Journal

Article · Elated Consulting

Cyber Essentials: A Plain-English Guide for UK Businesses

What Cyber Essentials is, why contracts and insurers increasingly demand it, the five controls it checks, what certification costs, and how to pass first time.

If a client contract, tender, or insurance renewal has just asked whether you hold Cyber Essentials, this guide is for you. No jargon, just what it is, what it costs, and how to pass.

What is Cyber Essentials?

Cyber Essentials is the UK government-backed certification scheme, run by the National Cyber Security Centre through IASME, that verifies your business has basic protections in place against the most common cyber attacks. It comes in two levels: Cyber Essentials, a verified self-assessment, and Cyber Essentials Plus, which adds an independent technical audit of your systems.

Why businesses get certified

  • Contracts require it. Central government contracts involving personal data mandate it, and larger private-sector clients increasingly copy that requirement into their supply chains.
  • Insurance. Cyber insurers ask about unsupported systems, and a claim involving one may be challenged.
  • It genuinely reduces risk. The five controls are aimed at the attacks that actually hit small businesses, not theoretical ones.

The five controls, in plain terms

  1. Firewalls: a properly configured boundary between your network and the internet.
  2. Secure configuration: default passwords changed, unused software and accounts removed.
  3. Access control: people only have the access they need, and admin accounts are protected.
  4. Malware protection: up-to-date protection on every device.
  5. Patch management: operating systems and software updated promptly, with unsupported software removed.

What it costs and how long it takes

The self-assessed certification starts from around £320 plus VAT depending on the size of your organisation, and renewal is annual. Cyber Essentials Plus costs more because an assessor tests your systems directly. For a well-prepared small business, the self-assessment can be completed in days; the preparation is where the real work lives.

Where businesses fail

The same findings come up again and again: unsupported operating systems still in use, no multi-factor authentication on cloud accounts, staff running as administrators day to day, and nobody able to say confidently which devices access company data. None of these are hard to fix, but they all need doing before you submit, because the assessment covers every device that touches your data, including home machines used for work.

How we help

We take businesses through the whole journey: a gap assessment against the five controls, fixing what needs fixing, completing the submission, and keeping you compliant year round so renewal is a formality rather than a scramble. If certification has landed on your desk with a deadline attached, get in touch and we will map out exactly what your pass requires.

IT SupportSecurityCompliance