Cyber Essentials Certified
National Cyber Security Centre
Basic cybersecurity certification for UK businesses.
The Cyber Essentials Certified costs $405 USD, and takes approximately 4 weeks. Over 30,000+ professionals hold this certification worldwide. Renewal costs $405 USD every 12 months.
Key Strengths
- UK government-backed scheme with strong institutional credibility
- Mandatory for many UK government contract bids, driving real demand
- Affordable entry-level cost starting at £320+VAT, accessible to SMEs
- Two-tier structure (Essentials and Plus) allows progressive assurance
- Covers five core technical controls addressing the most common cyber threats
- Recognised across healthcare, finance, education, and public sector
Ideal For
Cyber Essentials is best suited for UK-based small and medium-sized businesses, charities, and public sector organisations seeking a government-recognised baseline cybersecurity credential. It is particularly valuable for organisations bidding on UK government contracts, where certification is often mandatory, and for those wanting a structured, affordable entry point into formal cybersecurity assurance.
Target Audiences
Relevant Roles
Industries
Alignment & Recognition
Accrediting Body
Scope
Overview
Cyber Essentials is a UK government-backed scheme designed to help organizations protect against common cyber threats. Launched in 2014 by the National Cyber Security Centre (NCSC), it offers a straightforward, step-by-step framework to boost cybersecurity. Highlights include securing internet connections, controlling data access, and protecting from malware.
The certification, available at basic and plus levels, has been adopted by a range of sectors, including healthcare, finance, and education. It’s mandatory for companies bidding for certain government contracts. Major clients include NHS Trusts and various local councils.
Statistics show that businesses with Cyber Essentials certification are significantly less likely to fall victim to cyberattacks. As of recent reports, over 30,000 organizations have been certified. Key partners in this initiative include IASME Consortium and several cybersecurity firms.
In essence, Cyber Essentials aims to simplify cybersecurity, making it accessible for organizations of all sizes to protect their valuable data.
Requirements & Assessment
Evidence Requirements
Applicants must complete a self-assessment questionnaire (the 'Question Set') covering the five technical control areas. For Cyber Essentials (basic), the completed questionnaire is reviewed and verified by an accredited certification body. For Cyber Essentials Plus, an independent technical audit is also conducted, including vulnerability scanning and hands-on testing of devices and systems to verify that the controls are effectively implemented.
Prerequisites
Assessment Process
For Cyber Essentials (basic), organisations complete a self-assessment questionnaire covering five technical control areas (firewalls, secure configuration, access control, malware protection, patch management). The completed questionnaire is submitted to an IASME-accredited certification body for independent review and verification. For Cyber Essentials Plus, the same self-assessment is required, followed by an independent technical audit conducted by an accredited assessor, including remote vulnerability scanning and hands-on testing of a sample of in-scope devices and systems. The Plus audit typically takes 1–2 days depending on organisation size and network complexity.
Renewal & Maintenance
Cyber Essentials certification is valid for 12 months. To maintain certification, organisations must recertify annually by completing a new self-assessment questionnaire (and, for Plus, undergoing a new technical audit). There is no continuing education requirement; the renewal process mirrors the initial certification process and is priced according to organisation size.
Continuing Education (CPE/CEU)
None. Cyber Essentials does not require continuing professional education credits. Recertification is achieved by completing the full assessment process annually.
Accountability Model
Impact & Outcomes
Salary & Market Value
Cyber Essentials is an organisational certification rather than an individual credential, so direct salary impact data is limited. However, holding the certification is often a prerequisite for winning UK government contracts, which can represent significant revenue for certified organisations. IT professionals and consultants who can implement and manage Cyber Essentials compliance may see increased demand for their services.
Employer Recognition
Consider Alternatives If...
Organisations outside the UK may find limited recognition or relevance compared to internationally accepted frameworks like ISO 27001 or SOC 2. Those requiring deep, comprehensive security assurance beyond baseline controls should consider more rigorous standards rather than relying solely on Cyber Essentials.
Alternative Programs
How to Get CertifiedAI-synthesized
- Download the free Question Set: Visit the Cyber Essentials website and download the self-assessment questionnaire ('Question Set') and the 'Requirements for IT Infrastructure' document to understand what's expected before you begin.
- Use the free Readiness Tool: Complete the NCSC's online Readiness Tool to receive a tailored action plan identifying gaps in your current IT controls and what you need to fix before applying.
- Implement the five technical controls: Address the five core control areas — firewalls, secure configuration, user access control, malware protection, and patch management — across all in-scope devices and systems.
- Choose your certification level: Decide between Cyber Essentials (self-assessment with independent review) or Cyber Essentials Plus (self-assessment plus independent technical audit). Consider Plus if you handle sensitive data or want stronger assurance.
- Select an accredited certification body: Find an IASME-accredited certification body via the IASME website. Pricing is tiered by organisation size, starting at £320+VAT for Cyber Essentials.
- Complete and submit the self-assessment questionnaire: Answer all questions in the Question Set honestly and accurately, then submit it to your chosen certification body for independent review.
