Cyber Essentials. The UK's baseline for cyber security.
The UK Government's baseline cyber security certification, self-assessed against five technical control themes. Get certified as-is, or with full support, including gap analysis, remediation and assessor liaison.
What is Cyber Essentials?
The UK Government's baseline cyber security certification, developed by the NCSC and delivered by IASME through a network of over 300 licensed Certification Bodies. Launched in 2014, it protects businesses of any size against the most common, opportunistic internet-based attacks, the digital equivalent of checking your front door is locked.
Why is it worth the effort?
- Baseline protection
- Specifically designed to close off the most common, opportunistic attack routes. Insurer claims data cited by the NCSC shows Cyber Essentials-certified businesses are 92% less likely to make a claim.
- Contractual requirement
- Increasingly mandatory for UK government, public sector and defence supply chain contracts, and a growing number of private-sector tenders ask for it directly.
- Foundation for higher assurance
- The mandatory prerequisite for Cyber Essentials Plus, and for every level of the Defence Cyber Certification (DCC) scheme.
- Cyber insurance
- Businesses that certify their whole business, are domiciled in the UK, and have an annual turnover under £20 million, may be eligible for up to £25,000 of included cyber liability insurance.
- Customer and supplier assurance
- A recognised, government-backed signal that basic security hygiene is in place. A supply chain is only as secure as its weakest link; this helps secure it one link at a time.
- Keeps you current
- Reassessed every 12 months against the live standard, so your protection reflects new standards each year, designed around current recommendations and threats.
How does it work?
You complete a questionnaire against each control, a senior person confirms it's accurate, and an assessor reviews the submission. Cyber Essentials Plus assesses the same five themes but adds independent, hands-on technical verification. Cyber Essentials alone satisfies most contractual and insurance requirements; Plus is typically only needed where a specific contract or a higher DCC level demands independently verified assurance.
How do I scope this to my business?
The default position is that your entire business is in scope: every device, user account, network and cloud service used to access or process business data, unless there's a documented reason to exclude it.
In scope by default
- All office and remote-working devices, including relevant BYOD used for business purposes
- All cloud services that store or process business data (email, file storage, CRM, finance systems and more)
- Home working setups, where the firewall control is typically met by the device's own software firewall rather than an office boundary firewall
Narrower scoping is possible
- A well-defined sub-set can be certified instead, where it's genuinely segregated by a firewall or VLAN with internet traffic to the excluded portion blocked at the boundary
- Common for legacy systems or complex multi-entity structures; genuinely open guest networks, like hotel Wi-Fi, are a narrow exception
- Only a whole-business scope qualifies for the bundled cyber liability insurance
The five technical control themes
Every Cyber Essentials assessment, self-assessed or Plus, covers the same five areas.
Firewalls
Boundary firewalls and internet gateways configured to protect your network and devices from unauthorised access.
Secure configuration
Devices and software set up to reduce vulnerabilities, with unnecessary accounts, functionality and default settings removed or changed.
Security update management
Keeping all software, operating systems and firmware up to date, with a defined process for applying updates promptly.
User access control
User accounts only granted to authorised individuals, with access limited to what each person actually needs and administrative privileges tightly controlled.
Malware protection
Anti-malware software, application allow-listing or sandboxing in place to protect against malicious software.
What changed in April 2026? Introducing Danzell
Requirements for IT Infrastructure v3.3 applies to all assessment accounts created from 27 April 2026, alongside a new 2026 question set known as "Danzell". Here's what changes most for how you prepare.
New in v3.3
- A formal definition of cloud services means any cloud service holding your data must be in scope, even if only accessed from an otherwise out-of-scope network segment.
- Any device used to access an in-scope cloud service is also in scope, even if that device sits on an otherwise de-scoped network.
- Scoping language has been simplified: 'untrusted' and 'user-initiated' are no longer qualifiers for internet connections.
- New transparency rules mean businesses must list all legal entities covered by the certificate and describe any excluded infrastructure.
The auto-fail rules to check now
- Multi-factor authentication is mandatory for all cloud service authentication where available. Not enabling it causes automatic failure of the assessment.
- Critical security updates (CVSS v3 score 7 or above) must be applied within 14 days of release, an automatic-fail requirement.
- Any software or operating system no longer receiving security updates from its vendor must be removed from scope entirely, also an automatic-fail requirement. Unsupported software is the single most common reason assessments fail.
Two ways to get certified
Buy the certification as-is, or with full support, including gap analysis, remediation and assessor liaison. Choose the level that matches how ready you already are.
Certification, as-is
For businesses confident they already meet the five control themes and want the certificate processed efficiently. A lighter-touch, faster, lower-cost path, well suited to a mature IT setup.
