What is Cyber Essentials? A plain-English guide for UK businesses
Cyber Essentials keeps appearing on tenders and insurance forms. Here is what it actually is, what it covers, and why more UK businesses are getting certified.
If you run a UK business, "Cyber Essentials" has probably landed on your desk more than once — in a tender document, an insurance renewal, or a larger client's supplier questionnaire. It is easy to nod along without being completely sure what it is. This guide fixes that, without the jargon.
The short version
Cyber Essentials is a UK government-backed certification scheme. It sets out five basic technical controls that, implemented properly, stop the large majority of common, internet-based cyber attacks. Get those five things right, prove it, and you earn the certificate.
That is really the whole idea: it is not exotic, cutting-edge security. It is the equivalent of locking your doors and windows — the fundamentals that stop opportunistic attackers walking straight in.
The five controls
Certification is assessed against five areas:
- Firewalls and internet gateways — controlling what can reach your systems from the internet, and changing default passwords on the kit that guards the boundary.
- Secure configuration — removing the default accounts, unused software and needless services that give attackers an easy foothold.
- User access control — making sure people only have the access they need, admin rights are limited, and accounts are properly managed.
- Malware protection — keeping anti-malware in place and up to date, or only allowing approved software to run.
- Security update management — patching operating systems and applications promptly, and retiring anything no longer supported.
None of these should be controversial. Most are things a well-run IT setup already does. The certificate simply proves you are doing them.
Why it keeps coming up
Cyber Essentials has quietly become a commercial requirement, not just a security nicety:
- Contracts. Many public-sector contracts require it, and a growing number of private-sector buyers ask for it before they will work with you.
- Insurance. Cyber insurers increasingly expect the same basic controls, and certification is a clean way to demonstrate them.
- Trust. It is a fast, credible answer to a prospect's "how do you handle security?" — a badge that shortens sales conversations.
In other words, it reduces risk and removes friction from winning work. That combination is why demand has grown so steadily.
What certification actually involves
There are two levels. Cyber Essentials is a verified self-assessment: you answer for your controls against the current scheme, and the submission is checked. Cyber Essentials Plus adds an independent, hands-on technical audit — someone tests that those controls genuinely hold up.
Most businesses start with Cyber Essentials and step up to Plus when a contract calls for it. If you would like the difference laid out in full, see our guide to Cyber Essentials versus Cyber Essentials Plus.
Getting it without the headache
The scheme is achievable for almost any organisation, but the questionnaire can be fiddly if security is not your day job, and one wrong answer can mean a resubmission. That is where we come in: we review where you stand against the current scheme, help you close any gaps in plain English, and take you through to certification — including the technical audit for Plus.
If Cyber Essentials keeps appearing in your bids and you would rather just get it sorted, get a fixed-price quote and we will make it painless.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.