Cyber Essentials Certification
The Government-backed baseline that a growing number of contracts, insurers and clients now insist on. We are an appointed IASME Certification Body, so your certificate comes directly from us, assessed by a qualified human being.

Cyber Essentials is a Government-backed certification covering five technical controls that, between them, stop the overwhelming majority of commodity internet attacks. It is deliberately a baseline rather than a comprehensive security standard, and that is its strength: it addresses the attacks that actually happen to ordinary organisations rather than the ones that make good conference talks.
We are an appointed IASME Certification Body, so the certificate comes directly from us rather than through a broker, and your submission is marked by a qualified human assessor. Below is everything the scheme asks of you, what it costs, what actually causes a fail, and how long it realistically takes.
The five controls, one by one
Every Cyber Essentials question maps back to one of five control areas. Most organisations meet three of them already without having thought about it, and fail on the other two. Knowing which is which before you apply is the difference between a certificate and a wasted fee.
1. Firewalls
Every device that connects to the internet has to sit behind a correctly configured firewall, or have a software firewall enabled on the device itself. That covers the boundary firewall at your offices and the host firewall on every laptop that leaves the building. The administrative interface must not be reachable from the internet, default passwords must be changed, and any inbound rule has to have a documented business reason behind it.
Where this fails: forgotten port forwards from a project that finished two years ago, remote access left open to the world rather than restricted, and router admin panels still on the supplied default credentials.
2. Secure configuration
Devices and software have to be set up so that only what you actually need is running. Default accounts removed or renamed and given a strong password, unnecessary software and services removed, auto-run disabled so a connected device cannot execute code by itself, and a screen lock on every device. Password policy is in scope here too, and the scheme is specific: either multi-factor authentication, or a password of at least twelve characters with no maximum length below 160, or eight characters plus automated blocking of common passwords.
Where this fails: software installed for an evaluation and never removed, shared accounts with a password everybody knows, and a password policy that still forces a thirty-day rotation, which the scheme now discourages.
3. Security update management
All software has to be licensed, supported and in receipt of security updates. Critical and high severity patches must be applied within fourteen days of release. Anything the vendor no longer supports has to be removed from scope, removed from the estate, or segregated so it cannot reach the internet or be reached from it.
Where this fails: this is the single most common reason for a fail. An end-of-life Windows version on one machine in accounts, an old line-of-business application that will not run on anything current, a phone or tablet that stopped getting OS updates three years ago, and browsers or plug-ins that update on the user's whim rather than automatically.
4. User access control
Accounts are issued to named individuals through a documented process, removed when people leave, and given the minimum access needed. Administrative accounts are used for administration only, never for email or web browsing, and multi-factor authentication is required on all administrative accounts and on all cloud services.
Where this fails: the everyday account that also happens to be a local administrator, because it was easier that way when the machine was set up; leavers whose accounts are still enabled; and multi-factor authentication switched on for staff but not for the two administrator accounts that matter most.
5. Malware protection
Every device in scope has to be protected by one of the permitted approaches: anti-malware software kept up to date, or an allow list of approved applications, with the previously available sandboxing option no longer counted on its own. Built-in protection on modern Windows and macOS is acceptable provided it is enabled, updating and not silently disabled on a subset of machines.
Where this fails: protection disabled on a server "because it interferes with the application", and mobile devices assumed to be exempt when they are not.
The full checklist, in the order the questions come, goes through each requirement in detail. The question set is also revised annually, so see what changed in April 2026 before you reuse last year's answers.
What it costs
Our certification fees are fixed and published, based on the number of staff in scope. There is no consultation call built into the base price, because most organisations do not need one.
| Organisation size | Fee |
|---|---|
| Micro, 1 to 9 staff | £320 |
| Small, 10 to 49 staff | £440 |
| Medium, 50 to 249 staff | £500 |
| Large, 250+ staff | £600 |
| Prioritised turnaround, optional | +£100 |
What the fee does not include is the remediation, and for most organisations that is the larger number. If you need to replace two end-of-life laptops and buy a licence tier that supports conditional access, that will cost more than the certificate. We would rather you knew that before you paid us than after. The full cost breakdown, including what remediation typically runs to, sets out the realistic total.
