Cyber attacks are a real threat to organisations of all sizes. Cyber Essentials UK is a government-backed scheme designed to protect businesses from the most common online threats. Whether you’re an SME, supplier, or organisation bidding for government contracts, gaining this certification can significantly enhance your cyber security posture and credibility.
What Is Cyber Essentials UK?
Cyber Essentials UK is a UK government-supported scheme overseen by the National Cyber Security Centre (NCSC) and delivered via bodies like the IASME Consortium.
It is built around five technical controls intended to prevent common cyber threats. The most basic “level” is self-assessment, adding a higher assurance level with Cyber Essentials Plus.
Cyber Essentials vs Cyber Essentials Plus
| Feature | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment Type | Self-assessment questionnaire, submitted and verified by a cyber essentials assessor. | All that Cyber Essentials has, plus a technical audit of IT infrastructure (including internal & external vulnerability scanning, hands-on tests, proofs). |
| Level of Assurance | Moderate – ensures baseline security, but relies on your answers. | Higher – includes verification of actual implementation. |
| Cost | Lower cost (tiered by org size) for basic level Cyber Essentials cost. | Significantly higher due to extra testing, assessor or auditor involvement, more complexity. |
| Use Cases | Good for demonstrating baseline compliance, entering government contracts that require basic certification. | Needed when contracts or clients demand greater assurance, handling more sensitive information. |
Requirements for IT Infrastructure
To get certified, organisations must comply with a set of technical controls. Here are the major Cyber Essentials requirements for IT infrastructure:
- Firewalls & Boundary Security: ensure internet-connected systems are protected, routers configured safely.
- Secure Configuration: change default settings, disable unnecessary services, limit unused or outdated software.
- Access Control: least privilege access, separate admin accounts, strong authentication.
- Malware Protection: anti-malware tools, regular updates, monitoring.
- Security Update / Patch Management: timely patching of vulnerabilities, especially critical or high severity ones.
Recent updates (such as around version 3.2 “Willow”) have added stricter requirements, faster remediation windows for high/critical vulnerabilities, and clarified cloud services / remote working controls.
Cyber Essentials Certification Costs
Understanding the Cyber Essentials certification cost helps in planning. There are two parts: the basic Cyber Essentials, and then Cyber Essentials Plus which is more expensive.
Cost of Cyber Essentials (basic)
Here are typical fees based on organisation size, according to URM Consulting.
| Organisation Size | Cost (basic) + VAT |
|---|---|
| Micro (0-9 employees) | £320 |
| Small (10-49) | ~ £440 |
| Medium (50-249) | ~ £500 |
| Large (250+ employees) | ~ £600 |
Cost of Cyber Essentials Plus
Cyber Essentials Plus cost is significantly higher because of the hands-on testing, audits, vulnerability scans, etc.
For example, one provider quotes:
- ~ £1,650 for up to 9 users
- ~ £2,250 for 10-49 users
- ~ £3,250 for 50-249 users
- ~ £4,250+ for 250 or more
These vary depending on the complexity of your IT infrastructure, how many assets/devices, number of locations, and level of existing security maturity. Hidden costs may include consultant support, remediation of deficiencies, staff training, etc.
Certification Process
Here’s how the process generally works:
- Determine scope: which systems/devices/offices/users are in scope for the certification.
- Self-assessment questionnaire: basic level requires filling out and signing off a questionnaire. Must be signed by board member or equivalent. A Cyber Essentials assessor (via an accredited Certification Body) will review.
- Assessor review: the assessor checks your answers. If any feedback or corrections are needed, you’ll get them and may resubmit.
- Plus level audit / technical verification: for Cyber Essentials Plus, after the basic level, additional technical tests (vulnerability scanning, internal & external assessments).
- Certificate awarding: once passed, you receive the Cyber Essentials certificate, valid for 12 months. You can download it, also get guidance on how to display the Cyber Essentials logo or Cyber Essentials certified logo.
- Annual renewal: you have to re-assess every year to renew. If you don’t re-certify, the certificate expires and you’ll be removed from official registers.
Certificate Search, Lookup & Verification
Sometimes clients or partners will want to verify your status. Here are the tools and terms you should know:
- Certificate Check / Cyber Essentials certificate check: confirming the certificate is valid, not expired.
