Securing Cyber Essentials compliance is a major step for UK businesses looking to protect their server networks in 2026. This government-backed scheme helps companies demonstrate their commitment to data security to public sector buyers and enterprise clients, and maintaining these baselines blocks up to eighty percent of standard cyber attacks. This guide breaks down the certification process, technical controls, and budgeting guidelines required to achieve certification.
[!TIP] Scoping Recommendation: When preparing your audit scope, document all devices that access company databases (including remote worker laptops). Failing to list remote devices is the leading cause of audit failure during Cyber Essentials assessments.
Key Takeaways:
- Cyber Essentials certification protects against phishing, malware, and unauthorised remote access.
- The base self-assessment certification fee ranges from £320 to £600 depending on company size (fixed by IASME).
- Cyber Essentials Plus requires an independent, hands-on audit of network configurations and device setups.
- Implementing strict password policies and multi-factor authentication (MFA) is a mandatory requirement.
The Five Technical Controls of Cyber Essentials
To satisfy the assessment criteria, your company must implement five core security controls across all networks and user devices. According to guidelines from IASME , these technical baselines must remain active continuously to prevent security breaches:
1. Firewalls and Internet Gateways
All internet connections must run through configured hardware or software firewalls. Consequently, these gates must block unapproved ports and log incoming traffic to prevent network sniffing exploits.
2. Secure Configuration
Default settings on routers, operating systems, and servers are often insecure. Therefore, you must modify default administration passwords, disable unused software features, and remove pre-installed guest user accounts.
3. User Access Control
Access to customer databases and administrative servers must follow the principle of least privilege. Consequently, you must enforce three strict access rules:
- Role Scoping: Staff should only access the files required for their daily tasks, which restricts database exposure.
- MFA Enforcements: Multi-factor authentication must be enabled for all administrative and cloud email portals, blocking unauthorised brute-force attempts.
- Admin Tracking: Limit administrative accounts to specialised systems, preventing staff from browsing the web with admin rights. This mitigates cross-site scripting risks.
4. Malware Protection
All corporate devices must run updated antivirus software and block executions of unapproved files. Additionally, downloading software must be restricted to verified vendor marketplaces. Therefore, this security measure prevents remote access trojans from infecting laptops.
5. Security Update Management
Unpatched software represents a primary attack vector for hackers. Consequently, you must apply critical security patches to all operating systems, web browsers, and plugins within fourteen days of release.
Certification Levels: Standard vs. Plus
UK business leaders must choose between the self-assessment tier and the audited tier:
| Compliance Metric | Cyber Essentials (Standard) | Cyber Essentials Plus |
|---|---|---|
| Audit Style | Verified self-assessment questionnaire. | Hands-on audit by an independent assessor. |
| Vulnerability Check | No external scan required for submission. | Internal and external vulnerability scans. |
| Testing Scope | Administrative answers only. | Hands-on validation of endpoints and server systems. |
| Target Audience | Startup MVPs and standard supply chains. | Government contractors and financial enterprises. |
Best Practices to Prepare for Your Assessment
Preparing your network configurations before you apply for certification minimises audit friction and prevents failures. You should adopt these four configuration steps:
- Audit Remote Access Tools: Ensure remote access protocols (like RDP) are disabled or run behind secure VPN configurations.
- Review User Privileges: Audit all active user database accounts and delete profiles of staff members who have left the company.
- Upgrade Legacy Systems: Decommission obsolete operating systems (like Windows 7 or older Linux kernels) that do not receive security patches.
- Deploy MDM Software: Use Mobile Device Management (MDM) tools to enforce encryption, passwords, and remote wipe capabilities on corporate laptops.
A Readiness Checklist for the Five Controls
Before you pay for an assessment, run your estate against the checklist below. Each item maps to one of the five controls and reflects the specific evidence assessors look for. If you can tick every line honestly, the questionnaire should hold few surprises.
Firewalls and internet gateways
- Every internet-facing device has a boundary or host-based firewall enabled.
- The default firewall administrative password has been changed to a strong, unique credential.
- No inbound rules exist without a documented business case, and unused rules are removed.
- Home and remote workers connect through a firewall or a software firewall running on the device itself.
Secure configuration
- Default and guest accounts are removed or disabled on all servers and endpoints.
- Auto-run and auto-play are switched off so unapproved code cannot execute from removable media.
- Unused software, services, and accounts are uninstalled or deactivated.
- Device locking (PIN, biometric, or password) is enforced after a short idle period.
User access control
- Every user has a unique, named account, with no shared logins.
- Administrative rights are granted on request, reviewed regularly, and revoked when no longer needed.
- Multi-factor authentication is enabled on all cloud services, not only email.
- A documented starter and leaver process disables accounts the day someone leaves.
Malware protection
- Anti-malware is active and updating on every in-scope Windows and macOS device.
- Mobile devices only install applications from an approved, managed store.
- Where you rely on application allow-listing instead of anti-malware, the approved list is maintained.
Security update management
- Every operating system and application is still supported by its vendor (no Windows 7, no unsupported Linux kernels).
- High and critical updates are applied within 14 days of release.
- Automatic updates are enabled wherever the platform allows it.
