14 July 2026 · Compliance · 5 min read
Cyber Essentials: what it actually is, and whether you need it
Cyber Essentials is a UK government-backed certification scheme that checks your business against five basic security controls. It's not a penetration test and it's not a compliance framework in the ISO 27001 sense. It's a baseline: the minimum a business should have in place to stop the most common opportunistic attacks.
The five controls
Firewalls configured properly at the network boundary. Secure configuration, meaning devices and software set up with security in mind rather than left on default settings. User access control, so people only have access to what they actually need. Malware protection across every device. And patch management, keeping software updated so known vulnerabilities get closed before they're exploited.
Why it's becoming hard to avoid
A growing number of public sector contracts require Cyber Essentials before you can even submit a tender. Some insurers now ask for it, or offer better terms to businesses that have it. And increasingly, larger companies ask their suppliers for it as a condition of doing business at all. It's moving from “nice to have” to “table stakes” for a lot of SMEs, whether or not they work in a regulated industry.
How the process actually works
You complete a self-assessment questionnaire covering the five controls, which gets reviewed and signed off by a senior member of your business. It's then submitted through a certification body accredited by IASME, the scheme's official partner. If everything checks out, you get a certificate and a badge valid for twelve months. Cyber Essentials Plus adds an independent technical audit on top, for businesses that need a higher bar of assurance.
Where businesses usually trip up
Most first-time submissions get rejected on details rather than failing the controls outright: a firewall that's configured but not documented, an old admin account that never got removed, a patching process that exists informally but isn't written down anywhere. None of these are hard to fix. They're just easy to miss if nobody's looked at the questionnaire with fresh eyes before you submit it.
If you're thinking about certification, it's worth getting a readiness review first rather than finding out what's missing from a rejected submission.
Have a question about your own setup?
Call, email, or book a slot, whatever's easiest.