Quick Answer: Cyber Essentials Certification is the UK government-backed scheme, managed by the National Cyber Security Centre (NCSC) and administered by the IASME Consortium, that protects organisations against approximately 80% of common cyber attacks. Certification starts from £420 + VAT (micro organisations) through our certified partner, with the official IASME assessment fee set between £320 and £600 + VAT depending on organisation size and is mandatory for suppliers bidding on certain government and Ministry of Defence contracts. Two levels exist: Cyber Essentials (self-assessed) and Cyber Essentials Plus (independently verified).
What is Cyber Essentials Certification? (And Why It’s Mandatory for Some)
Cyber Essentials is a Government-backed, industry-supported cyber security certification scheme that was developed by the National Cyber Security Centre (NCSC) and is delivered and administered by the IASME Consortium — the sole licensed delivery partner of the scheme. First introduced in 2014, Cyber Essentials was designed to give UK organisations a clear, practical baseline of cyber security controls to defend against the most common internet-based threats.
The scheme protects data and systems held on networks, computers, servers, tablets, and mobile devices. Unlike ISO 27001, which covers all information in any medium, Cyber Essentials is specifically focused on technical IT infrastructure controls — making it a faster and more affordable entry point for most organisations.
Who Must Have Cyber Essentials Certification?
While not legally mandatory for every business, certification is a contractual requirement in several important contexts:
- Ministry of Defence (MOD) suppliers – Required for all contracts that involve handling sensitive or personal data or delivering IT products and services.
- Central Government contractors – Mandatory for all suppliers bidding on contracts that involve handling personal information or providing certain technical services.
- Education sector (2024/25 funding) – Schools and colleges applying for certain DfE funding streams must demonstrate Cyber Essentials certification.
- NHS and healthcare suppliers – Many NHS procurement frameworks require Cyber Essentials as a minimum baseline.
- Charity sector – The Cyber Essentials for Charities programme makes certification accessible to eligible non-profits.
Beyond contractual obligations, UK GDPR compliance expects organisations to implement “appropriate technical measures” to protect personal data. Achieving Cyber Essentials certification is a strong, demonstrable way to evidence this under Article 32 of the UK GDPR.
The 5 Technical Controls of Cyber Essentials [Updated for v3.2 – April 2025]
Cyber Essentials is built around five technical controls. The current version is v3.2 (Willow), effective from April 2025, which introduced updated definitions around “remote working” (previously “home working”) and replaced the term “plugins” with “extensions” across browser-related controls. Here is what each control requires:
1. Firewalls – Protecting Your Network Perimeter
A boundary firewall or internet gateway must be in place to create a buffer between the internet and your internal network. Under Cyber Essentials requirements, every device that connects to the internet — including home routers used for remote working — must be protected by a properly configured firewall. Key requirements include:
- Only necessary network ports and services are exposed to the internet.
- Default passwords on firewalls and routers must be changed.
- Firewall rules must be documented and regularly reviewed.
- Software firewalls must be enabled on all devices that are in scope but not behind a network-level firewall (e.g., laptops used remotely).
2. Secure Configuration – Stripping Away the Unnecessary
All computers, network devices, and software must be configured to reduce the attack surface. This control directly targets the risk of systems being compromised through default or insecure settings. Organisations must:
- Remove or disable software, accounts, and services that are not required.
- Change all default credentials — a leading cause of breaches, as noted by phishing and social engineering attacks.
- Disable auto-run features for removable media.
- Ensure that only necessary browser extensions (previously called “plugins” under v3.1) are installed and that they come from a known, reputable source.
3. User Access Control – The Principle of Least Privilege
Users must only be given access to the systems and data they actually need to do their jobs — known as the Principle of Least Privilege. The NCSC specifically requires that:
- Standard (non-admin) user accounts are used for day-to-day activities.
- Administrator accounts are strictly controlled and are only used when administrative tasks are being performed.
