What Is Cyber Essentials Certification in the UK?

A customer asks for proof of cyber security before signing a contract. A tender requires a recognised standard. Or a business has grown beyond informal IT practices and needs assurance that the basics are properly managed. In each case, the question often arises: what is Cyber Essentials certification, and is it the right step for your organisation?

Cyber Essentials is a UK Government-backed scheme designed to help organisations protect themselves against the most common internet-based cyber threats. It focuses on practical technical controls rather than complex policy documents alone. For small and medium-sized businesses, it provides a clear, achievable baseline for reducing risk and demonstrating that cyber security is being taken seriously.

What is Cyber Essentials certification?

Cyber Essentials certification shows that an organisation has put essential cyber security controls in place across the systems and devices within its agreed scope. The scheme is supported by the National Cyber Security Centre and administered through authorised certification bodies.

It is not a guarantee that a business can never suffer a cyber incident. No certification can offer that. Instead, it tests whether an organisation has addressed a set of common weaknesses that attackers routinely exploit, such as unpatched software, weak access controls and poorly configured devices.

The certification is particularly useful when a supplier, client or public-sector buyer needs confidence that basic cyber hygiene is in place. Some Government contracts require Cyber Essentials as a condition of bidding, especially where suppliers handle certain categories of sensitive information or provide services connected to Government systems.

For many businesses, its value is broader than procurement. Preparing for certification can expose everyday issues that are easy to overlook: former staff accounts still active, unsupported computers, inconsistent software updates or remote workers using unmanaged devices.

The five technical controls behind the scheme

Cyber Essentials is built around five areas of technical control. They are straightforward in principle, but the detail matters because controls need to work consistently across the organisation, not only on a few office computers.

Firewalls and internet gateways

A firewall helps control traffic entering and leaving a network or device. Businesses need to ensure routers, firewalls and internet-connected equipment are securely configured, using strong administrator credentials and avoiding unnecessary exposure to the internet.

This applies whether staff work from a single office, several sites or from home. A business broadband connection, cloud firewall and remote-working setup should be considered as part of the overall security picture.

Secure configuration

Devices and software should be configured to reduce unnecessary risk. That means removing or disabling unused accounts and services, changing default passwords, and setting devices up so that staff can work without having more access than they need.

Secure configuration is often where older technology causes difficulty. A legacy application may rely on outdated settings, while a shared PC may have been set up with convenience rather than security in mind. These issues do not always prevent certification, but they must be understood and managed appropriately.

User access control

People should only have access to systems, files and administration tools required for their role. Administrator privileges should be tightly controlled, and accounts must be removed or disabled promptly when someone leaves.

This is not just an IT task. Joiner, mover and leaver processes need involvement from managers, HR and whoever is responsible for payroll or staff records. A reliable process prevents former employees, contractors or shared accounts becoming a route into business systems.

Malware protection

Organisations need suitable protection against malicious software. This may include anti-malware tools, device management, application controls and measures that prevent unsafe downloads or unapproved software from running.

The right approach depends on the devices in use. A managed Windows laptop estate, Apple devices, mobile phones and servers may be protected in different ways. The key is being able to show that protection is active, current and appropriately managed.

Security update management

Software updates fix known security vulnerabilities. Cyber Essentials requires organisations to keep operating systems, applications, browsers, firewalls and other in-scope technology supported and updated within defined timescales where serious vulnerabilities are identified.

This requirement often has the greatest operational impact. If a line-of-business system cannot run on a supported operating system, or an old device cannot receive security updates, the business may need a replacement plan, a technical workaround or a carefully defined scope. Delaying that decision can create both certification and security problems.

Cyber Essentials and Cyber Essentials Plus

There are two levels of certification. The right option depends on why you need certification, the assurance expected by customers and the maturity of your IT environment.

Cyber Essentials is based on a self-assessment questionnaire. An authorised certification body reviews the submission and may ask for clarification or supporting information before issuing the certificate. The process requires honest, accurate answers, so it is worth checking the evidence behind each response rather than treating the questionnaire as a tick-box exercise.

Cyber Essentials Plus includes the Cyber Essentials assessment, followed by an independent technical assessment. This typically involves checking a sample of devices, testing for certain external vulnerabilities and verifying that malware protection and update controls operate as stated.

Cyber Essentials Plus offers stronger independent assurance, which can be valuable for organisations handling sensitive information, working with larger supply chains or seeking to differentiate themselves in competitive tenders. It also demands greater preparation. A business with inconsistent device management may find that resolving the underlying issues first is more cost-effective than rushing into assessment.

Both certificates are valid for 12 months. Certification should therefore be treated as part of an ongoing security cycle, not a once-a-year exercise completed just before renewal.

Who needs Cyber Essentials?

Cyber Essentials is relevant to organisations of almost any size, including professional services firms, schools, charities, manufacturers, property businesses and multi-site operations. It is especially helpful where staff use email, cloud applications, remote access, mobile devices or customer data – which now describes most organisations.

A small company with ten employees may use Microsoft 365, laptops and cloud accounting software, while a larger organisation may also operate on-site servers, CCTV, WiFi networks and specialist equipment. The technology differs, but both need a clear view of what is connected, who can access it and how it is kept secure.

Certification can also make supplier conversations easier. Rather than repeatedly explaining your approach to basic cyber controls, you have recognised evidence that a defined standard has been assessed. That said, some customers may require additional standards, contractual controls or evidence relating to data protection. Cyber Essentials is a useful foundation, not a replacement for every wider compliance obligation.

Preparing without disrupting the business

The most effective preparation starts with scope. Identify which legal entity, users, locations, devices, cloud services and networks will be included. It is tempting to keep the scope narrow, but it must accurately reflect the systems relevant to the certification and the services you provide. An artificially limited scope may offer little reassurance to customers and can cause complications during a tender review.

Next, create an up-to-date picture of your technology. This should include laptops, desktops, servers, mobile devices, network equipment, operating systems, key applications and cloud platforms. Many organisations discover they lack a reliable asset list, particularly when devices have been purchased over time or staff work across different locations.

Then review the five controls in practical terms. Are all supported devices receiving updates? Who has administrator access? Are default passwords changed on network equipment? Is multi-factor authentication used where appropriate? Can you prove that protection tools are installed and reporting correctly?

The aim is not to create unnecessary work for staff. Good security should support reliable operations. Central device management, standardised laptop builds, managed updates and clearly defined access processes can reduce helpdesk issues as well as lowering risk.

Where internal IT resource is limited, specialist support can help turn the requirements into a workable plan. iData can assess the existing environment, identify gaps across IT, connectivity and security, and provide practical support without losing sight of day-to-day business needs.

Common misconceptions to avoid

One misconception is that Cyber Essentials only concerns antivirus software. Malware protection matters, but certification also depends on access control, configuration, firewalls and patching. A business can have antivirus installed and still be exposed through an unsupported operating system or an unprotected administrator account.

Another is that cloud services automatically make a business compliant. Cloud providers secure their own platforms, but customers remain responsible for how accounts, users, devices and settings are managed. For example, Microsoft 365 can support strong security, but only if access, multi-factor authentication, devices and user permissions are properly configured.

Finally, certification should not be treated as a document to file away. Staff changes, new software, office moves, acquisitions and remote-working arrangements can all change the risk profile. Keeping a simple record of assets, access and update status makes renewal far less disruptive and gives leaders a more dependable view of operational risk.

Cyber Essentials works best when it becomes part of how technology is selected, installed and supported. Start with an honest view of your current environment, address the gaps that matter most, and build controls that your team can maintain long after the certificate is issued.

« Back to Blog