Cyber Essentials explained: what it is and why UK businesses need it
Cyber Essentials is a UK government-backed certification that says a business has the five basic cyber security controls in place. It's run by IASME on behalf of the National Cyber Security Centre. Roughly 30,000 UK businesses hold it, and the number that need it is climbing steadily as insurers, tender teams and public bodies start asking for it as standard.
The five controls
- Firewalls — every device that connects to the internet is behind a properly configured firewall.
- Secure configuration — devices and software are set up sensibly, with unused features and default passwords removed.
- User access control — people have the access they need for their job and no more, and admin accounts aren't used for everyday work.
- Malware protection — every device has anti-malware in place and it's kept up to date.
- Security update management — operating systems and important software are patched within 14 days of a critical update being released.
None of those are technically ambitious. They're the basics that most breaches skipped.
Cyber Essentials vs Cyber Essentials Plus
Cyber Essentials is a self-assessment. You fill in a questionnaire, an assessor reviews it, and if it stands up you get certified. Cyber Essentials Plus adds an independent, hands-on technical audit — an assessor tests a sample of your machines to prove you actually do what you said you do. Plus is required for some public-sector contracts and is a much stronger signal of security posture.
Who needs it?
In practice: anyone selling to central government (mandatory since 2014), anyone involved in NHS or MOD supply chains, most tier-1 manufacturing suppliers, an increasing number of law firms and accountants (for professional indemnity insurance), and any business tendering for local government work. Even if you're not in one of those buckets today, the direction of travel is clear — most cyber insurance renewals now expect it as a baseline.
How long does it take?
For a well-run business, two to four weeks from kick-off. If there's remediation to do — old kit to replace, MFA to roll out, patching to catch up on — allow six to eight weeks. We do the assessment work for you, and the annual renewal is much quicker once the first one is done.
If you'd like a scoping call to see what you're missing, we're happy to have a look — no obligation.