The Complete Guide to Cyber Essentials Certification
Everything UK organisations need to know about the NCSC's Cyber Essentials scheme – the five controls, who needs it, what it costs, and how to pass first time.
Last reviewed: July 2026 · Reviewed by Harpal Bilan, IASME-licensed Cyber Essentials assessor at NixInfinity-AI, an IASME-accredited Certification Body.
In 30 seconds
Cyber Essentials is a UK government-backed certification managed by the National Cyber Security Centre (NCSC) and delivered through IASME accredited certification bodies – like us. It demonstrates that your organisation has put in place the five basic technical controls that prevent around 80% of common cyber attacks. It is mandatory for many UK government contracts and increasingly required by enterprise customers and insurers.
What is Cyber Essentials?
Cyber Essentials is the UK's flagship cyber security certification scheme. Launched in 2014 by the UK government and now managed on its behalf by the NCSC, the scheme is designed to help organisations of any size demonstrate that they have implemented the five fundamental controls that defend against the most common internet-based threats.
Certification is delivered exclusively through IASME-accredited certification bodies like NixInfinity-AI. There are two levels: Cyber Essentials (a verified self-assessment) and Cyber Essentials Plus (which adds an independent technical audit of your systems).
The Five Cyber Essentials Controls
Firewalls
Boundary firewalls and internet gateways that filter incoming traffic and prevent unauthorised access to your internal network.
Secure Configuration
Removing or disabling default accounts, unused features, and unnecessary services from devices and software to reduce the attack surface.
User Access Control
Granting users only the access they need, using unique accounts, multi-factor authentication and the principle of least privilege.
Malware Protection
Anti-malware software, application allow-listing, or sandboxing to prevent, detect and respond to malicious software.
Security Update Management
Keeping operating systems, applications and firmware up to date – high-risk patches must be applied within 14 days of release.
Who needs Cyber Essentials certification?
Cyber Essentials is mandatory for many UK organisations and increasingly expected in commercial supply chains. You almost certainly need it if you:
- Bid on UK central government contracts handling personal information
- Supply technical products or services to the public sector
- Sell on the G-Cloud framework or Digital Marketplace
- Work with the MOD, NHS, or critical national infrastructure
- Are an FCA-regulated firm such as an IFA, broker or wealth manager
- Are part of an enterprise supply chain with cyber requirements
- Want to lower your cyber insurance premiums
Sector-specific guides: Law firms, IFAs, Property & finance, Schools, G-Cloud suppliers.
Cyber Essentials vs Cyber Essentials Plus
Cyber Essentials
Verified self-assessment questionnaire reviewed and certified by us as your IASME-licensed Certification Body.
- • £320 + VAT
- • Turnaround: from 24 hours
- • Includes £25,000 cyber liability insurance for eligible UK organisations under £20m turnover
Cyber Essentials Plus
Everything in CE, plus an independent technical audit of your systems and devices.
- • £1,400 + VAT
- • Turnaround: within 5 working days
- • Required for higher-assurance government contracts
How much does Cyber Essentials cost?
IASME standardises Cyber Essentials pricing by organisation size:
| Organisation size | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Micro (1–9) | £320 + VAT | £1,400 + VAT |
| Small (10–49) | £440 + VAT | £1,500 + VAT |
| Medium (50–249) | £500 + VAT | £1,650 + VAT |
| Large (250+) | £600 + VAT | £2,000 + VAT |
How to pass Cyber Essentials first time
- 1Define your scope clearly – whole organisation is preferred, but a sub-scope is allowed.
- 2Inventory all in-scope devices, including BYOD and home workers' laptops.
- 3Enable MFA on cloud admin and user accounts (this is the #1 failure point).
- 4Patch high/critical CVEs within 14 days – no exceptions.
- 5Remove unsupported software (Windows 10 after Oct 2025, old PHP, end-of-life routers).
- 6Let us pre-check your answers before submission – as an IASME accredited certification body, we walk you through the whole journey.
Common reasons organisations fail
Missing MFA on cloud accounts
MFA is mandatory for all cloud services and admin accounts. Email/M365 are the most common gaps.
Unsupported software
Any operating system or application past its end-of-life date is an automatic fail.
Unpatched devices
High and critical CVSS vulnerabilities must be patched within 14 days of vendor release.
BYOD scoping mistakes
Personal devices used for work email or admin tasks must be in scope and meet the controls.
Frequently asked questions
Ready to get certified?
We're an IASME accredited certification body offering pre-checked submissions, named UK assessors and 24-hour turnaround for Cyber Essentials.
