UK schemes

Cyber Essentials for beginners: what it is (and what it is not) for UK SMEs

What the certificate covers, common myths, and a starter checklist before you talk to a certifier.

  • What Cyber Essentials actually is
  • What it is not (common myths)
  • The five technical controls in plain English
  • Basic vs Cyber Essentials Plus
  • Who typically needs it (and who can wait)
  • Rough cost, effort, and timeline for under-50 staff
  • How it sits next to password managers, MFA, and VPN
  • A practical starter checklist
  • ASA-safe disclaimer

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed scheme that sets a baseline for how organisations protect themselves against common cyber attacks. It is run through the National Cyber Security Centre (NCSC) and delivered by licensed certification bodies. When people say "we have Cyber Essentials", they usually mean they have a current certificate against that baseline.

For an owner-manager, think of it as a structured hygiene check, not a badge that proves you are "secure forever". The scheme focuses on five technical control areas. You answer a questionnaire (and for the higher tier, undergo a hands-on test), then a certifier reviews whether your answers meet the standard for the scope you declared.

It exists because many UK breaches still come from unpatched software, weak passwords, phishing that leads to account takeover, and poorly configured devices. Cyber Essentials pushes firms to close those ordinary doors before they buy exotic tools.

What it is not (common myths)

Clear the myths early:

  • It is not ISO 27001. ISO is a broader management-system standard. Cyber Essentials is narrower and more technical-baseline oriented.
  • It is not a penetration test of your whole business, and it is not insurance. Passing does not guarantee you will never be breached.
  • It is not the same as "having a VPN" or "buying antivirus". Those may help some controls, but the certificate is about how you run access, patching, malware protection, secure configuration, and boundary firewalls across the devices and services you put in scope.
  • It is not only for huge corporations. Plenty of UK SMEs pursue it because customers, frameworks, or insurers ask. Many also skip it until a tender forces the issue.
  • It is not a substitute for staff judgement. Phishing, invoice fraud, and social engineering still need process and training.

If a vendor sells you "Cyber Essentials in a box" with no questionnaire, no scope decision, and no certifier, treat that as marketing, not certification.

The five technical controls in plain English

You will see these named slightly differently across guides, but the jobs are stable:

  • Firewalls / boundary protection: control what can talk in and out of your network and cloud estate. For a tiny firm this often means a decent router/firewall at the office plus sensible cloud defaults, not a rack of appliances.
  • Secure configuration: turn off default admin accounts, remove unused services, lock down devices so they are not left on factory settings.
  • Access control: who can get into which systems. Unique accounts, least privilege, and multi-factor authentication (MFA) where the standard expects it. Shared generic logins fight this control.
  • Malware protection: keep devices protected with supported anti-malware (or equivalent platform controls) and stop staff installing random junk.
  • Patch management: keep operating systems, browsers, and applications updated within the scheme's time windows. Unsupported Windows or abandoned apps are a common fail point.

OwnerSec's blunt translation for a 10–40 person company: unique passwords in a manager, MFA on email and finance, automatic updates, malware protection on every laptop, and a router that is not still using admin/admin. That is not the whole certificate, but it is where most of the practical work sits.

Basic vs Cyber Essentials Plus

There are two common tiers:

  • Cyber Essentials (sometimes called "basic"): self-assessed questionnaire, verified by a certification body. Lower cost and effort. Enough for many private-sector supplier questionnaires.
  • Cyber Essentials Plus: same baseline, plus a practical technical assessment (hands-on tests against sample devices and services in scope). Higher cost and more preparation. Often asked for in public-sector or higher-assurance supply chains.

Start with the tier your customers actually ask for. Buying Plus because a LinkedIn ad said so is a waste if nobody in your pipeline requires it.

Who typically needs it (and who can wait)

Pursue Cyber Essentials sooner if:

  • You bid on public-sector work, frameworks, or larger private buyers that list it as a mandatory or preferred control.
  • Insurers or brokers have started asking for evidence of baseline controls.
  • You handle personal data or client systems and want an external, recognised baseline rather than "we think we are fine".
  • You already have MFA, patching, and a password manager in place and need a structured way to prove it.

You can wait (and spend on higher-leverage hygiene first) if:

  • No customer or tender has asked for it in the last year.
  • You still share admin passwords in WhatsApp or a spreadsheet.
  • Half the estate is on unsupported operating systems.
  • You have never enforced MFA on Microsoft 365 / Google Workspace email.

In that last group, fix the basics first. A certificate on top of shared passwords is expensive theatre.

Rough cost, effort, and timeline for under-50 staff

Indicative only for 2026 (verify with a licensed body before budgeting):

  • Basic certification fees are often in the low hundreds of pounds for small scopes, plus your internal time.
  • Plus is materially more expensive because of the practical assessment.
  • Internal effort for a tidy under-50 firm with modern SaaS can be days to a couple of weeks of focused work. Messy estates take longer.
  • Allow time to define scope: which devices, which cloud services, which locations. Scope games that exclude everything useful will be challenged or commercially pointless.

OwnerSec does not sell certification. We explain the landscape so you can decide whether to chase the badge or invest in the underlying controls first.

How it sits next to password managers, MFA, and VPN

Different tools, different jobs:

  • Password manager: makes unique credentials practical. Strongly supports access control.
  • MFA: blocks many takeovers even when a password leaks. Often expected inside Cyber Essentials answers.
  • VPN: helps on untrusted networks and some remote-access patterns. Helpful in places, not a substitute for the five controls.
  • Cyber Essentials: the structured baseline and (if you certify) the external evidence.

OwnerSec's usual order for owner-managers: password manager and MFA, then patching and malware protection, then decide on VPN based on travel, then Cyber Essentials if a buyer or insurer asks.

A practical starter checklist

Before you talk to a certification body:

  • List every laptop, desktop, and phone that touches company email or client data.
  • Confirm every staff member has a unique account for email and core tools (no shared "office@" password).
  • Turn on MFA for Microsoft 365 / Google Workspace and for banking/finance tools.
  • Roll out a team password manager so people stop reusing passwords.
  • Enable automatic OS and browser updates; retire anything that cannot be patched.
  • Confirm malware protection is on and reporting on every in-scope device.
  • Change default router/admin passwords and note your firewall rules at a basic level.
  • Write down your scope in one page: people, devices, cloud apps, office network.

If more than two of those are red, pause the certificate and fix the red items. The questionnaire will only surface what you already know.

Recommended next step (affiliate placeholders)

Most SMEs starting Cyber Essentials preparation get stuck on unique passwords and MFA. If you do not yet have a team password manager, that is the highest-leverage buy before you pay a certifier:

For the certificate itself, use the official NCSC / IASME scheme pages and a licensed certification body. OwnerSec does not take affiliate commission on certification fees.

Written for UK SME owners. More guides · How we make money