All posts Security

Cyber Essentials: who actually needs it, and when

A plain-English guide to Cyber Essentials and Cyber Essentials Plus. Who needs certification, what it actually proves, and how to pass the first time.

Every few weeks a prospect asks us the same question. “Do we actually need Cyber Essentials?” And every few weeks we give the same answer. It depends on who is writing your next cheque.

What Cyber Essentials is, and is not

Cyber Essentials is a government-backed scheme run by the IASME consortium on behalf of the NCSC. It is a set of five technical controls that, done properly, stop most of the commodity attacks that target UK businesses. Firewalls, secure configuration, user access control, malware protection, and patch management.

It is not a comprehensive security framework. It does not replace ISO 27001, it does not cover your incident response, and it will not tell you whether your cloud tenant is configured sensibly. What it does is prove that the basics are in place.

There are two levels. Cyber Essentials is a self-assessment questionnaire, verified by a certifying body. Cyber Essentials Plus adds an external technical audit. Someone from the certifying body actually tests your controls rather than taking your word for it.

The five controls, in plain English

It helps to know what the assessor is actually looking for, because the scheme’s own wording is drier than it needs to be.

Firewalls. Every device that connects to the internet sits behind a firewall, and the firewall’s admin interface is not reachable from the internet with a default password. For a small office that is the router or the managed firewall we install; for a laptop working from a kitchen table it is the software firewall built into Windows or macOS, switched on.

Secure configuration. Default passwords changed, unused accounts and software removed, auto-run disabled, and a screen lock on every device. This is the control that catches the “we never got round to it” items: the guest account that still works, the printer with admin/admin, the CCTV recorder nobody has logged into since it was fitted.

User access control. Everyone has their own account, nobody uses an administrator account for day-to-day work, and multi-factor authentication is on for every cloud service. Since the 2023 update to the scheme, MFA on cloud services is mandatory, not recommended.

Malware protection. Supported anti-malware on every device, kept up to date, or application allow-listing. Modern endpoint detection and response tools such as SentinelOne or Defender for Business pass this comfortably; a free consumer antivirus somebody installed in 2019 does not.

Security update management. Every operating system and application is supported by its vendor, licensed, and patched within 14 days of a critical or high-severity fix being released. This is the one that fails most assessments, and we come back to it below.

Who genuinely needs it

Three groups, in our experience.

The first is anyone bidding for UK government work. Central government contracts above the threshold require Cyber Essentials as a minimum, and a lot of local authorities and NHS trusts now require Plus. If you sell to the public sector, it is not optional.

The second is anyone in a supply chain that has been asked. Large corporates push Cyber Essentials down to suppliers as a way of managing third-party risk without running their own audit. If your largest client asks for it, you are getting certified.

The third is anyone who wants a clear, externally validated baseline. Even if nobody is asking for it, going through Cyber Essentials Plus forces you to patch the things you knew needed patching.

There is a fourth group that is growing: businesses whose cyber insurer has started asking. Insurers have moved from “do you have antivirus” to a questionnaire that reads very much like the Cyber Essentials one, and a current certificate is the quickest way to answer it. Some policies now price it in.

Cyber Essentials or Cyber Essentials Plus?

Basic Cyber Essentials is the questionnaire. You answer around 80 questions about your estate, a director signs a declaration, and a certifying body reviews the answers. It takes a few hours if the estate is in good shape, and the certificate is valid for twelve months. It is the right level if a client or a tender simply says “Cyber Essentials” and does not specify Plus.

Plus is the same questionnaire followed by an audit within three months. The assessor connects to a sample of your devices, runs an authenticated vulnerability scan, checks that patches are actually installed, sends test emails with attachments to see whether the malware protection catches them, and tests the browser download behaviour. It is the level to choose when a tender or a client says Plus, when you handle regulated data, or when you want the certificate to mean something to a sceptical buyer.

The honest advice: if you are going to do the work to pass basic Cyber Essentials properly, the extra step to Plus is smaller than it looks, because the audit only tests what the questionnaire already claims.

What actually trips people up

Patching. The certification requires critical and high-severity patches within 14 days of release. Most SMBs think they are doing this. Very few are. We find 90-day-old Chrome installs on sales laptops all the time.

Bring-your-own-device. If you let staff access email or SharePoint from personal phones, those phones are in scope. Which means they need a screen lock, they need to be running a supported OS, and they need malware protection. Intune and conditional access solve this cleanly. Nothing else solves it.

Cloud services. A lot of people think that moving to Microsoft 365 took them out of scope. It did not. The questionnaire is explicit about cloud services being assessed, and MFA on every one of them is a hard requirement.

Unsupported software. Windows 10 reached end of support in October 2025. Any Windows 10 device still in use without extended security updates is an automatic fail, and so is that old Windows Server 2012 box running the accounts package. The same applies to phones: an iPhone or Android handset that can no longer get OS updates is out.

Scope creep in the other direction. Some businesses try to shrink the scope to a single “compliant” subnet to make the assessment easier. The scheme allows a defined scope, but the certificate then only covers that scope, and a client who reads the certificate will notice. Whole-organisation scope is what most buyers expect.

A realistic timeline

For a typical 20 to 50 person business that has not been through the scheme before, plan for six to ten weeks from deciding to do it to holding the Plus certificate.

Weeks one and two are discovery: an inventory of every device, every cloud service and every piece of software, and a vulnerability scan to see where the patching actually stands. This is where the surprises turn up.

Weeks three to six are remediation: patching, replacing or retiring unsupported kit, enrolling BYOD devices in Intune or removing their access, switching on MFA everywhere, and tightening the firewall and admin account rules. Most of the elapsed time is waiting for people to bring laptops in.

Week seven is the questionnaire. If the remediation was done honestly this is a short job.

Weeks eight to ten are the Plus audit, scheduled with the certifying body, plus any small fixes it throws up.

Renewal is annual, and the second year is much quicker because the estate is already in shape and the controls are now part of how the business runs.

How to actually pass

Patch the estate before you start. Run a baseline audit across endpoints and servers, close the gaps, then apply. Get MFA on everything, not just email. Write a short, honest acceptable use policy and make sure staff have actually seen it. Get your BYOD devices enrolled in Intune, or remove their access.

Keep the evidence as you go. The assessor will ask for your asset list, your patching reports and your MFA configuration; if those come out of a management platform rather than a spreadsheet somebody updated last night, the audit is quicker and the answers are believed.

If you want help, we get clients through Cyber Essentials Plus on a fixed fee. We are certified ourselves, yearly, so the checklist is not theoretical.

Find out more about our security services or get in touch.

Keep reading

More from the engineering floor.

Security

Microsoft 365 security: the ten settings everyone misses

Your M365 tenant probably ships with half the security off. Ten settings to change today, from conditional access to external sender banners.

4 March 2026 10 min read
Security

Why phishing still works in 2026, and how to stop it

Phishing hasn't got cleverer, your defences just haven't kept up. A practical look at what works: MFA, conditional access and impersonation protection.

18 February 2026 8 min read
AI

Why most Copilot pilots stall at week three

Microsoft 365 Copilot rollouts tend to fail for four predictable reasons, none of them technology. A practical guide to making adoption stick.

21 April 2026 5 min read
Free · no slide deck

Questions that go beyond the post?

Book a 30 minute call with an engineer. No sales pitch, no slide deck, just a conversation about your setup and what to tighten up next.