- Undergo the Plus audit (if applicable): For Cyber Essentials Plus, an accredited assessor will conduct remote vulnerability scanning and hands-on testing of a sample of in-scope devices, typically over 1–2 days.
- Receive your certificate and badge: Upon successful verification, you'll receive your Cyber Essentials certificate and can display the official badge on your website, proposals, and marketing materials. Recertify annually to maintain status.
What the Exam CoversAI-synthesized
Cyber Essentials evaluates organisations against five core technical control areas, which together address the most common vectors used in commodity cyber attacks:
1. Firewalls (Boundary Firewalls and Internet Gateways): Organisations must demonstrate that all internet-connected devices are protected by a properly configured firewall or equivalent network boundary device. This includes ensuring that default passwords are changed, unnecessary services are disabled, and only approved inbound connections are permitted.
2. Secure Configuration: All computers and network devices must be configured securely before deployment. This means removing or disabling unnecessary software, services, and user accounts, and changing any default credentials. The aim is to reduce the attack surface of every device in scope.
3. User Access Control: Organisations must show that user accounts — particularly those with administrative privileges — are carefully managed. Standard user accounts should be used for day-to-day tasks, admin accounts should only be used when necessary, and unused accounts must be removed or disabled.
4. Malware Protection: All in-scope devices must be protected against malware through at least one of three approved approaches: anti-malware software with up-to-date signatures, application whitelisting (allowing only approved software to run), or sandboxing (running applications in a restricted environment).
5. Patch Management (Security Update Management): Software and firmware on all in-scope devices must be kept up to date. Operating systems and applications must be licensed and supported, automatic updates should be enabled where possible, and critical patches must be applied within 14 days of release.
For Cyber Essentials Plus, an independent assessor additionally conducts vulnerability scanning and hands-on testing of a representative sample of devices to verify that the controls are not just documented but effectively implemented in practice.
Market Context & AdoptionAI-synthesized
Cyber Essentials is the dominant entry-level cybersecurity certification in the United Kingdom, with over 30,000 organisations certified since its launch in 2014. Its mandatory status for suppliers bidding on UK government contracts involving the handling of personal data or sensitive information has been a primary driver of adoption, creating a large and stable demand base. The scheme is particularly well-embedded in the public sector supply chain, with NHS Trusts, local councils, and Ministry of Defence suppliers among the most active participants. IASME Consortium, the NCSC's delivery partner, manages the accreditation network and has built a broad ecosystem of certification bodies across the UK.
Within the UK market, Cyber Essentials occupies a distinct niche as a government-endorsed, affordable baseline standard — positioned below the more comprehensive ISO/IEC 27001 but above having no formal cybersecurity assurance at all. It is widely regarded as the appropriate starting point for SMEs and organisations new to formal cybersecurity frameworks. The two-tier structure (Essentials and Plus) allows organisations to progress from self-assessed compliance to independently verified technical assurance, which has helped sustain relevance as cyber threats have evolved. The scheme's technical requirements are updated periodically — a significant revision was introduced in January 2022 — to keep pace with changes in working practices such as cloud adoption and remote working.
Internationally, Cyber Essentials has very limited recognition outside the UK. Organisations operating globally or seeking internationally portable credentials typically look to ISO/IEC 27001, SOC 2, or NIST CSF-aligned frameworks instead. Within the UK, however, demand for Cyber Essentials is growing steadily, driven by increasing government procurement requirements, rising cyber insurance prerequisites, and broader awareness of supply chain risk. The scheme's low cost and clear scope make it particularly attractive to smaller organisations that would find ISO 27001 prohibitively expensive or complex to implement.
History & EvolutionAI-synthesized
Cyber Essentials was launched in June 2014 by the UK government, developed jointly by the Cabinet Office and the then-Communications Electronics Security Group (CESG), which later became part of the National Cyber Security Centre (NCSC) when it was established in 2016. The scheme was created in response to growing evidence that the vast majority of successful cyber attacks exploited a small number of well-understood technical vulnerabilities — and that basic preventive controls could block the majority of them. The government simultaneously mandated that suppliers bidding for contracts involving personal data or sensitive government information must hold Cyber Essentials certification, providing immediate commercial impetus for adoption.
IASME Consortium was appointed as the NCSC's delivery partner to manage the accreditation network and certification body ecosystem. Over the years, the scheme's technical requirements have been updated to reflect the evolving threat landscape and changes in how organisations use technology. The most significant revision came in January 2022, when the requirements were substantially updated to address cloud services, home working, and multi-factor authentication — reflecting the dramatic shift in working practices accelerated by the COVID-19 pandemic. The scheme has grown steadily since launch, surpassing 30,000 certified organisations, and remains the UK government's primary vehicle for raising baseline cybersecurity standards across the economy.
Frequently Asked Questions
Quick Facts
Certification
English
2014
30K+
Available
Cost Breakdown
How to Use This Credential
Certification Details
Assessment
Verification
Structure
Governance
Fee Structure
Related Certifications
Sources & Citations
Content on this page is AI-enriched from primary sources.
National Cyber Security CentreLast verified Jun 5, 2026