- Multi-Factor Authentication (MFA) is mandatory for all cloud services (such as Microsoft 365, Google Workspace, and AWS) that are in scope — a key update from the v3.1 Montrose requirements.
- MFA is required for all remote access to the organisation’s network.
- Accounts of staff who leave the organisation are disabled or removed promptly.
4. Malware Protection – Defending Against Malicious Software
Organisations must have active protection against malware on all devices in scope. Cyber Essentials accepts three approaches, and organisations must implement at least one:
- Signature-based anti-malware software that is kept up to date and actively scanning.
- Application allowlisting — where only approved applications are permitted to run (a higher-assurance approach).
- Sandboxing — where code is executed in an isolated environment before being allowed to run on the device.
On mobile devices and in cloud environments, built-in platform protections (such as Apple iOS or Android) may satisfy this control if configured correctly.
5. Patch Management – The 14-Day Rule
All software and firmware must be kept up to date to fix known security vulnerabilities. This is one of the most specific and enforceable requirements in the Cyber Essentials scheme:
- Critical and high-severity patches must be applied within 14 days of release — this is a hard rule under both v3.1 and v3.2.
- Software that is no longer supported by the vendor (i.e., “end-of-life” software) must be removed from in-scope devices or placed behind a compensating control.
- All operating systems, applications, and browser extensions must be patched.
- Auto-update settings should be enabled wherever possible.
Cyber Essentials vs. Cyber Essentials Plus: Key Differences

Cyber Essentials
Cyber Essentials is ideal for smaller organisations, those new to the scheme, and those bidding on contracts that specify basic Cyber Essentials compliance. It gives you protection, credibility, and access to free cyber insurance — all at a lower cost and with a faster turnaround.

Cyber Essentials Plus
Cyber Essentials Plus is the higher-assurance option. Because an accredited third-party assessor independently verifies your controls through hands-on technical testing — including internal network scans and workstation audits — it carries significantly more weight with larger public sector clients and in higher-risk procurement environments. Many NHS frameworks and Tier 1 defence supply chains require Cyber Essentials Plus specifically.scribing your block.
Both certifications cover the same five technical controls, but the level of verification differs significantly. The right choice depends on your organisation’s risk profile, the tenders you are pursuing, and your budget.
| Feature | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Verification Method | Self-assessment questionnaire (SAQ), reviewed by a Certification Body | Independent technical audit by an accredited assessor |
| External Vulnerability Scan | ✅ Included | ✅ Included (more extensive) |
| Internal Vulnerability Scan | ❌ Not included | ✅ Included |
| On-Site Assessment | ❌ Not included | ✅ Workstations & mobile devices |
| Level of Assurance | Good – suitable for most SMEs and standard tenders | High – required for higher-value or higher-risk contracts |
| Typical Timeline | 1–5 days (self-assessment + SAQ review) | 1–3 weeks (including audit scheduling) |
| Cost | £320–£600 + VAT (assessment fee only) | Assessment fee + additional auditor fees (varies) |
| Badge Displayed | Cyber Essentials badge | Cyber Essentials Plus badge |
| Free Cyber Insurance | ✅ (UK orgs, turnover under £20m) | ✅ (UK orgs, turnover under £20m) |
How Much Does Cyber Essentials Certification Cost in 2025?
