
Cyber Essentials: The Complete UK Business Guide
Cyber Essentials and Cyber Essentials Plus: What UK Businesses Need to Know
Cyber Essentials has quietly gone from a nice-to-have to a line on the tender form. Public sector buyers ask for it, larger customers write it into supplier contracts, and insurers look for it. If you run a UK business and haven't been asked yet, you probably will be.
This guide covers what Cyber Essentials is, the difference between Cyber Essentials and Cyber Essentials Plus, what you actually have to put in place, what it costs and how to get certified without the stress. Each section links to a deeper guide if you want the detail.
What is Cyber Essentials?
Cyber Essentials is the UK government-backed certification scheme for basic cyber security. It is overseen by the National Cyber Security Centre (NCSC) and delivered by IASME, which licenses a network of certification bodies to carry out assessments.
The scheme is built around five technical controls. Put them in place properly and you block the large majority of everyday, untargeted attacks: phishing links, password guessing, exploited unpatched software and malware dropped by email. These are the attacks that hit small and medium businesses hardest, precisely because they are cheap to run at scale.
Certification proves to customers, suppliers and insurers that those controls are in place across your organisation, not just on paper.
Why UK businesses get certified
Most businesses come to Cyber Essentials for one of four reasons:
- Contracts. Since 2014, central government has required Cyber Essentials for many contracts involving personal data or certain IT services. The Ministry of Defence supply chain uses it as a baseline, and a growing number of councils, NHS bodies, universities and private companies now ask their suppliers for it too.
- Insurance. Insurers see certified businesses as a lower risk. NCSC research found organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance. Eligible UK organisations with a turnover under £20m that certify their whole organisation can also receive free cyber liability cover with their certificate.
- Genuine protection. The UK government's Cyber Security Breaches Survey 2025 found 43% of UK businesses had a breach or attack in the previous 12 months, and phishing was involved in 85% of those. The controls in Cyber Essentials are aimed squarely at that kind of attack.
- Trust. Your certificate appears on a public register, so anyone can check it. For a lot of buyers, it's the quickest way to judge whether you take security seriously. See why smaller firms are so often targeted in Small Businesses Are the Prime Target for Cyber Attacks.
Cyber Essentials vs Cyber Essentials Plus
There are two levels, and they cover exactly the same five controls. The difference is how they are checked.
Cyber Essentials is a verified self-assessment. You answer an online question set about your organisation's IT, a senior person signs it off as accurate, and a certification body reviews your answers. If they pass, you're certified.
Cyber Essentials Plus adds a hands-on technical audit. An assessor tests a sample of your devices, user accounts and cloud services to confirm the controls are really working. That includes vulnerability scans, checks that malware protection stops test files, and confirmation that multi-factor authentication is switched on. You have to pass Cyber Essentials first, and the Plus audit must be completed within three months of that.
Plus carries more weight with buyers because it is independently tested rather than self-declared. We compare the two in detail, including which one different contracts ask for, in Cyber Essentials vs Cyber Essentials Plus.
The five Cyber Essentials controls
In one line each:
- Firewalls. Every device that connects to the internet sits behind a properly configured firewall, with default passwords changed and unused rules removed.
- Secure configuration. Devices and software are set up securely: unnecessary accounts and software removed, default passwords changed, auto-run disabled and screens locked.
- Security update management. Software is licensed, supported and patched. High and critical security updates go on within 14 days, and anything no longer supported by its vendor has to go.
- User access control. People only have the access they need. Admin accounts are separate and only used for admin work, and multi-factor authentication is on for cloud services.
- Malware protection. Every in-scope device is protected by anti-malware software or application allow-listing, kept up to date and running.
The detail is where businesses trip up. Our Cyber Essentials requirements checklist goes through each control with the specific checks that cause the most failures.
What's in scope
Scope is the single most common source of failed assessments. Cyber Essentials expects you to include every device, account and service that can access your business data, which usually means:
- Office desktops, laptops, servers and network equipment
- Laptops and home routers used by remote staff
- Mobile phones and tablets that access business email or files, including personal devices used for work
- Cloud services such as Microsoft 365, Google Workspace and line-of-business apps
