All guidesExplainer

Cyber Essentials Explained in Plain English

If a client, tender, or insurer has just told you that you need “Cyber Essentials,” and you’ve no idea what that means — you’re in the right place. This is the no-jargon version, written for small business owners, not IT departments.

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed certificate that shows your business has the basic security measures in place to protect against the most common cyber attacks. It’s run by a body called IASME on behalf of the National Cyber Security Centre (NCSC).

In practice, it’s becoming a passport for winning work. Many public-sector contracts require it, and a growing number of larger companies now ask their suppliers to hold it before they’ll sign. That’s usually why a business first hears about it — someone they want to work with has made it a condition.

The two levels (you probably only need the first)

  • Cyber Essentials (Basic): a self-assessment questionnaire. You answer questions about your setup, a qualified assessor reviews them, and if you pass, you’re certified. It typically costs around £300–£500 + VAT depending on your company size. This is the one most small businesses need.
  • Cyber Essentials Plus: everything in Basic, plus a hands-on technical audit of your actual devices. More thorough, more expensive (£1,350+), and usually only required for higher-risk work.

The certificate lasts 12 months, then you renew.

The five things it checks

Cyber Essentials looks at five basic areas of security:

  1. Firewalls — keeping your network’s “front door” closed to attackers.
  2. Secure configuration — setting devices up safely and removing what you don’t need.
  3. User access control — making sure only the right people can access the right things, with two-factor login.
  4. Malware protection — guarding against viruses and malicious software.
  5. Security update management — keeping software up to date so known holes get patched.

None of these require deep technical knowledge to understand — but the official questionnaire describes them in language that assumes you have an IT person, which is where most small businesses get stuck.

Do I really need it?

If a contract or client has asked for it, then yes — and there’s a real upside beyond winning that one job. It signals trust to every future client, and it forces a handful of genuinely sensible security habits that protect your business day to day.

How to get certified, in three steps

  1. Find out where you stand. Work out which of the five areas you already meet and where the gaps are.
  2. Fix the gaps. Usually this is simpler than people fear — turning on two-factor login and automatic updates covers a lot of it.
  3. Complete the assessment. Answer the official questionnaire and submit it through a licensed body.

The hardest part is almost always the first one — knowing whether you’d pass, in plain terms, before you pay.