The cost of Cyber Essentials certification is determined by the IASME Consortium using an official tiered pricing structure based on the number of employees in your organisation. These rates, effective from April 2024 and continuing into 2025, are the assessment fees charged by the Certification Body for the self-assessment questionnaire (SAQ) and external vulnerability scan:
🧮 Cyber Essentials Package Finder
Step 1: Select your organisation size
Cyber Essentials Pricing: Partner Packages via IT Governance
Our certified partner IT Governance — one of the founding Cyber Essentials Certification Bodies and one of the UK’s largest — offers fixed-price packages that include the IASME assessment fee plus additional expert support. The packages are structured around three levels of help:
| Package | What’s Included | Price (ex. VAT) | Best For |
|---|---|---|---|
| CE – Do It Yourself | Certification + SAQ review + external scan + free cyber insurance | From £420 (Micro) to £775 (Large) | Experienced teams, renewals |
| CE – Get A Little Help | As above + 2 hours’ remote consultancy (year 1) | From £720 (Micro) | Organisations needing SAQ guidance |
| CE – Get A Lot Of Help | As above + 1 full consultancy day (remote or on-site, year 1) | From £1,420 (Micro) | First-timers, complex structures |
| CE + CE Plus – Do It Yourself | Both certifications: SAQ + external scan + internal scan + on-site/remote audit | From £2,055 (Micro) | Confident teams needing both certs |
| CE Plus – Get A Little Help ⭐ | Both certs + 2 hours’ consultancy (year 1) + pre-test call | From £2,355 (Micro) | Most popular for Plus certification |
| CE Plus – Get A Lot Of Help | Both certs + 1 full consultancy day (year 1) + pre-test call | From £3,055 (Micro) | Complex organisations new to CE Plus |
Note on IASME base fees: The official IASME assessment fee — which is the same regardless of provider — sits within each package price above. Standalone, the IASME fee is £320 (Micro), £440 (Small), £500 (Medium), or £600 (Large) + VAT. The difference between the IASME fee and the package price reflects IT Governance’s additional services, portal access, and expert support.
All packages from IT Governance include free £25,000 cyber liability insurance for UK organisations with a turnover under £20m, same-day turnaround on Cyber Essentials assessments, a 98% customer success rate, and two attempts to pass included as standard.
CYBER ESSENTIALS

The Cyber Essentials certification process includes a self-assessment questionnaire (SAQ) and an external vulnerability scan. This ensures that best practice is in place and that there are no known vulnerabilities present on the Internet-facing networks and applications. Packages start from £420 + VAT for micro organisations and scale by organisation size.
CYBER ESSENTIALS PLUS

Cyber Essentials Plus certification includes all of the assessments for the Cyber Essentials certification, plus an additional internal scan and an on-site or remote assessment of your infrastructure, specifically focusing on workstations and mobile devices. Packages start from £2,055 + VAT for micro organisations.
Step-by-Step Guide to Getting Cyber Essentials Certified
The Cyber Essentials certification process is straightforward when approached in the right order. Here is how to achieve certification efficiently:
- Define Your Scope – Determine which devices, systems, and locations are “in scope.” Under v3.2, this includes any device used for work, including personal devices (BYOD), home routers used for remote working, and cloud services used by the organisation. Scoping correctly is critical — over-scoping increases cost and complexity; under-scoping risks failing the assessment.
- Download the Question Set – The latest version of the Cyber Essentials self-assessment questionnaire is available from the IASME Consortium website. Always ensure you are working from the current version (v3.2, effective April 2025).
- Conduct a Gap Analysis – Review your current cyber security posture against the five technical controls. A qualified Cyber Advisor or GDPR/cyber security consultant can help you identify vulnerabilities and prioritise remediation. This is also a valuable step for evidencing compliance with the data security principle under UK GDPR.
- Remediate Any Gaps – Address any control weaknesses identified in the gap analysis. Common quick wins include enabling MFA on cloud accounts, patching out-of-date software, changing default router passwords, and reviewing user account privileges.
- Complete and Submit the SAQ – Submit your completed self-assessment questionnaire through a licensed Certification Body (such as IT Governance). The Certification Body will review your answers, conduct an external vulnerability scan of your internet-facing infrastructure, and issue your certificate if you pass.
- Cyber Essentials Plus Only – Technical Audit – If you are pursuing the Plus level, an accredited assessor will also conduct an internal vulnerability scan and an on-site (or remote) audit of your workstations and mobile devices to verify the controls are operating as stated.
