P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Guide

What is Cyber Essentials?

The UK government-backed certification for basic cyber hygiene. The five controls, what it costs, and the answers that fail you outright.

Cyber Essentials is a UK government-backed certification scheme covering five technical controls that between them stop the majority of commodity cyber attacks. It is deliberately basic, which is the point: it is a floor rather than a ceiling. It is also pass or fail, and a small number of answers fail the whole assessment regardless of how well you do everywhere else. Knowing which ones before you start is worth more than any readiness score.

Last reviewed:

What it is, and who runs it

Cyber Essentials is a UK government-backed certification scheme. It is owned by the National Cyber Security Centre and delivered by IASME, which accredits the certification bodies that assess you. That division matters when you are choosing who to work with: the scheme is one thing, and the body selling you help with it is another.

The scheme covers five technical controls. The NCSC's argument for choosing those five is that between them they stop the large majority of commodity attacks, meaning the untargeted, opportunistic ones that make up most of what actually happens to most organisations. It is deliberately basic. That is the design rather than a shortcoming: it is a floor, and it is meant to be one that every organisation can reach.

What the scheme covers

  1. Control 1Firewalls
  2. Control 2Secure configuration
  3. Control 3User access control
  4. Control 4Malware protection
  5. Control 5Security updates
All five, across everything in your defined scope. Scope is the decision that everything else depends on, and it is made before any of the controls are considered.

The two marked in red are where the outright failures live, and they are the subject of the next section.

Briefly, what each one asks for.

Firewalls. Every device that connects to the internet sits behind a correctly configured boundary or software firewall. The common gap is not the office perimeter but the laptop on a home network, which is now the normal case rather than the exception.

Secure configuration. Devices and software are set up to reduce unnecessary exposure: default passwords changed, unused accounts and software removed, unnecessary services turned off. This is the control that fails quietly, because a default that nobody chose is nobody's responsibility.

User access control. Accounts are assigned to named individuals, administrative privilege is granted only where it is needed and used only for administrative work, and access is removed when somebody leaves. Standing administrative rights on everyday accounts are the classic finding here.

Malware protection. In-scope devices are protected by one of the permitted approaches: anti-malware software, application allow-listing, or running untrusted code only inside a sandbox. Any of the three is acceptable, which surprises organisations who assume the scheme mandates a product.

Security update management. Software is licensed and supported, unsupported software is removed, and high-risk or critical fixes are applied within fourteen days. The removal requirement has teeth: an out-of-support operating system anywhere in scope is a failure, and no compensating control fixes it.

None of the five is technically difficult. What makes them difficult is applying them consistently across an estate that nobody has fully enumerated, which is why the scope decision below governs everything.

An illustration of a receding row of tall apertures cut into a dark plane, a beam passing cleanly through the open ones and stopping dead against one that is sealed flat, with the row continuing into shadow beyond it.
The illustration is generated and deliberately wordless. The beam stops rather than dimming, which is the whole design of the scheme: a single answer ends the assessment regardless of how strong everything else is.

Pass or fail, and the answers that decide it

Not scored. Pass or fail, and three answers decide it

There is no score. Three answers decide the result.Most questions cost you that question. These fail the whole assessment, whatever else is true.THE FIVE CONTROLSFirewallsSecureconfigurationUseraccess controlMalwareprotectionSecurity updatesThe two in red are where the outright failures live. The other three cost you a question and nothing more.ANSWER NO TO ANY OF THESE AND THE ASSESSMENT FAILSMFA on cloud servicesMandatory wherever a service offers it,free, bundled or paid. Off is a fail.A6.4High-risk and critical updates for operating systems,routers and firewall firmware, within 14 days.A6.5The same 14 days for applications, explicitlyincluding their extensions and plug-ins.Router and firewall firmware is the one that catches people.It rarely sits on the same patching cycle as the rest of the estate, and A6.4 does not care.Requirements v3.3, the Danzell question set, for assessment accounts created from 26 April 2026. Cloud services can no longer be excluded from scope.
Every word here is real text, which matters on a page whose facts move: the question set changed in April 2026 and will change again. The five controls are the scheme's own structure; the two in red are where the outright failures sit.

