Cyber Essentials Certified logo

Cyber Essentials Certified

National Cyber Security Centre

Basic cybersecurity certification for UK businesses.

The Cyber Essentials Certified costs $405 USD, and takes approximately 4 weeks. Over 30,000+ professionals hold this certification worldwide. Renewal costs $405 USD every 12 months.

For Individuals
Technology
Industry
Financial

Key Strengths

  • UK government-backed scheme with strong institutional credibility
  • Mandatory for many UK government contract bids, driving real demand
  • Affordable entry-level cost starting at £320+VAT, accessible to SMEs
  • Two-tier structure (Essentials and Plus) allows progressive assurance
  • Covers five core technical controls addressing the most common cyber threats
  • Recognised across healthcare, finance, education, and public sector

Ideal For

Cyber Essentials is best suited for UK-based small and medium-sized businesses, charities, and public sector organisations seeking a government-recognised baseline cybersecurity credential. It is particularly valuable for organisations bidding on UK government contracts, where certification is often mandatory, and for those wanting a structured, affordable entry point into formal cybersecurity assurance.

Target Audiences

Professionals

Relevant Roles

Auditor
Consultant

Industries

Technology
Government
Healthcare
Finance

Alignment & Recognition

Accrediting Body

IASME Consortium

Scope

Values/Processes
Performance

How to Get CertifiedAI-synthesized

  1. Download the free Question Set: Visit the Cyber Essentials website and download the self-assessment questionnaire ('Question Set') and the 'Requirements for IT Infrastructure' document to understand what's expected before you begin.
  1. Use the free Readiness Tool: Complete the NCSC's online Readiness Tool to receive a tailored action plan identifying gaps in your current IT controls and what you need to fix before applying.
  1. Implement the five technical controls: Address the five core control areas — firewalls, secure configuration, user access control, malware protection, and patch management — across all in-scope devices and systems.
  1. Choose your certification level: Decide between Cyber Essentials (self-assessment with independent review) or Cyber Essentials Plus (self-assessment plus independent technical audit). Consider Plus if you handle sensitive data or want stronger assurance.
  1. Select an accredited certification body: Find an IASME-accredited certification body via the IASME website. Pricing is tiered by organisation size, starting at £320+VAT for Cyber Essentials.
  1. Complete and submit the self-assessment questionnaire: Answer all questions in the Question Set honestly and accurately, then submit it to your chosen certification body for independent review.
  1. Undergo the Plus audit (if applicable): For Cyber Essentials Plus, an accredited assessor will conduct remote vulnerability scanning and hands-on testing of a sample of in-scope devices, typically over 1–2 days.
  1. Receive your certificate and badge: Upon successful verification, you'll receive your Cyber Essentials certificate and can display the official badge on your website, proposals, and marketing materials. Recertify annually to maintain status.

What the Exam CoversAI-synthesized

Cyber Essentials evaluates organisations against five core technical control areas, which together address the most common vectors used in commodity cyber attacks:

1. Firewalls (Boundary Firewalls and Internet Gateways): Organisations must demonstrate that all internet-connected devices are protected by a properly configured firewall or equivalent network boundary device. This includes ensuring that default passwords are changed, unnecessary services are disabled, and only approved inbound connections are permitted.

2. Secure Configuration: All computers and network devices must be configured securely before deployment. This means removing or disabling unnecessary software, services, and user accounts, and changing any default credentials. The aim is to reduce the attack surface of every device in scope.

3. User Access Control: Organisations must show that user accounts — particularly those with administrative privileges — are carefully managed. Standard user accounts should be used for day-to-day tasks, admin accounts should only be used when necessary, and unused accounts must be removed or disabled.

4. Malware Protection: All in-scope devices must be protected against malware through at least one of three approved approaches: anti-malware software with up-to-date signatures, application whitelisting (allowing only approved software to run), or sandboxing (running applications in a restricted environment).

5. Patch Management (Security Update Management): Software and firmware on all in-scope devices must be kept up to date. Operating systems and applications must be licensed and supported, automatic updates should be enabled where possible, and critical patches must be applied within 14 days of release.

For Cyber Essentials Plus, an independent assessor additionally conducts vulnerability scanning and hands-on testing of a representative sample of devices to verify that the controls are not just documented but effectively implemented in practice.

Market Context & AdoptionAI-synthesized

Cyber Essentials is the dominant entry-level cybersecurity certification in the United Kingdom, with over 30,000 organisations certified since its launch in 2014. Its mandatory status for suppliers bidding on UK government contracts involving the handling of personal data or sensitive information has been a primary driver of adoption, creating a large and stable demand base. The scheme is particularly well-embedded in the public sector supply chain, with NHS Trusts, local councils, and Ministry of Defence suppliers among the most active participants. IASME Consortium, the NCSC's delivery partner, manages the accreditation network and has built a broad ecosystem of certification bodies across the UK.

Within the UK market, Cyber Essentials occupies a distinct niche as a government-endorsed, affordable baseline standard — positioned below the more comprehensive ISO/IEC 27001 but above having no formal cybersecurity assurance at all. It is widely regarded as the appropriate starting point for SMEs and organisations new to formal cybersecurity frameworks. The two-tier structure (Essentials and Plus) allows organisations to progress from self-assessed compliance to independently verified technical assurance, which has helped sustain relevance as cyber threats have evolved. The scheme's technical requirements are updated periodically — a significant revision was introduced in January 2022 — to keep pace with changes in working practices such as cloud adoption and remote working.

Internationally, Cyber Essentials has very limited recognition outside the UK. Organisations operating globally or seeking internationally portable credentials typically look to ISO/IEC 27001, SOC 2, or NIST CSF-aligned frameworks instead. Within the UK, however, demand for Cyber Essentials is growing steadily, driven by increasing government procurement requirements, rising cyber insurance prerequisites, and broader awareness of supply chain risk. The scheme's low cost and clear scope make it particularly attractive to smaller organisations that would find ISO 27001 prohibitively expensive or complex to implement.

History & EvolutionAI-synthesized

Cyber Essentials was launched in June 2014 by the UK government, developed jointly by the Cabinet Office and the then-Communications Electronics Security Group (CESG), which later became part of the National Cyber Security Centre (NCSC) when it was established in 2016. The scheme was created in response to growing evidence that the vast majority of successful cyber attacks exploited a small number of well-understood technical vulnerabilities — and that basic preventive controls could block the majority of them. The government simultaneously mandated that suppliers bidding for contracts involving personal data or sensitive government information must hold Cyber Essentials certification, providing immediate commercial impetus for adoption.

IASME Consortium was appointed as the NCSC's delivery partner to manage the accreditation network and certification body ecosystem. Over the years, the scheme's technical requirements have been updated to reflect the evolving threat landscape and changes in how organisations use technology. The most significant revision came in January 2022, when the requirements were substantially updated to address cloud services, home working, and multi-factor authentication — reflecting the dramatic shift in working practices accelerated by the COVID-19 pandemic. The scheme has grown steadily since launch, surpassing 30,000 certified organisations, and remains the UK government's primary vehicle for raising baseline cybersecurity standards across the economy.

Frequently Asked Questions

Quick Facts

Type

Certification

Regions
United Kingdom
Languages

English

Established

2014

Certified Professionals

30K+

Digital Badge

Available

Cost Breakdown

Registration / Initial$405
Renewal (every 12 mo)$405
First-year total$810

How to Use This Credential

Public Seal/Badge
Online Registry
Marketing Toolkit

Sources & Citations

Content on this page is AI-enriched from primary sources.

National Cyber Security Centre

Last verified Jun 5, 2026