What is cyber essentials

Every business in the UK is a potential target for cybercriminals. Why? Because every organisation, regardless of size, industry, product or service offering, possesses valuable assets that are attractive to attackers. Whether it’s customer data, credit card details, intellectual property, to less obvious items such as operational documents or client work, the consequences of lost, corrupt, or stolen information can be devastating – ranging from revenue loss and diminished customer trust to, in the worst cases, closure of the business.

This article explores what Cyber Essentials certification is, why it is crucial for every organisation to safeguard against cyber threats, and how Cyber Essentials helps businesses protect their data, enhance resilience, and unlock opportunities for growth.

So, what is Cyber Essentials certification?

Cyber Essentials is a government-backed certification, delivered by IASME on behalf of the NCSC, that helps organisations put in place the technical controls that stop the most common internet-based cyber attacks.

Why does Cyber Essentials matter?

Every business is a target because every business has something to lose. In the past, cybercriminals focused on large organisations in industries like financial services or pharmaceuticals, where the potential payoff – banking details or intellectual property –was substantial.

Today, the threat landscape has shifted. Attackers have become more sophisticated, and tools for initiating attacks are widely accessible. Small and medium-sized enterprises (SMEs), often with weaker security measures, have become prime targets. Why target a massive corporation with top-notch security that would require substantial skill and sophisticated tools to get around when you could target an SME with less impressive security? Infect their systems with malware, encrypt their documents and spreadsheets, putting a stop to them trading and then demanding payment for the encryption key?

The reality of the cyber threat

The need for cyber resilience is backed by the facts – according to the Cyber Security Breaches Survey 2024:

  • 43% of UK businesses identified a cyber security breach or attack in the last 12 months – around 612,000 organisations..
  • For medium and large businesses the figures rise to 65% and 69% respectively.

What changed in 2026

Danzell · 27 April 2026

Cyber Essentials moved to a new question set on 27 April 2026. If you last certified before then, three changes matter most.

Automatic fail

Multi-factor authentication is now mandatory

MFA must be enabled on every cloud service that offers it, including free tiers and services you may not think of as cloud, such as email, file sharing and CRM tools.

There is no partial credit here. One service without MFA fails the whole assessment.

Automatic fail

Critical updates within 14 days

High-risk and critical security updates must be applied within 14 days. Two questions cover this, A6.4 and A6.5, and both now fail you outright.

Previously these were major non-compliances rather than automatic fails.

Scope

Cloud services cannot be excluded

Any internet-connected device is in scope, whether it accepts incoming connections or only makes outbound ones. Scope descriptions are now unlimited in length and exclusions must be documented.

A cloud service is defined as "an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet".

The bigger shift sits behind all three: an organisation could previously still certify with up to two major non-compliances against its name. Under Danzell, the items above fail the assessment on their own.

Malware protection
Security update management

How Cyber Essentials helps

Cyber Essentials outlines fundamental technical controls to mitigate risk, including:

  • Firewalls – Boundary and device firewalls sit between your systems and the internet, blocking unauthorised inbound connections. Default administrative passwords must be changed and any open port justified. 

  • Secure Configuration – Devices and software arrive set up for convenience rather than safety. Unused accounts and applications are removed, default passwords changed, and only what you actually need is left enabled.

  • User Access Controls – Multi-factor authentication is now mandatory on every cloud service where it’s available, including free tiers. Passkeys and FIDO2 authenticators are explicitly covered.

  • Security Update Management – High-risk and critical updates must be applied within 14 days.

  • Malware Protection – Every device in scope needs anti-malware software kept current, or an allow list that only permits approved applications to run.

Through a straightforward self-assessment process, businesses can ensure these controls are in place, making them a less attractive target for attackers.

The importance of Cyber Essentials certification

Cyber-attacks can devastate businesses, affecting operations, revenue, and reputation. Beyond disrupted workflows and financial loss, the long-term damage – diminished customer trust and tarnished brand reputation – can lead to declining revenue or even closure. Fines for failing to meet regulatory requirements, such as GDPR, add another layer of risk.

Key benefits of Cyber Essentials certification

  • Boosts Cyber Resilience: Cyber Essentials helps safeguard against 80% of common cyber threats, strengthening business resilience.

  • Enhanced Credibility and Market Opportunities: Show commitment to protecting stakeholders, making it easier to attract customers, bid on government contracts, and improve trust.

  • Insurance Savings: According to the National Cyber Security Centre’s (NCSC) 2024 annual review, businesses with Cyber Essentials certification are 92% less likely to make an insurance claim, potentially lowering premiums. Take-up is climbing fast in exactly the organisations that set supplier requirements: 35% of large UK businesses now hold Cyber Essentials, up from 21% a year ago.

Supporting statistics

  • 91% of Cyber Essentials users say it boosts confidence in reducing cyber security risks (Cyber Essentials impact evaluation for 2024)
  • 80% report improved customer confidence.
  • Over one-third of businesses find Cyber Essentials mandated by clients or partners in contracts – not just for government and public sector bids – stating ‘all contracts they entered into over the preceding 12 months required them to be Cyber Essentials certified’.

