Home » Cyber Essentials Explained: What UK Small Businesses Need to Know

Cyber Essentials Explained: What UK Small Businesses Need to Know

Cyber Essentials certification explained for UK small businesses. Learn what it covers, the cost and how it strengthens your cybersecurity.

UK small business owner reviewing cyber essentials certification and cybersecurity on a laptop

Cyber Essentials certification is a UK government-backed scheme that helps your business guard against the most common cyber attacks. In plain terms, it’s a checklist of five basic security controls, get them right, and you dramatically reduce your risk of being caught out by everyday threats like phishing emails, malware and password attacks, and newer hidden document threats such as the Copilot AI worm. For any small business handling customer data, it’s one of the simplest ways to prove you take security seriously.

Here’s the direct answer most owners are looking for: the entry-level Cyber Essentials cost starts at around £300 to £500 plus VAT for a micro or small business (fewer than 10 staff), and it’s a self-assessment you can complete in a few days. It sits at the heart of good small business cybersecurity in the UK, and it also supports your wider GDPR data protection duties, because keeping personal data safe is a legal requirement, not just good practice.

What is Cyber Essentials, exactly?

Cyber Essentials is overseen by the National Cyber Security Centre (NCSC), part of GCHQ, and delivered through a partner called IASME. The scheme focuses on five technical controls that stop the vast majority of common attacks:

  • Firewalls, creating a barrier between your network and the internet.
  • Secure configuration, turning off default passwords and features you don’t need.
  • User access control, making sure staff only have access to what they need, with admin rights limited.
  • Malware protection, anti-virus or equivalent software kept switched on and up to date.
  • Security update management, applying software and operating system updates promptly (usually within 14 days of release).

None of this is exotic. Most of it is housekeeping that a well-run business should be doing anyway.

Cyber Essentials vs Cyber Essentials Plus

There are two levels. Cyber Essentials is a self-assessment questionnaire, you answer honestly, an assessor reviews it, and you’re certified. Cyber Essentials Plus adds a hands-on technical audit where an assessor tests your systems to confirm the controls actually work.

Cyber Essentials Plus costs more, often £1,400 to £3,000+ depending on the size and complexity of your setup, because it involves real testing. For most micro and small businesses, the standard certification is the sensible starting point. Step up to Plus if a client or contract specifically requires it.

How much does Cyber Essentials cost?

Pricing is tiered by organisation size. As a rough guide for the basic self-assessment:

  • Micro business (0, 9 staff): around £320 + VAT.
  • Small business (10, 49 staff): around £400 + VAT.
  • Medium business (50, 249 staff): around £480 + VAT.

These figures change from time to time, so check the current rate on the NCSC or IASME website before you budget. Certification lasts 12 months, after which you renew.

Why bother? The business case

Beyond the obvious benefit of being harder to hack, Cyber Essentials opens doors:

  • Winning contracts. Many public sector tenders, and a growing number of larger private clients, require suppliers to hold Cyber Essentials. If you sell to government or big corporates, it’s often non-negotiable.
  • Reassuring customers. Displaying the certification badge signals that you handle their data responsibly.
  • Cheaper insurance. Some cyber insurance policies offer better terms to certified businesses, and standard Cyber Essentials often includes a limited amount of cyber liability insurance for smaller UK firms.

How Cyber Essentials fits with GDPR

Cyber Essentials and GDPR data protection go hand in hand. Under UK GDPR, you’re legally required to have “appropriate technical and organisational measures” to protect personal data. Cyber Essentials gives you a recognised framework for the technical side, which can help demonstrate to the Information Commissioner’s Office (ICO) that you’ve made a genuine effort.

It won’t cover everything, GDPR also involves policies, staff training and how you handle data requests, but it’s solid evidence that you’ve taken security seriously if a breach ever happens.

What this means for a small business

Think of Cyber Essentials as an MOT for your digital front door. A local accountancy firm, an online retailer, a trades business storing customer details on a laptop, all of them handle data that criminals want. The certification forces you to check the basics, and the badge gives clients confidence. For a few hundred pounds a year, it’s cheap insurance against a costly, reputation-damaging breach.

What to do next

  • Review the five controls. Read the free Cyber Essentials requirements on the NCSC website and check where you already comply.
  • Fix the quick wins. Turn on automatic updates, enforce strong passwords with multi-factor authentication, and remove admin rights staff don’t need.
  • Choose a certification body. Apply through an IASME-accredited partner and budget for the annual fee.
  • Link it to your GDPR duties. Note your certification in your data protection records so you can show the ICO you’ve acted responsibly.

Preparing for certification: a realistic timeline

Most micro businesses can go from a standing start to certified in two to four weeks, and much of that time is spent tidying up rather than filling in forms. If you leave everything to the last minute you will fail the questionnaire, because the assessor checks specific details like how quickly you patch software and whether every account uses multi-factor authentication. Here is a sensible order of work.