How certification works, step by step
- Decide the scope. Whole organisation, or a clearly separable part. Get this right first, because everything else follows from it.
- Gap analysis, if you want one. We go through the question set with you and tell you honestly where you stand. Most organisations have three or four genuine gaps.
- Remediate. Specific guidance for your environment, not a restatement of the requirement. If you run Microsoft 365 and Intune we will tell you which settings to change. If your IT is outsourced we write the instructions in a form your provider can action without a further round of translation.
- Complete the assessment. We give you access to the IASME portal and you answer the question set. You can preview the questions before you commit to anything.
- Submission and marking. We review your answers, mark the submission, and come back on anything that needs clarifying. Because we assess for a living we know what the marking actually looks for, which is not always what the question appears to ask.
- Certificate. Issued directly by us as an appointed Certification Body, and listed on the public IASME register so your client can verify it.
How fast is realistic
We review a submitted assessment within one business day, and prioritised turnaround is available if you need it sooner. That is the part we control. The part you control is the remediation, and it is almost always the longer half.
An organisation already running current Windows or macOS, Microsoft 365 with multi-factor authentication switched on everywhere, and no end-of-life software can realistically certify inside a week. An organisation that discovers an unsupported server and no multi-factor authentication on its administrator accounts is looking at three to six weeks, and no assessor can compress that, because the work genuinely has to be done. Anyone promising you a certificate in hours is promising you a marking turnaround, not a certification timeline. Our page on fast certification sets out exactly what determines the clock, and what to do if you are already against a deadline.
Scoping honestly
Scope is where most of the difficulty arises. Certification can cover the whole organisation or a defined subset, and the temptation is to draw a boundary that excludes the awkward parts. Be careful. A scope that excludes most of your estate produces a certificate that a sophisticated buyer will read and discount, and it may well not satisfy the contract you are certifying for in the first place.
Three questions settle most scoping arguments. Does this device or service touch organisational data? Does the excluded part connect to the included part? And would you be comfortable showing the scope statement to the client who asked you to certify? If the answer to the last one is no, the scope is wrong. We will tell you if we think a proposed scope will not stand up, before you pay rather than after.
Why organisations get certified
Contracts. Central government contracts involving personal data or the provision of technical services require it under the Procurement Policy Note. Increasingly, so do local authorities, NHS trusts, universities and large private-sector buyers pushing requirements down their supply chain. If a client has just asked you for it, that is usually why.
Insurance. Many cyber insurance policies price on it, and some UK insurers include automatic cover for smaller organisations that hold it. What insurers actually do with it is worth understanding before you assume it lowers your premium.
Client assurance. A certificate answers a security questionnaire far more efficiently than forty pages of prose, and it is independently verifiable, which prose is not.
Because the controls are right. Setting the certificate aside entirely, these five are the right five things for a small organisation to get in order first, and most breaches we are called to would have been prevented by two of them.
Cyber Essentials, Cyber Essentials Plus, or something broader
Cyber Essentials is the baseline. Cyber Essentials Plus adds the hands-on audit and is what larger contracts increasingly specify by name; we assess it from late October 2026 and slots are open now. IASME Cyber Assurance is the natural next step for organisations needing something broader than five controls but proportionate rather than ISO 27001. And if you supply the Ministry of Defence, Defence Cyber Certification is the scheme that applies, with Cyber Essentials required at every level of it.
The full comparison of CE and CE Plus covers which one your contract actually requires, which is a question worth settling before you buy either.
What comes after
Certification lasts twelve months. Recertification is a fresh assessment against whatever the question set says at that point, so treat it as an annual exercise rather than a renewal. Two things tend to break certification between one year and the next: an operating system or application going end of life partway through the year, and growth, because a scope that made sense at fifteen people rarely survives to forty without revision.
The organisations that find recertification painless are the ones that fixed things properly the first time rather than working around the question. That is the whole argument for doing it with an assessor who tells you what is actually wrong.
Ready to buy?
Transparent, fixed pricing based on your organisation size. By default we give you access to the IASME portal to complete your Cyber Essentials assessment yourself, and once you submit it we aim to assess within one business day. You can preview the Cyber Essentials self-assessment questions to see where you stand first. There is no call or consultation as standard; we simply send you the questionnaire to complete. Your submission is reviewed by a qualified, certified assessor, never fed into AI. Need it faster? Add urgent turnaround below. Want us to review your setup against the controls before you apply? That is a gap analysis, quoted separately: ask for one using the contact button under the form.
