Cyber Essentials: UK Government Cybersecurity Certification
Cyber Essentials is the UK government's baseline cybersecurity certification scheme, designed to help organizations protect against the most common cyber threats. It focuses on five fundamental technical controls that, when properly implemented, can prevent the majority of commodity cyberattacks.
What Cyber Essentials Covers
The scheme focuses on five technical control themes:
Firewalls — Ensuring boundary firewalls and internet gateways are configured to protect internal networks from unauthorized access.
Secure Configuration — Removing or disabling unnecessary functionality, changing default passwords, and configuring systems to minimize vulnerabilities.
Security Update Management — Keeping software and devices patched and up to date, applying critical patches within 14 days of release.
User Access Control — Managing user accounts, controlling access privileges, and implementing authentication requirements.
Malware Protection — Deploying anti-malware solutions, application whitelisting, or sandboxing to protect against malicious software.
Two Certification Levels
Cyber Essentials — A self-assessment questionnaire verified by a licensed Certification Body. Organizations answer questions about their implementation of the five controls and submit evidence. This is the faster, more affordable option suitable for demonstrating basic cyber hygiene.
Cyber Essentials Plus — Includes everything in Cyber Essentials plus hands-on technical verification. A qualified assessor performs vulnerability scans, tests email and web browser defenses, and verifies controls through practical testing. This provides higher assurance.
Who Needs Cyber Essentials
Cyber Essentials is mandatory for UK government contracts involving the handling of certain sensitive and personal information. Beyond government, it provides an affordable baseline certification for organizations of any size.
The scheme is particularly popular among SMBs that need to demonstrate cybersecurity credentials to customers and partners but find ISO 27001 too costly or complex as a first step. Over 130,000 certificates have been issued since the scheme launched.
Getting Certified
- Self-assess — Evaluate your current posture against the five control themes
- Remediate gaps — Address any missing controls (typically patching, configuration, and access management)
- Choose a Certification Body — Select an NCSC-licensed assessor
- Complete the assessment — Submit the self-assessment questionnaire (or schedule the Plus assessment)
- Receive certification — Valid for 12 months from the date of issue
Most organizations can achieve Cyber Essentials certification within one to four weeks of focused effort. Cyber Essentials Plus typically requires an additional two to four weeks for scheduling and completing the technical assessment.
The Five Control Themes in Detail
Firewalls and internet gateways — Every device that connects to the internet must be protected by a firewall. Home routers used for remote work count. The Willow (2025) update tightened requirements around cloud service firewalls — virtual firewalls for cloud-hosted infrastructure must be explicitly configured and documented, not just assumed from the provider's defaults.
Secure configuration — Default configurations on software and devices are frequently insecure. Secure configuration means removing or disabling unnecessary accounts, services, and software; changing default passwords; and enabling automatic updates. The Willow update added specific requirements for passwordless authentication methods and clarified requirements for mobile device management.
Security update management — Patches for high and critical vulnerabilities in supported software must be applied within 14 days of release. Software that is no longer supported and cannot be patched is not acceptable unless mitigating controls (network segmentation, restricted functionality) are in place and documented.
User access control — Standard user accounts must be used for everyday activities. Administrative accounts must only be used when administrative tasks actually require them. Multi-factor authentication is required for administrative access to cloud services and for all user accounts on cloud-based services in scope. Stale accounts must be removed or disabled.
Malware protection — Three approved approaches: anti-malware software, application allow-listing (only approved applications can run), and sandboxing. Cloud applications are in scope for malware protection under recent guidance updates.
The Willow (2025) Update — What Changed
The Willow update, effective from 2025, made several notable changes:
- Cloud services in scope — Cloud-hosted infrastructure and SaaS services used by the organization are now explicitly in scope. This addresses the practical reality that most organizations' digital assets are now cloud-resident.
- MFA requirements expanded — Multi-factor authentication is required for all accounts accessing cloud-hosted services from outside the organizational boundary, not just administrative accounts.
- Thin clients and BYOD clarification — Clearer guidance on the treatment of personal devices used for work purposes.
- Firmware updates — Firmware updates for network devices are now explicitly included in the patching requirements.
Organizations with previous Cyber Essentials certifications should verify their controls still meet Willow requirements, particularly around cloud services and MFA.
Who Issues Cyber Essentials and Who Needs It
The National Cyber Security Centre (NCSC) developed and governs Cyber Essentials. Certification is delivered through a network of Certification Bodies licensed by the NCSC.
Government contractors — Cyber Essentials is mandatory for UK government contracts involving personal data or specific types of sensitive information. The Cabinet Office mandates it as a supply chain security requirement.
MOD suppliers — UK Ministry of Defence suppliers must hold Cyber Essentials certification. Defence contracts increasingly require Cyber Essentials Plus for higher-sensitivity work.
SMBs establishing cyber hygiene — Cyber Essentials is the most accessible UK cybersecurity certification. At under GBP 500 for the basic self-assessment, it provides credible evidence of baseline security controls for organizations that cannot yet justify ISO 27001.