  • Week 1, take stock. List every device that connects to your work data: laptops, desktops, phones, tablets and any servers. Note the operating system version on each. This is where many businesses discover an old Windows machine or an unsupported phone that will scupper the whole application.
  • Week 2, fix the gaps. Retire or upgrade anything running unsupported software. Turn on automatic updates everywhere. Enable multi-factor authentication on email, cloud storage and any admin accounts. Remove local admin rights from standard user accounts.
  • Week 3, document and apply. Confirm your firewall and antivirus settings, write down your patching approach, then complete the online self-assessment through your chosen certification body.
  • Week 4, respond and pass. Assessors often come back with clarifying questions. Answer promptly and you will usually have your certificate within a few days.

Common pitfalls that cause failures

The self-assessment looks simple, but a surprising number of small businesses fail on their first go. These are the trip hazards to watch for.

  • Unsupported software. An old operating system, an out-of-date browser, or a phone no longer receiving security updates will fail you outright. Check the manufacturer’s support dates before you apply.
  • Home working devices. Since staff often work from home, their personal laptops and home routers may fall within scope. You need to account for how those devices are secured, or provide company kit.
  • Missing multi-factor authentication. Cloud services must have MFA switched on for all users, not just admins. This is now a hard requirement.
  • Default passwords. Routers, network printers and smart devices frequently ship with a default admin password that never gets changed. Assessors ask about this directly.
  • Bring your own device confusion. If staff use personal phones for work email, those phones are in scope. Decide your policy before you apply, not after.
  • Rushing the honesty. The self-assessment relies on truthful answers, and for Cyber Essentials Plus an assessor will physically verify them. Fudging a self-assessment answer that later gets tested is a waste of money.

What the whole thing really costs

The certification fee is only part of the picture. Budget for the remediation work too, because that is where the real spend often lands. Here is a realistic breakdown for a typical five-person UK business.

Item Typical cost (ex VAT) Notes
Cyber Essentials certification fee £320 Micro business tier, paid annually
Multi-factor authentication £0 to £50 Built into Microsoft 365 and Google Workspace at no extra cost
Antivirus / endpoint protection £30 to £80 per device per year Windows Defender is free and acceptable for many setups
Password manager £20 to £40 per user per year Optional but strongly recommended
Replacing unsupported hardware £400 to £700 per device Only if you are running old kit
Consultant support (optional) £300 to £800 For those who want hand-holding through the process

A business with reasonably modern equipment can realistically achieve certification for £400 to £600 all in. A business limping along on ageing laptops could spend a few thousand once you factor in replacements, but that spend was overdue anyway.

DIY or use a consultant?

You do not have to pay anyone beyond the certification fee. Plenty of confident owners complete the self-assessment themselves using the free NCSC guidance. That said, a consultant can save time and reduce the risk of a failed first attempt, which matters if a contract deadline is looming.

Approach Best for Rough cost Watch out for
Do it yourself Small, tech-confident teams with modern kit Certification fee only Time cost and misreading the requirements
Consultant-assisted Businesses short on time or facing a tender deadline £300 to £800 plus the fee Check they are IASME-linked and not overselling
Full managed IT provider Firms who already outsource their IT Often bundled into monthly support Confirm certification is genuinely included, not extra

Keeping certification alive after year one

Cyber Essentials is not a set-and-forget badge. It lapses after 12 months, and the controls only protect you if you keep them running. Build a few habits into your routine: check that updates are actually installing rather than sitting pending, review who has access when someone leaves, and repeat your device stocktake before each renewal. Diarise the renewal date at least a month ahead so you are not scrambling if a client asks for proof. Many businesses treat the annual renewal as a useful prompt to review their wider security posture, which is exactly the point of the scheme.

Frequently asked questions

How long does Cyber Essentials certification take?

The self-assessment itself takes a few hours to complete, and most businesses are certified within a few days of submitting. The real time goes into preparation, typically two to four weeks if you need to fix things like updates, multi-factor authentication or unsupported devices first.

Do I need Cyber Essentials or Cyber Essentials Plus?

Start with standard Cyber Essentials unless a specific client or contract demands Plus. Plus adds an independent technical audit and costs considerably more, so only pay for it when someone actually requires that extra level of assurance.

Does Cyber Essentials cover home and remote workers?

Yes, and this catches people out. Devices used to access work data from home, including personal laptops and home routers in some cases, fall within scope. Decide how you secure remote working before you apply, and consider providing company devices to keep things simple.

Is free antivirus like Windows Defender good enough?

For many small businesses, yes. Windows Defender is built in, kept updated and accepted for Cyber Essentials, provided it is switched on and configured correctly. Paid products add extra features and central management, which becomes more useful as your team grows.

What happens if my certification lapses?

You simply lose the valid badge and can no longer claim to be certified, which may affect contracts that require it. You will need to reapply and be reassessed. Set a reminder a month before your renewal date so you never fall out of cover unexpectedly.