
How to get Cyber Essentials certified in the UK
How do I get Cyber Essentials certified in the UK?
Define your scope, meet the five technical controls, complete the IASME self-assessment questionnaire through a certification body, and submit it for review. Most UK SMEs complete it in two to six weeks. Cyber Essentials Plus adds an independent technical audit of a sample of your devices.
What Cyber Essentials is
A UK government-backed certification scheme administered by IASME on behalf of the National Cyber Security Centre. It covers a baseline of technical controls that defend against common internet-based attacks. It is a requirement for many UK public sector contracts and is increasingly asked for in private supply chains.
Step 1 - Define scope
Scope is the first decision and the one that causes most problems. You can certify the whole organisation or a defined subset, but a partial scope must be a genuine boundary, not a convenience.
Your scope needs to account for every device that accesses organisational data - including personally owned laptops and phones used for work, and every cloud service you use.
Step 2 - Meet the five controls
Firewalls. Boundary firewalls and host firewalls enabled on all in-scope devices. Default administrative passwords changed. No unnecessary services exposed to the internet.
Secure configuration. Remove or disable unused accounts and software. Change default passwords. Disable auto-run. Apply a documented device build.
User access control. Individual accounts, no shared logins. Administrative privileges granted only where needed and used only for administrative tasks. Multi-factor authentication on all cloud services. A working leaver process that removes access promptly.
Malware protection. Anti-malware on all in-scope devices, kept updated, or application allow-listing where that is the chosen approach.
Security update management. All software supported by its vendor and licensed. High-risk and critical updates applied within 14 days of release. Unsupported software removed from scope.
Step 3 - Choose a certification body
Certification is issued through IASME-accredited certification bodies. Fees vary by organisation size; a small business typically pays a few hundred pounds for the base level, with Cyber Essentials Plus costing significantly more because it includes an audit.
Step 4 - Complete the questionnaire
The self-assessment runs to roughly 70 questions across the five controls plus scope and organisational detail. Answers must be truthful and signed off by a board-level representative.
Expect to be asked for specifics: which anti-malware, which update policy, how MFA is enforced, how many devices of each type, and what your cloud services are.
Step 5 - Submit and remediate
The certification body reviews your answers. If something fails, you generally get a short window to fix it and resubmit. Passing awards certification for twelve months.
Step 6 - Consider Cyber Essentials Plus
Plus is the same five controls, verified independently. An assessor tests a sample of devices, runs vulnerability scans and checks that malware protection and update management work as described. It is materially more credible to a buyer, and materially harder to pass without the underlying work being real.
Where businesses fail
Unsupported software in scope. An old operating system or an end-of-life application will fail the assessment outright.
The 14-day patching rule. Common, and usually a monitoring problem rather than a patching one - you cannot evidence what you do not measure.
Administrative accounts used for daily work. Very common and straightforward to fix.
Personal devices forgotten. A director’s personal laptop reading company email is in scope.
MFA gaps. One cloud service without it fails the control.
No leaver process. Accounts belonging to people who left last year are found routinely.
How long it really takes
Two to six weeks for a business in reasonable shape. Three months or more if unsupported systems have to be replaced first. The assessment itself takes days. The remediation is the timeline.
What it does not cover
Cyber Essentials is a baseline, not a security programme. It says nothing about monitoring, detection, incident response, backup testing or supplier risk. If clients are auditing you, ISO 27001 is the next step.
NVOY delivers Cyber Essentials readiness and certification support as part of IT Security.
BLOGS