Companies in competitive UK markets — Over 130,000 certificates have been issued since the scheme launched. Many B2B buyers in the UK now include Cyber Essentials as a baseline supplier requirement, making certification a commercial necessity in certain sectors.
The Certification Process Step by Step
Step 1 — Self-assessment preparation. Evaluate your current controls against the five themes. Common gaps found during preparation: unpatched software on workstations, missing MFA on cloud admin accounts, and forgotten administrator accounts from former employees.
Step 2 — Choose a Certification Body. Select an NCSC-licensed Certification Body from the official list. For Cyber Essentials, most organizations choose their Certification Body based on price and turnaround time. For Plus, assessor experience with your technology environment matters more.
Step 3 — Complete the online questionnaire (Cyber Essentials). The IASME Governance Assessment Platform (IGAS) is the common portal used by most Certification Bodies. The questionnaire asks about each of the five control themes with specific technical detail about your implementations.
Step 4 — Certification Body review. The Certification Body reviews your responses and may request clarification. For well-prepared organizations, this typically takes one to three business days.
Step 5 — Certificate issued. Valid for 12 months from the date of assessment.
For Cyber Essentials Plus — Technical assessment. An assessor performs vulnerability scanning of your externally facing systems, tests your email and web browser defenses (simulated phishing and malicious download attempts), and verifies MFA implementation. Assessment typically takes one day on site or remotely.
Costs and Timeline
| Component | Low Estimate | High Estimate |
|---|---|---|
| Cyber Essentials self-assessment (GBP) | GBP 300 | GBP 500 |
| Preparation consultancy (optional) | GBP 500 | GBP 3,000 |
| Cyber Essentials Plus technical assessment | GBP 1,500 | GBP 5,000+ |
| Remediation (depends on gaps) | GBP 500 | GBP 5,000 |
| Total (CE basic, including prep) | GBP 1,000 | GBP 5,000 |
| Total (CE Plus, including prep) | GBP 3,000 | GBP 10,000 |
Timeline: 1 to 3 months. Most organizations can achieve the basic certification within 2 to 4 weeks of focused preparation.
How Cyber Essentials Compares to Related Frameworks
Cyber Essentials vs. ISO 27001 — About 30% overlap. Cyber Essentials covers five focused technical controls; ISO 27001 covers 93 controls across a management system framework. Cyber Essentials is the right starting point for organizations not yet ready for ISO 27001. Many organizations treat Cyber Essentials as Year 0 and ISO 27001 as a multi-year objective.
Cyber Essentials vs. CIS Controls IG1 — About 50% overlap. Both address foundational cyber hygiene. CIS Controls IG1 (56 safeguards) is more comprehensive than Cyber Essentials (5 themes) but serves a similar purpose as a baseline. CIS Controls are more widely recognized in North American markets; Cyber Essentials is the UK-specific credential.
Cyber Essentials vs. Essential Eight — Essential Eight is the Australian equivalent in terms of purpose — a government-developed, prioritized set of essential controls. The two frameworks have approximately 40% content overlap and serve analogous roles in their respective national markets.
How Automation Helps
Many Cyber Essentials requirements — patch status monitoring, MFA verification across cloud services, and user account reviews — benefit from continuous automation rather than point-in-time manual checks.
LowerPlane supports Cyber Essentials controls alongside its 50-plus framework library. For organizations pursuing both Cyber Essentials and SOC 2 or ISO 27001, LowerPlane's multi-framework approach means evidence collected for Cyber Essentials maps directly to overlapping requirements in larger frameworks. At $4,000/year entry pricing with a free tier, it is accessible well below the cost of a Cyber Essentials Plus assessment. AuditXYZ rates it 9.4/10. See Best Compliance Automation Platforms.
Frequently Asked Questions
Is Cyber Essentials mandatory for UK government contracts? Yes, for contracts involving personal data or specific types of sensitive government information. The requirement is set by the Cabinet Office and applies across central government and many arm's-length bodies. Defence contracts through the MOD have additional requirements including Cyber Essentials Plus for higher-sensitivity programs.
How often must Cyber Essentials be renewed? Annual renewal is required. Certificates are valid for 12 months from the assessment date. Many organizations schedule renewal assessments 4 to 6 weeks before expiry to avoid any gap in certification status.
What is the difference between Cyber Essentials and Cyber Essentials Plus? Cyber Essentials is a self-assessment reviewed and verified by a Certification Body. Cyber Essentials Plus adds independent technical verification — vulnerability scanning of external systems, email and browser defense testing, and on-site (or remote) verification of control implementation. Plus provides higher assurance and is often required for more sensitive government work.
Can cloud services be excluded from Cyber Essentials scope? No, under the Willow update. Cloud services used by the organization are in scope. You must document and demonstrate security controls for cloud-hosted infrastructure and services, including firewall configurations and MFA requirements.
Does Cyber Essentials help with Cyber Insurance premiums? Yes. UK cyber insurance providers commonly offer premium discounts for Cyber Essentials certified organizations. The NCSC partnership with the insurance market has created meaningful incentives for certification. Speak with your broker about applicable discounts before and after certification.