Cyber Essentials: what it actually involves, and why customers keep asking for it
Cyber Essentials has gone from a nice-to-have to the thing that decides whether you can bid. Here's what the five controls are, what the process looks like, and where businesses usually trip up.

If you've bid for a public sector contract or filled in a larger customer's supplier questionnaire in the last couple of years, you've been asked about Cyber Essentials. Increasingly you're not being asked whether you have it, you're being told you need it. This is what it is, in plain terms.
What it is
Cyber Essentials is a government-backed certification run by the National Cyber Security Centre. It sets out five basic controls that stop the large majority of common, untargeted attacks. It's deliberately not exotic. The point is to prove your business has the basics in place and keeps them there.
There are two levels. Cyber Essentials is a self-assessment, verified by an assessor. Cyber Essentials Plus adds a technical audit where someone actually tests your devices. Plus is what larger customers and most public bodies now want.
The five controls
- Firewalls: every connection to the internet goes through a properly configured firewall, and the default passwords have been changed.
- Secure configuration: devices and accounts are set up with unnecessary features removed and sensible passwords enforced.
- Access control: people have the access they need for their job and no more, and administrator accounts are separate from day-to-day ones.
- Malware protection: every device is protected and kept up to date.
- Patch management: security updates are applied within 14 days of release. This is the one most businesses fail on.
Where businesses trip up
The scope. Cyber Essentials covers every device that accesses your business data, including the personal phones people read email on. If you've never thought about that, you're not alone, and it's usually the first thing an assessment turns up.
Old kit. A laptop running software the manufacturer no longer supports is an automatic fail. Finding those and replacing them is often the longest part of the job.
Admin accounts. Someone in accounts having administrator rights because it was easier five years ago. Untangling that without breaking their workflow takes care.
How long it takes and what it costs
For a business of ordinary complexity, four to eight weeks from starting the gap analysis to holding the certificate. The assessment fee itself is a few hundred pounds; the real cost is fixing what the gap analysis finds, which varies enormously. A business that already has managed IT support with security included will usually have very little to fix. One that has been running on goodwill and an old server will have more.
The certificate lasts a year. The renewal is much quicker if the controls have been maintained, and much like the first time if they haven't.
Is it worth it?
If a customer or a framework requires it, the question answers itself. Beyond that: it often lowers cyber insurance premiums, it gives you a straight answer to every supplier questionnaire, and the controls themselves stop the attacks that actually hit small businesses, which are overwhelmingly the boring, automated ones the five controls are designed against.
What we do
We take clients from gap analysis to certificate, and then handle the renewal each year so it never becomes a scramble. For clients on our managed support, most of the controls are already in place as part of the service, and certification is mostly evidence. If you'd like to know where you'd stand today, the free audit will tell you.