- Setting up the assessment account at the correct business-size band
- Guidance completing the self-assessment questionnaire accurately, reflecting current v3.3/Danzell requirements
- Submitting to a Certification Body
- Liaising with the assessor on any clarification requests or resubmission
- Delivering the finished certificate and digital badge
Full consultancy and certification support
For businesses not yet confident they meet all five control themes, or without the internal resource to find out. Suits anyone early in their security maturity, or who would rather hand the whole thing to a team that does this daily.
- Everything included in certification as-is
- Gap analysis against the live v3.3 requirements, control by control
- Scope definition, including whole-business vs sub-set advice and network segregation
- Remediation delivery: MFA, 14-day critical patching, secure configuration, access control clean-up, malware protection
- Completing and submitting the questionnaire on your behalf, with your senior sign-off
- Managing the assessor relationship end-to-end, including any resubmission cycle
- Setting you up for renewal, so next year is a light annual touchpoint
How certification happens
Five straightforward steps, from purchasing the assessment through to certification, which stays valid for 12 months and is renewed annually.
Step by step
- 1 Purchase the assessment
Priced by business size, this gives you access to a secure online assessment platform.
- 2 Complete the questionnaire
Up to six months from account creation to finish, with progress saved as you go.
- 3 Senior sign-off
A senior person in your business confirms the answers are accurate before submission, a genuine attestation rather than a formality.
- 4 Assessor review
A qualified assessor from a Certification Body reviews your submission, typically within a few working days.
- 5 Outcome and Certification
A clean pass issues your certificate promptly, plus a digital badge and an IASME register listing.
Certification cost
This covers the IASME certification fee itself, plus us handling everything around it: setting up your assessment account, guiding you through the questionnaire, submitting to a Certification Body and liaising with the assessor on your behalf. Remediation work to close any gaps is priced separately. All figures are shown excluding VAT.
Micro
0 to 9 employees
£469.99
- IASME assessment and certificate
- Questionnaire guidance
- Assessor liaison and resubmission
Small
10 to 49 employees
£589.99
- IASME assessment and certificate
- Questionnaire guidance
- Assessor liaison and resubmission
Medium
50 to 249 employees
£649.99
- IASME assessment and certificate
- Questionnaire guidance
- Assessor liaison and resubmission
Large
250+ employees
Get in touch for a quote tailored to the size of your business.
Not sure how to go about it? We can help
If you're not confident you already meet the five control themes, our consultancy service covers gap analysis, remediation and the assessment itself, so you're not working it out alone. We can help close control and software gaps too.
Need some one off help to get you across the line?
Tell us where you're stuck and we'll come back with a tailored plan to close the gaps, without committing to an ongoing managed service.
Want it fully managed, year after year?
Munitus Core is our fully managed service that gets you certified against Cyber Essentials and Cyber Essentials Plus, then keeps you certified year on year.
Learn moreFrequently asked questions
How long does the process take?
The questionnaire itself can often be completed in a day once you're prepared. Including submission, assessor review and certificate issue, the full process typically takes around a week. Where remediation is needed first, timescales depend on the scale of the gaps, from a couple of weeks for minor fixes to several weeks for larger patch management, access control or configuration work.
What happens if we don't pass first time?
You get specific feedback on which controls weren't met, then two working days to fix the issues and resubmit for a free re-mark by the same assessor. Miss that window, or fail again, and you need to reapply and pay the assessment fee a second time. With our full support option, we handle remediation and resubmission for you, so that two-day clock isn't a scramble.
Do we need Cyber Essentials Plus as well?
Not necessarily. Cyber Essentials alone satisfies most contractual and insurance requirements. Plus is worth considering where a specific customer or tender requires independently verified assurance, or as a stepping stone to a higher DCC level. If you do go on to Plus, certify within three months of your Cyber Essentials date and you skip repeating the questionnaire stage entirely.
Does remote or hybrid working affect scope?
Yes, home-working devices and any cloud services used for business are in scope by default. For a fully remote business, the firewall control is usually met by each device's own software firewall rather than an office boundary firewall.
Can we certify only part of the business?
Yes, via a sub-set scope, but only where it's genuinely segregated from the rest of the network by a firewall or VLAN, with the exclusion clearly documented. Only a whole-business scope qualifies for the bundled cyber insurance.
Do sole traders or very small businesses need this?
It's not mandatory generally, but it's increasingly requested by customers, insurers and public sector procurement, even for very small suppliers, and the micro-business fee tier is designed to keep it accessible.
How is our business size worked out for pricing?
IASME counts everyone in scope, not just full-time staff: part-time employees, contractors and freelancers who use your systems all count towards the band. Get the count wrong and it can invalidate the submission, so we check this with you upfront.
What happens at renewal, and how long does full support take?
Certification lasts 12 months, so you reassess annually against whatever the standard looks like by then. With full support, timescales depend on the scale of any gaps found during the initial review, from a couple of weeks for minor fixes to several weeks for larger remediation work; we set out a clear timeline before you commit.
Ready to get certified?
Choose the level of support that matches how ready you already are, and we'll take it from there.