Cyber Essentials is a UK government-backed certification scheme, run by the National Cyber Security Centre (NCSC) and delivered through accredited certification bodies, that verifies a business has the basic technical controls in place to defend against the most common cyber attacks. It's not a deep-dive audit – it's a baseline, and increasingly a baseline that clients, insurers and government contracts expect you to meet.
The five technical controls
Certification is built around five areas. Get all five right and you're protected against the bulk of opportunistic, automated attacks that make up most of what actually hits small businesses:
- Firewalls. Configured to control what traffic can reach your devices and network, with default passwords changed and unnecessary services closed off.
- Secure configuration. Devices and software set up with security in mind from the start – removing unused accounts and software, and switching off features you don't need.
- User access control. Accounts given only the access they actually need, admin rights kept to a minimum, and strong authentication (ideally MFA) on the accounts that matter.
- Malware protection. Antivirus or application allow-listing in place and kept up to date across every device that can reach your data.
- Security update (patch) management. Operating systems and software kept up to date, with critical patches applied promptly – and nothing unsupported still running. This is exactly where an end-of-life system like Windows 10 past its October 2025 support cut-off becomes a problem: an unpatched, unsupported machine is an automatic fail.
Cyber Essentials vs Cyber Essentials Plus
Standard Cyber Essentials is a self-assessment questionnaire, verified by an external assessor – it checks that the right controls are in place and correctly configured. Cyber Essentials Plus goes further with hands-on technical testing of your systems, giving a more rigorous, independently verified result. Plus is worth considering if you handle sensitive data or if clients specifically ask for it; standard certification is the right starting point for most small and medium businesses.
Why it's worth doing even if nobody's asking yet
- Tenders and client requirements. Government contracts and a growing number of private-sector clients require Cyber Essentials before they'll work with you, particularly if you handle their data.
- Cyber insurance. Certification can lower premiums, and some insurers now expect it as a condition of cover.
- A genuine security baseline. The controls it checks are exactly the ones that stop the majority of real-world attacks – this isn't box-ticking, it closes real gaps.
- Client trust. The certification mark is a quick, credible signal that you take security seriously, without anyone having to take your word for it.
Where to start
The honest first step is finding out where you'd fail today – unsupported software, missing MFA, local admin rights handed out too freely, and so on are the most common trip-ups. We can run that assessment, fix what's found, and support you through certification itself as part of our cybersecurity services. Call 01865 594100 or get in touch for a free consultation.