- Receive Your Certificate and Badge – Upon passing, you will receive your Cyber Essentials certificate, which is valid for 12 months, and the right to display the badge on your website, tenders, and marketing materials.
Free Cyber Insurance: Are You Eligible?
One of the most underrated benefits of Cyber Essentials certification is that UK-based organisations with an annual turnover of under £20 million automatically receive a free cyber liability insurance policy upon achieving certification. This is provided by IASME’s insurance partner and typically includes:
- Cyber liability indemnity cover (usually up to £25,000)
- Coverage for first-party losses from cyber attacks
- Access to an incident response helpline
This insurance is included in the assessment fee and activates automatically once your certificate is issued — there is no separate application process. For larger organisations (turnover above £20m), commercial cyber insurance is available separately and many insurers now offer preferential rates to Cyber Essentials certified businesses.
The increasing risks associated with remote working make this free cover particularly valuable for smaller organisations whose staff connect from home networks — a scenario now explicitly captured under the v3.2 “remote working” scope.
Cyber Essentials and UK GDPR: The Critical Link
For organisations that handle personal data — which includes virtually every UK business — Cyber Essentials and UK GDPR compliance are deeply connected. Under Article 32 of the UK GDPR (“Security of Processing”), organisations are legally required to implement “appropriate technical and organisational measures” to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Achieving Cyber Essentials certification provides documented, verifiable evidence that you have implemented technical security controls appropriate to your risk level. The five technical controls map directly onto the ICO’s expectations under Article 32:
- Firewalls → Controls unauthorised access to systems holding personal data
- Secure Configuration → Reduces vulnerabilities that could lead to a personal data breach
- User Access Control + MFA → Prevents unauthorised access to personal data, particularly relevant for cloud-stored data
- Malware Protection → Defends against ransomware and data-stealing malware — a primary cause of reportable personal data breaches
- Patch Management → Closes known vulnerabilities before they can be exploited to access personal data
In the event of a personal data breach investigation, a current Cyber Essentials certificate is a meaningful mitigating factor when demonstrating to the ICO that you had appropriate technical measures in place. Without it, organisations may find it difficult to evidence their compliance with Article 32 — particularly if the breach arose from one of the five control areas that Cyber Essentials directly addresses.
For a comprehensive understanding of your broader UK GDPR obligations, see our guide to the UK GDPR data protection principles and our article on GDPR fines and penalties. If you are comparing Cyber Essentials with a broader information security framework, our ISO 27001 and GDPR guide covers the key differences in detail.
Benefits of Cyber Essentials Certification
- Demonstrable cyber security posture – Show customers, partners, and insurers that your organisation has independently verified technical controls in place to protect their data.
- Reduced risk of common attacks – The NCSC estimates that implementing the five controls can prevent up to 80% of the most common cyber attacks, including phishing, ransomware, and exploitation of known vulnerabilities.
- Win more business – Cyber Essentials certification is now a specified requirement in many public sector tenders, MOD contracts, and NHS procurement frameworks. Without it, your organisation is ineligible to bid.
- Free cyber insurance – UK organisations with a turnover under £20m receive automatic cyber liability cover upon certification.
- UK GDPR Article 32 evidence – Provides documented proof of appropriate technical security measures, directly supporting UK GDPR compliance.
- Supply chain confidence – If you work with larger organisations, many now require their suppliers to be certified to demonstrate that sensitive data shared across the supply chain is adequately protected.
Cyber Essentials Certification FAQs
Is Cyber Essentials mandatory?
Cyber Essentials is not mandatory for all businesses, but it is a contractual requirement in specific situations. Any supplier bidding on UK government or Ministry of Defence contracts that involve handling personal information or delivering IT products and services must hold a valid Cyber Essentials certificate. It is also required for certain DfE education sector funding streams and is widely specified in NHS procurement frameworks. Even where it is not mandatory, it is increasingly expected as a baseline in B2B supply chains.