With all that in mind, how does a business become Cyber Essentials certified?

User access controls
penetration testers

Steps to getting Cyber Essentials certification

Obtaining Cyber Essentials certification is a straightforward process, involving four key steps: scoping, completing a questionnaire, addressing security gaps, and submitting your application. With professional guidance, the process becomes even smoother.

  1. 1

    Define your scope

    Decide what the certificate covers. Cloud services can no longer be excluded, and any internet-connected device is in scope whether it accepts incoming connections or only makes outbound ones.

  2. 2

    Complete the self-assessment

    Answer the Danzell question set against the five controls: firewalls, secure configuration, security update management, user access control and malware protection.

  3. 3

    Close the gaps

    Fix what the assessment exposes before you submit. Missing MFA on a cloud service, or critical updates older than 14 days, now fail you outright.

  4. 4

    Submit for certification

    Send your assessment to a licensed Certification Body such as RightCue. Fees start at £345+VAT for micro organisations and rise by size band.

Not sure where to start? Our assisted certification service walks you through scoping, the question set and a final review before submission.

Cyber Essentials certification cost: is it worth it?

If you’re considering whether the Cyber Essentials certification is worth it, just consider the financial implications of a data breach, ransomware attack or DDoS attack.

The government’s 2025/26 Cyber Security Breaches Survey puts the cost of most incidents low,  a median of near zero, but the tail is expensive: the worst 5% of incidents cost small businesses around £4,000 and medium and large businesses around £10,000. The cost that actually hurts smaller organisations is the disruption, not the fine.

All prices exclude VAT. Certification with assistance includes RightCue guiding you through the self-assessment before submission.
Organisation size Self-certification Certification with assistance
Micro organisation 0–9 employees £345 + VAT £645 + VAT
Small organisation 10–49 employees £475 + VAT £775 + VAT
Medium organisation 50–249 employees £540 + VAT £840 + VAT
Large organisation 250+ employees £650 + VAT £950 + VAT

Progression: From Cyber Essentials to Cyber Essentials Plus and beyond

In the research commissioned by the UK government and released in the Cyber Essentials impact evaluation for 2024, it was highlighted that slightly more than three-quarters of UK businesses with Cyber Essentials took their security posture a step further by implementing other preventative actions.

Cyber Essentials provides an excellent foundation for businesses to mitigate risk and increase their cyber resilience. It leads to other certifications such as Cyber Essentials Plus and ISO 27001 (information security), depending on the needs of the business.

Key differences between Cyber Essentials and Cyber Essentials Plus

The main difference between Cyber Essentials and Cyber Essentials Plus is that the former relies on a self-assessment, while the latter offers a higher level of assurance by including a technical audit of the technology infrastructure to ensure that the technical controls have been properly implemented, including:

  • Internal vulnerability scans
  • Testing of in-scope systems
  • External IP vulnerability scans

The technical audit is carried out by an independent third-party organisation and looks at a representative set of user devices, all internet gateways, and all servers with services accessible to unauthenticated internet users.

From April 2026, a failed update management test triggers a retest against a fresh random sample of devices, and a second failure revokes the certificate. Selectively patching only the devices under test is prohibited.

Benefits of upgrading to Cyber Essentials Plus

The benefits of upgrading to Cyber Essentials Plus include:

  • Improved cyber resilience: Enhanced protection against cyber threats.

  • Better protection: Stronger safeguards against potential attacks.

  • Enhanced reputation: Increased trust with customers, future customers, and the wider market.

  • Business growth: Opportunities to bid for more business, particularly government contracts that require cyber security assurances.

  • Insurance savings: Potential reductions in cyber insurance premiums.

ISO 27001 consultants
ISO 27001 transition

Next step – from Cyber Essentials Plus to ISO 27001

ISO 27001 is the internationally recognised standard for information management security, and is a complementary certification to Cyber Essentials Plus, often building on its foundation. ISO 27001 provides a framework for creating and managing an information security management system (ISMS). The key difference between the two certifications is that ISO 27001 is a more rigorous standard, covering a broader scope than Cyber Essentials Plus.

Here are a few more differences:

  • ISO 27001 doesn’t just look at technical controls, but also considers policies, documentation, data, products, processes, services and systems.
  • It applies to both physical and digital information assets.
  • The certification is also focused on risk management and requires regular internal audits.
  • ISO 27001 can be used to comply with legal and regulatory requirements.

The important thing to remember is that the two certifications are complementary and provide a crucial layered approach to building cyber resilience and mitigating risk.

Why Choose RightCue for Cyber Essentials, Cyber Essentials Plus and ISO 27001 certification?

RightCue is an expert in cyber security compliance – with over 15 years’ experience helping organisations achieve certifications, increase cyber resilience and mitigate risk. With that experience comes an intricate understanding of business and what organisations need to succeed when it comes to cyber security. As a cyber security consultancy and Cyber Essentials Certification Body, RightCue is ideally positioned to help you with your compliance journey.

Ready to secure your business?

Take the next step in improving your cyber security posture and get in touch with our team of experts today.

Related articles & guides