary of your network and on individual devices. This means ensuring default passwords are changed, unnecessary services are disabled, and inbound rules are locked down.
2. Secure Configuration
Devices and software should be configured to minimise vulnerabilities - removing unnecessary software, disabling features you don't use, and ensuring default settings are hardened before deployment.
3. User Access Control
User accounts should only have the access they genuinely need (principle of least privilege). Administrative accounts must be separate from standard accounts and only used when necessary.
4. Malware Protection
Protection against malware - this can be traditional antivirus, application allowlisting, or sandboxing. The key requirement is that all devices are covered and protection is kept current.
5. Patch Management
Software, operating systems, and firmware must be kept up to date. High-risk vulnerabilities should be patched within 14 days of release.
Who Needs Cyber Essentials?
The short answer is: most UK businesses benefit from it, and many now require it. Specifically, you should prioritise Cyber Essentials certification if:
- You bid for government contracts or public sector work
- You work with NHS trusts, councils, or local authorities
- Your clients include corporate or enterprise businesses with supplier security requirements
- You hold cyber insurance (many insurers now use CE as a baseline for favourable premiums)
- You handle sensitive personal data under UK GDPR
- You're in legal, accountancy, healthcare, education, or financial services
We see this requirement increasingly across the East Midlands - Nottingham, Derby, and Leicester-based businesses tell us their larger clients are starting to mandate it as a condition of doing business.
What Does the Assessment Process Look Like?
The standard Cyber Essentials process involves:
- Gap assessment - reviewing your current setup against the five controls to identify what needs fixing
- Remediation - addressing any gaps (firewall config, patching, access control policies)
- Self-assessment questionnaire - completed online via an NCSC-approved platform
- Verification - a certifying body reviews your submission and either approves or requests clarification
- Certificate issued - valid for 12 months, renewable annually
For Cyber Essentials Plus, step four is replaced by an on-site or remote technical audit of your actual systems - not just what you've declared.
Common Reasons Businesses Fail Their Assessment
We've helped dozens of businesses through the process, and the same issues come up repeatedly:
- Out-of-scope devices included in the assessment boundary that aren't patched
- Personal mobile phones used for work that aren't enrolled in MDM
- Software with end-of-life versions still running (particularly older Windows or Office)
- Multi-factor authentication not enabled on internet-facing services (email, remote access)
- Admin accounts being used as day-to-day accounts
None of these are difficult to fix - but they do need to be addressed before assessment, not discovered during it.
How Long Does It Take?
For a well-prepared organisation, Cyber Essentials can be achieved in 2–4 weeks. If there are significant gaps to address first, allow 4–8 weeks. Cyber Essentials Plus typically adds a further 1–2 weeks for the technical audit.
CloudHost clients in Nottingham, Derby, Leicester and across the East Midlands typically complete the process in 4–6 weeks from initial gap assessment to certificate.
Is Cyber Essentials the Same as ISO 27001?
No - and it's worth being clear about this. Cyber Essentials is a baseline technical certification covering five specific controls. ISO 27001 is a full information security management standard that covers processes, policies, people and technology across your whole organisation. They're not competing standards - CE is a practical starting point; ISO 27001 is a much more involved undertaking suited to larger organisations or those with particularly sensitive data obligations.
How Much Does Cyber Essentials Cost?
Costs vary by organisation size and which certifying body you use, but as a guide:
| Organisation size | Cyber Essentials | CE Plus |
|---|---|---|
| Micro (1–9 staff) | ~£300 | ~£700–£1,200 |
| Small (10–49 staff) | ~£400 | ~£1,200–£2,000 |
| Medium (50–249 staff) | ~£500 | ~£2,000–£4,000 |
These figures cover the certification cost only. If you use a managed IT provider like CloudHost to prepare for and support the assessment, that preparation work is typically included within your managed IT contract or quoted separately as a fixed-fee project.
CloudHost note: We include Cyber Essentials readiness as part of our standard managed IT service for clients in the East Midlands. If you're already a client, speak to your account engineer about scheduling your assessment.
The Bottom Line
Cyber Essentials isn't a silver bullet - no single certification is. But it's a meaningful, affordable, and increasingly essential baseline that demonstrates to clients, insurers and regulators that you take cybersecurity seriously. For most UK small and medium businesses, it's the single highest-return security investment you can make.
If you're not yet certified and want to understand where the gaps are in your current setup, get in touch with the CloudHost team - we'll run a free gap assessment and give you a clear picture of what's involved.