How long does Cyber Essentials certification last?
Cyber Essentials certification is valid for 12 months from the date of issue. Organisations must renew annually to maintain their certified status, continue displaying the badge, and retain access to the free cyber insurance benefit (where eligible). Annual renewal also ensures your controls are reviewed against the latest version of the question set, including any updates such as the v3.2 changes effective April 2025.
How long does the certification process take?
For Cyber Essentials (self-assessment), the process typically takes between 1 and 5 working days from submitting a complete and accurate self-assessment questionnaire to receiving your certificate, once the Certification Body has completed their review and external vulnerability scan. For Cyber Essentials Plus, the process takes longer — usually 1 to 3 weeks — due to the scheduling of the technical audit by an accredited assessor.
Do remote workers need to be included in the scope?
Yes. Under the v3.2 (Willow) requirements effective from April 2025, the previous term ‘home working’ has been broadened to ‘remote working,’ and any device used to connect to organisational systems or handle work data from any location outside the office must be in scope. This includes laptops and PCs connecting via home broadband routers. Home routers used for remote working must be protected by a correctly configured firewall, and default credentials must be changed.
What is the v3.2 April 2025 update to Cyber Essentials?
The v3.2 (Willow) update, effective from April 2025, introduced two main changes. First, the terminology ‘home working’ was replaced with ‘remote working’ to reflect the broader reality of how and where people now work. Second, the term ‘plugins’ (used in browser and software contexts) was replaced with ‘extensions,’ aligning with how modern browsers and application ecosystems describe these add-ons. Organisations renewing their certification in 2025 should ensure they are working from the v3.2 question set available via the IASME Consortium.
Is Cyber Essentials an international standard?
Cyber Essentials is a UK government-backed scheme developed by the National Cyber Security Centre (NCSC) and is not an international standard in the same sense as ISO 27001. However, it is recognised internationally, and organisations outside the UK can pursue certification. For internationally operating organisations or those seeking a more comprehensive information security management standard, ISO 27001 may be a more appropriate framework — though many UK organisations hold both certifications.
What is the difference between ISO 27001 and Cyber Essentials?
The key difference is scope and depth. ISO 27001 is a comprehensive information security management system (ISMS) standard that covers all information in any form or medium and requires an organisation-wide risk management approach. Cyber Essentials, by contrast, focuses specifically on five technical IT controls for systems connected to the internet. ISO 27001 is not required for working with the UK public sector (Cyber Essentials is), but ISO 27001 is generally seen as a more rigorous and internationally recognised standard. Many organisations use Cyber Essentials as the baseline and ISO 27001 as the next step. See our detailed comparison in our ISO 27001 and GDPR guide.
Is Cyber Essentials Plus worth it?
For most organisations, Cyber Essentials Plus is worth the additional investment if you are bidding on higher-value contracts, operating in regulated sectors (healthcare, defence, finance), or want the highest available level of assurance that your controls are genuinely effective. The independent technical audit by an accredited assessor provides assurance that goes beyond self-declaration, which is increasingly important in supply chain due diligence. If your primary goal is meeting a baseline tender requirement or evidencing UK GDPR Article 32 compliance, standard Cyber Essentials may be sufficient.
Who qualifies for free cyber insurance with Cyber Essentials?
UK-based organisations with an annual turnover of under £20 million are eligible for a complimentary cyber liability insurance policy that activates automatically upon achieving Cyber Essentials certification. The cover is provided by IASME’s insurance partner and typically includes up to £25,000 of cyber liability indemnity. There is no separate application — the insurance is issued as part of the certification process.
This page contains links to courses provided by a third party. When you purchase a course via our links we may earn a small commission at no extra cost to you. We only recommend courses we have reviewed and believe provide genuine value for UK organisations seeking to meet their GDPR and cyber security obligations.

