Skip to main content
    NixInfinity-AI
    For 1–49 staff organisations

    Cyber Essentials for Small Business

    A practical, plain-English guide to certifying your small business – what it costs, how long it takes, and how to pass first time without disrupting your day job.

    Why small businesses are now Cyber Essentials' biggest audience

    When the National Cyber Security Centre launched Cyber Essentials in 2014, the assumption was that medium-to-large enterprises would lead adoption. A decade later, the pattern looks very different: more than 70% of new certifications now go to organisations with fewer than 50 staff. Three forces are driving this shift.

    First, supply-chain pressure. Enterprise customers, public sector buyers and insurers increasingly require Cyber Essentials before they will sign a contract or renew a policy. If you supply a tier-1 supplier – directly or indirectly – you are likely to be asked.

    Second, attack economics. Ransomware operators have moved down-market. Automated tooling makes it as cheap to attack a 12-person accountancy practice as a 1,200-person enterprise – and the smaller firm is far less likely to have layered defences.

    Third, insurance. Cyber liability premiums for uncertified SMEs have risen sharply. Many insurers now decline cover entirely without a baseline framework like Cyber Essentials.

    The four pain points we hear from small business owners

    No dedicated IT team

    Most small businesses outsource IT or rely on a generalist. Cyber Essentials gives a clear, opinionated baseline you can hand to your IT partner.

    Limited time

    Owners and directors juggle compliance with day-to-day delivery. Our 14-day fast-track minimises internal effort.

    Tight budgets

    £320 + VAT for 1 to 9 staff and £440 + VAT for 10 to 49, including £25,000 of cyber liability insurance for eligible UK organisations under £20m turnover – the insurance benefit alone usually exceeds the certification fee.

    Lost contracts

    Increasingly, small suppliers are being asked to demonstrate certification before a contract is signed – losing the deal is more expensive than certifying.

    Pricing for small organisations

    Cyber Essentials fees are set by IASME and tiered by staff numbers. There are no hidden costs in our quotes – the figure you are given includes IASME's certification charge, full preparation support and £25,000 of cyber liability insurance for eligible UK organisations under £20m turnover.

    Micro (1–9 staff)

    £320 + VAT

    Cyber Essentials. CE Plus £1,400 + VAT.

    Small (10–49 staff)

    £440 + VAT

    Cyber Essentials. CE Plus £1,500 + VAT.

    See our full pricing guide for medium and large organisations.

    The 5 controls – translated for small businesses

    Cyber Essentials assesses five technical control areas. Here is what each one actually means when you don't have a dedicated IT team.

    1

    Firewalls

    Use the firewall built into your router and turn on Windows/macOS firewall on every device. Block inbound traffic by default.

    2

    Secure configuration

    Remove default accounts, set strong unique passwords, disable unused services. Most small businesses already do most of this – we help you evidence it.

    3

    User access control

    Staff should not be local admins. Use a separate admin account for installs. Apply MFA on all cloud accounts (Microsoft 365, Google Workspace, accounting).

    4

    Malware protection

    Microsoft Defender (free, built-in) is sufficient for most small businesses. Keep it on, keep it updated, don't disable it.

    5

    Security update management

    Turn on automatic updates for Windows, macOS, mobile devices and any internet-facing software. Replace anything end-of-life within 14 days.

    For a deeper, NCSC-aligned breakdown of each control, read our 5 Cyber Essentials Controls Explained guide.

    The 14-day fast-track

    Most of our small-business clients move from kick-off to certification in two weeks. The flow is intentionally lightweight to suit owner-led organisations:

    1. Day 1 – 30-minute scoping call to understand your estate (devices, cloud services, staff numbers).
    2. Days 2–4 – We send a tailored evidence checklist and walk you through the IASME question set.
    3. Days 5–10 – You implement any small remediation (typically: enable MFA, retire unsupported software, document password policy).
    4. Days 11–13 – We review your draft submission for first-time-pass before it goes to IASME.
    5. Day 14 – Certificate issued and £25,000 insurance activated if eligible.

    For organisations with already-strong security posture, our 24-hour fast-track route is available – see our timeline guide for details.

    Frequently Asked Questions

    Get your small business certified in 14 days

    Fixed-price £320 + VAT for 1 to 9 staff and £440 + VAT for 10 to 49. £25,000 cyber insurance for eligible UK organisations. IASME-qualified assessors.

    Get my certification quote
    Related: Pricing · Timeline · Checklist

    Related Cyber Essentials Guides