Cyber Essentials vs Cyber Essentials Plus: The Decision in Detail
The earlier table covered how the two tiers are assessed. For most buyers the deciding factors are cost, effort, and timing. The comparison below sets illustrative figures against the practical differences. All fees exclude VAT, and the Plus figure varies by Certification Body.
| Factor | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Certification fee | £320–£600 by company size (fixed by IASME) | Typically £1,400–£3,000+, set by the assessor |
| Assessment format | Online self-assessment questionnaire | On-site or remote hands-on technical audit |
| Preparation effort | 2–4 weeks for a small, tidy estate | The same prep, plus remediation of any scan findings |
| Evidence | Your written answers, verified by an assessor | Sampled devices, authenticated scans, live MFA tests |
| Prerequisite | None | A valid Cyber Essentials pass within the last 3 months |
| Free cyber insurance | Included for UK organisations under £20m turnover | Included on the same basis |
| Best fit | Baseline assurance for most supply chains | MOD and government contracts, regulated or high-trust sectors |
If a tender specifies Cyber Essentials Plus, budget for both certifications. You must hold the base certificate first, so the two run back to back rather than as alternatives.
A Worked Certification Timeline and Cost Scenario
Consider a 25-person software firm in London preparing for a public-sector tender that requires Cyber Essentials Plus. Here is how a realistic engagement tends to unfold, with illustrative figures.
Weeks 1–2: Scoping and gap analysis. The firm catalogues 25 laptops, three cloud services (Microsoft 365, a CRM, and a code repository), and eight remote workers. A gap analysis finds two laptops on an unsupported operating system, MFA missing on the CRM, and three dormant leaver accounts.
Weeks 3–4: Remediation. The two laptops are rebuilt on a supported version, MFA is switched on across all three cloud services, the dormant accounts are disabled, and auto-update policies are pushed out through Mobile Device Management.
Week 5: Self-assessment. The firm completes the questionnaire and submits it. Base certification costs £400, the fee for the 10–49 employee band. It passes within a few working days.
Weeks 6–7: Plus audit. Inside the three-month window, an assessor samples roughly a third of the devices, runs authenticated vulnerability scans, and tests malware protection and MFA live. One medium-severity patch is flagged and fixed on re-test. The Plus assessment costs £1,750.
Totalling the certification fees gives £400 + £1,750 = £2,150, plus roughly 40–60 hours of internal time and any hardware or licensing needed for remediation. The whole path runs about six to eight weeks. A cleaner estate finishes faster, while unsupported systems or a large device count push both the timeline and the Plus fee upward.
Common Failure Points and Questions to Ask Your Assessor
Most first-attempt failures come from the same handful of gaps. Watch for these red flags before you submit:
- Unsupported software still in scope. A single out-of-support operating system or browser fails the whole assessment.
- MFA gaps on cloud services. Enabling it on email but not on the CRM or admin console is a frequent miss.
- Incomplete scope. Leaving out a home-working laptop or a forgotten cloud service undermines the certificate.
- Slow patching. No evidence that high and critical updates land inside 14 days.
- Shared or default accounts. Generic “admin” logins with no named owner.
Choosing a Certification Body is itself a vetting exercise, so treat it like assessing any supplier. Useful questions to ask:
- Are you an IASME-licensed Certification Body, and how long have you delivered Cyber Essentials?
- Is a pre-assessment or readiness review included, or charged separately?
- How do you sample devices for the Plus audit, and what counts as a re-test if we fail an item?
- What is the total fee, and does it include a free re-test window?
- Can you advise on remediation, or do you only assess?
Before spending anything, run the free Cyber Essentials Readiness Tool on the IASME website. It walks you through the current question set and produces a tailored action plan, which is the cheapest way to surface gaps early.
Partner with a Vetted UK Security Consultancy
Achieving certification protects your company and helps secure public tenders. Mecanik provides professional server security audit services and infrastructure hardening through our penetration testing services page. We specialise in network auditing, device compliance, and cloud firewall configurations. Contact us today to schedule your compliance scoping session.
Frequently Asked Questions
What is cyber essentials compliance uk? Cyber essentials compliance uk is a government-backed cybersecurity certification scheme designed to protect businesses against common online threats. Achieving certification demonstrates to clients that your company has implemented core controls to protect sensitive customer data.
How much does it cost to get Cyber Essentials certified? The self-assessment certification fee is tiered by company size, ranging from £320 for micro-businesses (1-9 employees) to £600 for large enterprises (250+ employees). The cost of Cyber Essentials Plus is higher because it requires hands-on auditor testing.
What is the difference between Cyber Essentials and Cyber Essentials Plus? Cyber Essentials is a self-assessment questionnaire verified by an assessor. Conversely, Cyber Essentials Plus requires an independent, hands-on audit of your systems, including internal device checks and vulnerability scans, to verify the controls are working.
Do remote workers affect my Cyber Essentials scope? Yes, any corporate laptops, tablets, or smartphones used by remote workers to access company data are in scope. Therefore, these devices must comply with the same security configurations, password policies, and patch updates as office-based systems.
How long does the Cyber Essentials certification last? The certification is valid for 12 months. Consequently, your business must run through the assessment annually to renew the certification, ensuring your security configurations adapt to evolving cyber threats.
Comments