- Cyber Essentials certification check / certificate search: using official directories (e.g. IASME, NCSC) or via portal to see if an organisation is listed.
- Cyber Essentials lookup / register: organisations certified are listed in a public register so others can verify.
It’s good practice to give partners your certificate and direct them to check via the official register so that they can verify everything, especially for tenders.
Logos and Branding
Once certified, you’ll have rights to use approved logos to show your status. Key points:
- Cyber Essentials logo and Cyber Essentials Plus logo are branding assets issued by the certification body. You must follow the guidance on usage.
- Cyber Essentials certified logo is typically available with your certificate and may have specifications (size, colour, placement).
- Always ensure your certificate is valid when using the logo; the branding guidance will require that.
- Logos are useful for marketing, proposals, website, email signatures etc., to show trust.
Benefits of Cyber Essentials UK
Here are reasons why investing in Cyber Essentials UK is worthwhile:
- Eligibility for many government contracts requires having a valid Cyber Essentials certificate.
- Demonstrates to customers, partners, suppliers that you take cyber security seriously.
- Helps with cyber essentials insurance; some insurers provide better terms or discounts if you’re certified. Also, certification can reduce risk of insurance claims.
- Reduces risk from common cyber threats by following baseline controls.
- May boost reputation and competitive advantage.
Cyber Essentials Checklist
Before you apply, ensure you have these in place:
- Asset inventory: list of devices, users, software, cloud systems.
- Firewalls configured properly, boundary security in place.
- Secure configuration: disable default accounts, remove unnecessary services.
- Strong access controls: least privilege, separate admin accounts, enforcing secure passwords / multi-factor authentication.
- Malware protection: anti-malware tools installed and updated.
- Patch management in place: ensure critical patches are applied quickly. (Under newer rules, high/critical vulnerabilities must be remediated within 14 days in many cases.)
- Internal policies and roles defined (who is responsible), and sign-off from senior management.
- Prepare for evidence and possibly technical tests (for Plus level).
How Much Value Do You Get? Is It Worth It in 2025?
Given the costs and effort, is obtaining Cyber Essentials UK worth it?
- For most small to medium organisations, yes, it’s a relatively low cost and offers substantial risk reduction.
- If you’re entering tenders for government contracts, supply chains, or regulated sectors, basic certification may be required; Plus gives a stronger assurance.
- For organisations with complex infrastructure, high security needs, or regulatory oversight, the extra cost of Cyber Essentials Plus is often justified.
- Also, with evolving threats and tighter requirements (e.g. “Willow”), maintaining controls continuously is becoming more important and business value increases as compliance becomes baseline.
Frequently Asked Questions (FAQs)
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment (questionnaire), verified by an assessor. Plus adds technical audits / vulnerability scanning to verify the implementation.
How much does Cyber Essentials cost?
For basic level, costs typically range from £320 for micro orgs up to £600 for large orgs. Plus level costs vary significantly but can start in the thousands depending on complexity.
How do I check if a company is Cyber Essentials certified?
Use the official Cyber Essentials register / lookup (such as via IASME or NCSC) to perform a certificate search / certification check.
Is Cyber Essentials mandatory?
Not by law for most businesses, but often required in public sector contracts and by clients or suppliers in supply chains.
Can being Cyber Essentials certified affect insurance?
Yes. Some insurers offer better premiums or require it for coverage (“cyber essentials insurance”). Certification lowers risk of common attacks and can help in claims.
Conclusion
Certification under Cyber Essentials UK is a solid investment in cyber security. It provides a clear path to baseline security, helps win trust and contracts, and can reduce risk and cost associated with cyber incidents.
If your organisation is preparing for this, focus first on ensuring the technical controls are in place (firewalls, access control, patching etc.), then work with a Cyber Essentials assessor and choose the appropriate level (basic vs Plus). The cost of doing it well is far less than the cost of recovering from a breach or being excluded from tenders.
Contact us today for any queries or concerns you may have about getting Cyber Essentials registered!
This might also be interesting to you: Cyber Insurance UK: 16 Things for SMBs to Know