You can exclude a separate part of the network, but only if it is genuinely segregated. Certifying the whole organisation is simpler, and it's also a condition of the free insurance. If your team works from home, our cyber security guide for remote teams covers the practical side.
How much Cyber Essentials costs
There are two parts to the cost. The certification fee for Cyber Essentials is set by IASME on a sliding scale by organisation size. Cyber Essentials Plus costs more because of the assessor's time, and rises with the number of devices and sites.
IASME certification fees and external audit costs change from year to year, so rather than passing on a string of separate bills, we include them in one monthly fee:
- Cyber Essentials from £130 a month + VAT, including our time to get you ready and take you through assessment
- Cyber Essentials and Cyber Essentials Plus for £279 a month + VAT, including all external audit fees
Spreading the cost monthly makes certification easier to budget for and far more affordable than paying for everything up front. And if you're on our Flo360+ managed support, Cyber Essentials is included as standard, because we want every one of our partners to have it as a baseline for security.
The bigger variable is getting ready. A business with modern, managed devices might need very little work. One with old laptops, shared admin accounts and no MFA might need replacement hardware and a few weeks of fixes. We break it all down in How Much Does Cyber Essentials Cost?
How to get Cyber Essentials certified: the practical order
Done properly, getting certified follows a clear sequence:
1. Readiness check. Compare your devices, accounts, cloud services and firewalls with the current requirements. IASME offers a free readiness tool, or a provider can do it for you.
2. Agree the scope. Decide what's in and make sure nothing is missed, particularly home workers, mobiles and cloud apps.
3. Fix the gaps. Patch, remove unsupported software, split admin accounts, switch on MFA, tighten firewall rules and confirm malware protection everywhere.
4. Complete the question set. Answer accurately and in enough detail. Vague answers are a common reason for being sent back.
5. Book the Plus audit (if needed). Within three months of passing Cyber Essentials, the assessor tests a sample of your systems. Anything they find must be fixed and retested.
6. Stay compliant. Keep controls in place all year and renew before your certificate expires.
Step 3 is where most of the effort goes, and it's where DIY attempts usually stall.
Staying compliant after certification
A Cyber Essentials certificate proves your business met the standard on the day it was assessed. It says nothing about next month. Devices fall behind on updates, someone gets local admin rights "just for a minute", a new laptop is set up without malware protection. None of it is deliberate, and all of it can undermine your cover if something goes wrong.
Certificates are valid for 12 months, and most buyers expect a current one. The businesses that sail through renewal are the ones that treat the controls as everyday practice, not an annual exam. That's exactly the gap Active Protect was built to close.
Active Protect is Flotek's own product, designed to keep you in constant protection and compliance, not just on audit day. It checks your devices every day to make sure nothing has slipped: security updates, admin rights, malware protection and the other settings Cyber Essentials depends on. If something does slip, our team will reach out to you straight away, or, if you have a managed support agreement with us, fix it behind the scenes before it becomes a problem.
We explain more in Why Cyber Essentials Needs Active Protect. Pair it with staff awareness training, because people remain the most common way in, as covered in Why Your People Are Your Biggest Cybersecurity Threat.
Cyber Essentials and your wider cyber security
Cyber Essentials is a baseline, not the finish line. It deliberately doesn't cover things like threat detection, backups, incident response or email authentication. For most small businesses, the next steps are 24/7 monitoring through a service like CyberGuard MDR, protecting Microsoft 365 with FloCDR, and stopping criminals sending email in your name with Flo Verified Mail. A cyber security risk assessment is a good way to decide what matters most for you.
If you'd rather not do this yourself
Our Cyber Essentials and Cyber Essentials Plus service handles the whole journey. We run the readiness check, agree your scope, fix the gaps, work through the question set with you and prepare you for the Plus audit. Then Active Protect keeps you compliant every day until renewal. It all comes in one monthly fee, from £130 a month + VAT, with certification and audit fees included. If a contract deadline is looming, or you simply want to know where you stand, book a free readiness check with our team.
Further reading
• Cyber Essentials vs Cyber Essentials Plus: which does your business need?
• Cyber Essentials requirements: the five controls checklist
• How much does Cyber Essentials cost?






.jpg)






Schedule a Free IT Audit & Cost Breakdown




.avif)


%20amended%20logo.avif)







