Every business in the UK is a potential target for cybercriminals. Why? Because every organisation, regardless of size, industry, product or service offering, possesses valuable assets that are attractive to attackers. Whether it’s customer data, credit card details, intellectual property, to less obvious items such as operational documents or client work, the consequences of lost, corrupt, or stolen information can be devastating – ranging from revenue loss and diminished customer trust to, in the worst cases, closure of the business.
This article explores what Cyber Essentials certification is, why it is crucial for every organisation to safeguard against cyber threats, and how Cyber Essentials helps businesses protect their data, enhance resilience, and unlock opportunities for growth.
So, what is Cyber Essentials certification?
Cyber Essentials is a government-backed certification, delivered by IASME on behalf of the NCSC, that helps organisations put in place the technical controls that stop the most common internet-based cyber attacks.
Why does Cyber Essentials matter?
Every business is a target because every business has something to lose. In the past, cybercriminals focused on large organisations in industries like financial services or pharmaceuticals, where the potential payoff – banking details or intellectual property –was substantial.
Today, the threat landscape has shifted. Attackers have become more sophisticated, and tools for initiating attacks are widely accessible. Small and medium-sized enterprises (SMEs), often with weaker security measures, have become prime targets. Why target a massive corporation with top-notch security that would require substantial skill and sophisticated tools to get around when you could target an SME with less impressive security? Infect their systems with malware, encrypt their documents and spreadsheets, putting a stop to them trading and then demanding payment for the encryption key?
The reality of the cyber threat
The need for cyber resilience is backed by the facts – according to the Cyber Security Breaches Survey 2024:
- 43% of UK businesses identified a cyber security breach or attack in the last 12 months – around 612,000 organisations..
- For medium and large businesses the figures rise to 65% and 69% respectively.
What changed in 2026
Danzell · 27 April 2026Cyber Essentials moved to a new question set on 27 April 2026. If you last certified before then, three changes matter most.
Multi-factor authentication is now mandatory
MFA must be enabled on every cloud service that offers it, including free tiers and services you may not think of as cloud, such as email, file sharing and CRM tools.
There is no partial credit here. One service without MFA fails the whole assessment.
Critical updates within 14 days
High-risk and critical security updates must be applied within 14 days. Two questions cover this, A6.4 and A6.5, and both now fail you outright.
Previously these were major non-compliances rather than automatic fails.
Cloud services cannot be excluded
Any internet-connected device is in scope, whether it accepts incoming connections or only makes outbound ones. Scope descriptions are now unlimited in length and exclusions must be documented.
A cloud service is defined as "an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet".
The bigger shift sits behind all three: an organisation could previously still certify with up to two major non-compliances against its name. Under Danzell, the items above fail the assessment on their own.


How Cyber Essentials helps
Cyber Essentials outlines fundamental technical controls to mitigate risk, including:
Through a straightforward self-assessment process, businesses can ensure these controls are in place, making them a less attractive target for attackers.
The importance of Cyber Essentials certification
Cyber-attacks can devastate businesses, affecting operations, revenue, and reputation. Beyond disrupted workflows and financial loss, the long-term damage – diminished customer trust and tarnished brand reputation – can lead to declining revenue or even closure. Fines for failing to meet regulatory requirements, such as GDPR, add another layer of risk.
Key benefits of Cyber Essentials certification
Supporting statistics
- 91% of Cyber Essentials users say it boosts confidence in reducing cyber security risks (Cyber Essentials impact evaluation for 2024)
- 80% report improved customer confidence.
- Over one-third of businesses find Cyber Essentials mandated by clients or partners in contracts – not just for government and public sector bids – stating ‘all contracts they entered into over the preceding 12 months required them to be Cyber Essentials certified’.
With all that in mind, how does a business become Cyber Essentials certified?


