Home
›
Articles
›

Cyber Essentials for small businesses

Cyber Essentials for small businesses

By Ibi Hasanli

·

·

4 min read

Cyber Essentials for small businesses is a UK government-backed certificate that shows you have five basic security controls in place. If a client or a tender has asked for it, the controls aren't complicated, but a few details catch people out.

What Cyber Essentials covers

The scheme belongs to the National Cyber Security Centre (NCSC), with IASME as its delivery partner. The current standard is Requirements for IT Infrastructure v3.3. If you buy an assessment from 27 April 2026, you answer a question set called Danzell. The requirements sit under five technical controls.

Firewalls filter traffic between the internet and your devices. Your office router counts. You must change its default admin password and block incoming connections nobody asked for.

Secure configuration means tidying devices after they come out of the box. Remove accounts and software you don't use, change default passwords and put a PIN or password on laptops and phones.

Security update management means all software must be licensed and still supported by its maker. Fixes rated critical or high risk must go on within 14 days of release.

User access control means only the right people have accounts, with only the access they need. Logins to cloud services such as Microsoft 365 or Google Workspace must always use multi-factor authentication (MFA). That's a second check, like a code on your phone, on top of the password.

Malware protection means something must stop harmful software from running on each device. The antivirus built into Windows and macOS can meet this if it's switched on and kept up to date.

Cyber Essentials vs Cyber Essentials Plus

When people talk about Cyber Essentials for small businesses, they can mean either level. Both check the same five controls. The difference is how much someone else checks your work.

  • How it's assessed: Cyber Essentials is a verified self-assessment. You answer the questions, a board member signs to confirm they're true and an assessor marks them. Plus adds a technical audit by an independent assessor.
  • Testing: The basic level has no vulnerability scan. Plus includes internal and external scans and tests a sample of user devices, plus your internet gateways and any servers open to the internet.
  • Timing: The Plus audit must happen within 3 months of your basic certificate. You can do both together.
  • Price: The basic level has a fixed price set by staff numbers. Plus is quoted individually by a certification body, based on the size and complexity of your network.

What can fail first

IASME's own FAQ is blunt on one point. If you use unsupported software anywhere in scope, you fail. That can be one old laptop on an operating system its maker no longer patches, or an ageing copy of accounting software.

Patching is next. The 14-day rule applies to fixes rated critical or high risk, and to updates where the vendor doesn't say how serious the flaw is. Turn on automatic updates where you can, and remember phones and routers count too.

Admin rights trip people up. The standard says admin work must be done from a separate account, never used for email or browsing. So if your staff log in as administrators day to day, that needs to change.

Then there's MFA on cloud services. Since v3.3, cloud services can't be left out of scope. I'd fix this first, because it's quick and costs little. Leavers matter here too. Accounts must be removed or disabled when someone leaves, which is why offboarding staff from Microsoft 365 or Google Workspace properly pays off.

When you need Cyber Essentials for contracts

The Cabinet Office's PPN 014 covers central government departments, their agencies, non-departmental public bodies and NHS bodies. For certain contracts, suppliers must show Cyber Essentials or Plus, or equivalent controls, before the contract is awarded.

Those contracts include ones where you'd handle citizens' personal details, such as home addresses or bank details. They also include work on government staff data like payroll, and ICT systems that store or process data at the OFFICIAL classification. The certificate must then be renewed each year for the life of the contract.

Outside government, the NCSC says a growing number of organisations ask suppliers to be certified before they can bid. So it can be worth having before a large client asks.

What Cyber Essentials costs

IASME prices the basic level by staff numbers. At the time of writing, it's £320 + VAT for 0 to 9 employees and £440 + VAT for 10 to 49. It's £500 + VAT for 50 to 249 and £600 + VAT above that. Check IASME's FAQ for current figures. Certificates at both levels expire after 12 months, so it's a yearly cost.

Getting ready for an assessment

Eight Mile isn't a certification body, and we don't issue certificates. Our security audit covers ground that overlaps with the five controls, including leaver access, lost devices, remote access and router configuration. You get a plain-English report with evidence for each finding and a prioritised fix list. We retest once the fixes are in. If you're weighing that up against a penetration test (a simulated attack), read our comparison of a security audit vs penetration test.

If a tender is coming up and you're not sure where you stand, talk to an engineer and we'll agree what to check first.

Field service
Mobile apps

From paper job sheets to a phone app

What changes when a trades business moves from paper job sheets to a phone app, including how the app copes with no signal.

·

4 min read

Email
SPF

Why your quotes land in spam

Why your quotes land in spam: SPF, DKIM and DMARC explained for business owners, and how to check your own domain with free tools.

·

3 min read

Networking
Office move

Office move IT checklist for London SMEs

Office move IT checklist for London SMEs: internet lead times, surveys, cabling, network design, servers and security before and after moving.

·

4 min read

Networking
VPN

Multi-site office network

Multi-site office network design for London SMEs: site-to-site links, consistent segmentation, accounts you keep.

·

3 min read

Security
Audit

Security audit vs penetration test

Security audit vs penetration test: when to review config first, when a buyer needs a pentest, and usual order for SaaS.

·

3 min read

Security
Git

Secrets in git repository

Secrets in git repository history outlive a deleted file. Rotate first, then stop the next temporary commit.

·

3 min read