Cyber Essentials Explained in Plain English
If a client, tender, or insurer has just told you that you need “Cyber Essentials,” and you’ve no idea what that means — you’re in the right place. This is the no-jargon version, written for small business owners, not IT departments.
What Cyber Essentials actually is
Cyber Essentials is a UK government-backed certificate that shows your business has the basic security measures in place to protect against the most common cyber attacks. It’s run by a body called IASME on behalf of the National Cyber Security Centre (NCSC).
In practice, it’s becoming a passport for winning work. Many public-sector contracts require it, and a growing number of larger companies now ask their suppliers to hold it before they’ll sign. That’s usually why a business first hears about it — someone they want to work with has made it a condition.
The two levels (you probably only need the first)
- Cyber Essentials (Basic): a self-assessment questionnaire. You answer questions about your setup, a qualified assessor reviews them, and if you pass, you’re certified. It typically costs around £300–£500 + VAT depending on your company size. This is the one most small businesses need.
- Cyber Essentials Plus: everything in Basic, plus a hands-on technical audit of your actual devices. More thorough, more expensive (£1,350+), and usually only required for higher-risk work.
The certificate lasts 12 months, then you renew.
The five things it checks
Cyber Essentials looks at five basic areas of security:
- Firewalls — keeping your network’s “front door” closed to attackers.
- Secure configuration — setting devices up safely and removing what you don’t need.
- User access control — making sure only the right people can access the right things, with two-factor login.
- Malware protection — guarding against viruses and malicious software.
- Security update management — keeping software up to date so known holes get patched.
None of these require deep technical knowledge to understand — but the official questionnaire describes them in language that assumes you have an IT person, which is where most small businesses get stuck.
Do I really need it?
If a contract or client has asked for it, then yes — and there’s a real upside beyond winning that one job. It signals trust to every future client, and it forces a handful of genuinely sensible security habits that protect your business day to day.
How to get certified, in three steps
- Find out where you stand. Work out which of the five areas you already meet and where the gaps are.
- Fix the gaps. Usually this is simpler than people fear — turning on two-factor login and automatic updates covers a lot of it.
- Complete the assessment. Answer the official questionnaire and submit it through a licensed body.
The hardest part is almost always the first one — knowing whether you’d pass, in plain terms, before you pay.