Steps to getting Cyber Essentials certification
Obtaining Cyber Essentials certification is a straightforward process, involving four key steps: scoping, completing a questionnaire, addressing security gaps, and submitting your application. With professional guidance, the process becomes even smoother.
-
1
Define your scope
Decide what the certificate covers. Cloud services can no longer be excluded, and any internet-connected device is in scope whether it accepts incoming connections or only makes outbound ones.
-
2
Complete the self-assessment
Answer the Danzell question set against the five controls: firewalls, secure configuration, security update management, user access control and malware protection.
-
3
Close the gaps
Fix what the assessment exposes before you submit. Missing MFA on a cloud service, or critical updates older than 14 days, now fail you outright.
-
4
Submit for certification
Send your assessment to a licensed Certification Body such as RightCue. Fees start at £345+VAT for micro organisations and rise by size band.
Not sure where to start? Our assisted certification service walks you through scoping, the question set and a final review before submission.
Cyber Essentials certification cost: is it worth it?
If you’re considering whether the Cyber Essentials certification is worth it, just consider the financial implications of a data breach, ransomware attack or DDoS attack.
The government’s 2025/26 Cyber Security Breaches Survey puts the cost of most incidents low, a median of near zero, but the tail is expensive: the worst 5% of incidents cost small businesses around £4,000 and medium and large businesses around £10,000. The cost that actually hurts smaller organisations is the disruption, not the fine.
| Organisation size | Self-certification | Certification with assistance |
|---|---|---|
| Micro organisation 0–9 employees | £345 + VAT | £645 + VAT |
| Small organisation 10–49 employees | £475 + VAT | £775 + VAT |
| Medium organisation 50–249 employees | £540 + VAT | £840 + VAT |
| Large organisation 250+ employees | £650 + VAT | £950 + VAT |
Progression: From Cyber Essentials to Cyber Essentials Plus and beyond
In the research commissioned by the UK government and released in the Cyber Essentials impact evaluation for 2024, it was highlighted that slightly more than three-quarters of UK businesses with Cyber Essentials took their security posture a step further by implementing other preventative actions.
Cyber Essentials provides an excellent foundation for businesses to mitigate risk and increase their cyber resilience. It leads to other certifications such as Cyber Essentials Plus and ISO 27001 (information security), depending on the needs of the business.
Key differences between Cyber Essentials and Cyber Essentials Plus
The main difference between Cyber Essentials and Cyber Essentials Plus is that the former relies on a self-assessment, while the latter offers a higher level of assurance by including a technical audit of the technology infrastructure to ensure that the technical controls have been properly implemented, including:
- Internal vulnerability scans
- Testing of in-scope systems
- External IP vulnerability scans
The technical audit is carried out by an independent third-party organisation and looks at a representative set of user devices, all internet gateways, and all servers with services accessible to unauthenticated internet users.
From April 2026, a failed update management test triggers a retest against a fresh random sample of devices, and a second failure revokes the certificate. Selectively patching only the devices under test is prohibited.
Benefits of upgrading to Cyber Essentials Plus
The benefits of upgrading to Cyber Essentials Plus include:


Next step – from Cyber Essentials Plus to ISO 27001
ISO 27001 is the internationally recognised standard for information management security, and is a complementary certification to Cyber Essentials Plus, often building on its foundation. ISO 27001 provides a framework for creating and managing an information security management system (ISMS). The key difference between the two certifications is that ISO 27001 is a more rigorous standard, covering a broader scope than Cyber Essentials Plus.
Here are a few more differences:
- ISO 27001 doesn’t just look at technical controls, but also considers policies, documentation, data, products, processes, services and systems.
- It applies to both physical and digital information assets.
- The certification is also focused on risk management and requires regular internal audits.
- ISO 27001 can be used to comply with legal and regulatory requirements.
The important thing to remember is that the two certifications are complementary and provide a crucial layered approach to building cyber resilience and mitigating risk.
Why Choose RightCue for Cyber Essentials, Cyber Essentials Plus and ISO 27001 certification?
RightCue is an expert in cyber security compliance – with over 15 years’ experience helping organisations achieve certifications, increase cyber resilience and mitigate risk. With that experience comes an intricate understanding of business and what organisations need to succeed when it comes to cyber security. As a cyber security consultancy and Cyber Essentials Certification Body, RightCue is ideally positioned to help you with your compliance journey.