An appointed IASME Certification Body: your certificate comes directly from us. Verify our credentials on the BlockMark registry, and find us listed on the IASME website.
Cyber Essentials by area
We certify organisations across the UK, mostly remotely, and on site where it helps. Area guides: Shropshire, West Midlands, Staffordshire, East Midlands, Greater Manchester, North Wales, South Wales.
Cyber Essentials by sector
The buyer or funder driving certification differs by sector, and so does the scoping argument. Sector guides: Schools, Colleges, Universities, Accountants, Law Firms, Charities, Manufacturers, Financial Services.
Common questions
How long does Cyber Essentials take?
If you already meet the five controls, the assessment itself takes a few days to complete and we review it within one business day of submission. Realistically most organisations need two to six weeks in total, because the remediation is the slow part. Replacing unsupported software and rolling out multi-factor authentication across a workforce are the two delays that cannot safely be rushed.
What does Cyber Essentials cost?
Our fee is £320 + VAT for a micro organisation of 1 to 9 staff, £440 for 10 to 49, £500 for 50 to 249 and £600 for 250 or more. A gap analysis before you apply is £300 and prioritised turnaround is £100. The certification fee is the small part of the total cost for most organisations; the remediation is the larger part, and it varies enormously depending on what you already have in place.
Can we fail Cyber Essentials?
Yes, and a fail costs you the fee. You are given an opportunity to correct a small number of non-compliant answers within a set window, but a submission that is substantially short will not pass. The four most common causes are unsupported operating systems or software still in use, multi-factor authentication missing from cloud administrator accounts, everyday user accounts holding local administrator rights, and patches outstanding beyond fourteen days. This is exactly what the gap analysis is for.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment that is independently marked. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit: vulnerability scanning of a sample of devices, plus practical tests of malware protection, patching and email and web browser controls. You must hold a valid Cyber Essentials certificate, less than three months old, before the Plus audit begins.
Do you assess Cyber Essentials Plus?
From late October 2026, and slots are open to book now. Until then we certify your Cyber Essentials, run the gap analysis that decides whether a Plus audit will pass, and hold your audit date. If your deadline falls before then we will tell you plainly and point you at another appointed assessor.
Do we need it if we do not sell to government?
Not necessarily, but the requirement is spreading through supply chains faster than most people expect. If you supply anyone who supplies the public sector, hold client data, or answer security questionnaires as part of winning work, it is usually worth having before somebody demands it at three weeks notice.
Does Cyber Essentials cover our cloud services?
Yes. All cloud services in use are in scope, including infrastructure, platform and software as a service. Responsibility is shared: the provider secures the platform, you are responsible for configuration, accounts and access. The requirements around administrative access and multi-factor authentication on cloud services are where organisations most often discover a gap they did not know they had.
Do staff home devices and personal phones count?
If a device accesses organisational data or services, it is in scope, including personally owned phones and laptops used for work. Home routers supplied by an internet provider are out of scope, but the software firewall on the device itself is in scope. Bring-your-own-device is permitted, but the device still has to meet the controls, which is why some organisations choose to restrict it rather than manage it.
Who actually assesses our submission?
A qualified, certified IASME assessor, and at Solusec that is the founder. Your answers are never fed into an AI system for marking. The credentials are published and can be verified on the IASME register.
How long does the certificate last?
Twelve months. Recertification is a fresh assessment against whatever the question set says at that point, not a renewal of the old one, and the question set is revised periodically. What passed last year does not automatically pass this year, which catches people out.
Can we certify only part of the organisation?
Yes, provided the scope is a genuinely separable part of the business and is described accurately on the certificate. A whole-organisation scope is stronger and is what most buyers assume they are getting. A narrow scope that excludes most of your estate will be read and discounted by any buyer who looks closely, and may not satisfy the contract you are certifying for in the first place.
We failed with another assessor. Can you help?
Yes. Send us the feedback you were given and we will tell you what it will take to pass, including whether the original scope was the problem. There is a longer guide on what to do after a fail.
Related
Cyber Essentials guides
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.