This is the part most introductions bury, and it is the single most useful thing to know before you begin. Cyber Essentials is not scored. There is no percentage, no maturity level and no partial credit. Most questions cost you a pass on that question. A small number fail the entire assessment whatever else is true.

The answers that fail the whole assessment

RequirementWhat it saysWhy it catches people
MFA on cloud servicesMulti-factor authentication is mandatory for all cloud services where it is availableIt makes no difference whether the feature is free, bundled or costs extra. An available option left switched off is a failure
Question A6.4High-risk or critical security updates for operating systems and router and firewall firmware installed within 14 days of releaseRouter and firewall firmware is rarely on the same patching cycle as the rest of the estate, and often on nobody’s cycle at all
Question A6.5The same 14 days for applications, including any associated files and extensionsBrowser add-ins and content management plug-ins land here, and are usually owned by nobody
Wording as published by IASME for the Danzell question set. These are absolute rather than weighted: no amount of strength elsewhere offsets them.

Two observations on that table. The fourteen days runs from the release of the fix, not from the date you found out about it, so a monthly patch cycle does not satisfy it and neither does a fortnightly one that occasionally slips. And the update questions are split deliberately: an organisation with excellent server patching and an unmanaged browser extension estate fails on A6.5 while passing A6.4.

What changed in April 2026

The requirements moved to v3.3, with a new question set named Danzell, published on 13 February 2026 and in force for assessment accounts created from 26 April 2026. Accounts opened before that date keep six months to certify under the previous requirements.

Four changes are worth knowing about.

Cloud services now have a definition, and cannot be excluded. The scheme defines a cloud service as "an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet". Previously organisations argued about what counted. Now the definition is fixed and cloud services cannot be scoped out at all, which closes the most common route to a comfortable-looking scope that did not reflect how the organisation works.

MFA became an outright failure. It was already expected. It is now absolute, on every cloud service that offers it.

Passwordless authentication is promoted. Passkeys are now presented as preferred over passwords rather than as an alternative to them. This is not yet a requirement, and it is a clear signal of where the scheme is going.

Scope description became more demanding, and more useful. Detailed scope descriptions are no longer length-limited, areas excluded from scope must be documented, legal entities have to be named, and separate certificates can be issued per legal entity. For a group structure that last point solves a problem that used to require awkward compromises.

The sequencing mistake

More Cyber Essentials attempts are made expensive by the order of the work than by any technical control.

The clock starts earlier than people think

SIX-MONTH ASSESSMENT WINDOWaccount createdAccount opened firstthe common orderRemediationAssesswindow closes with nothing left if a question failsRemediation firstthe cheaper orderRemediationno clock runningAssessfour months of slack0123456months from the account being created
The six-month window begins when the assessment account is created, not when the questionnaire is submitted. Bar lengths here are schematic: there is no published average remediation time, and the shape is the whole point.

The window is six months from the creation of the assessment account. Nothing about opening that account helps you remediate, and nothing about remediating requires the account to be open. So an account opened at the start of the work converts a comfortable project into a deadline, and the deadline arrives precisely when you least want it: after a failed question, when you need time to fix something and resubmit.

Doing it the other way round feels slower, because there is a period where apparently nothing official is happening. It finishes sooner and more cheaply, and it leaves slack for the thing that goes wrong.

1

Define the scope

Whole organisation, or a defensible subset. v3.3 tightened this considerably: any internet-connected device is in scope unless the exclusion can be justified to an assessor, exclusions must be documented, and cloud services cannot be excluded at all.

You should see: A scope you could defend, covering what your customer actually asked about.

2

Self-assess honestly

Find out where you stand before anyone is watching. An honest internal answer is worth more than a flattering one, because the assessor is not the audience for this step and a comfortable answer here becomes an expensive one later.

You should see: You know which questions you would currently fail, especially the outright ones.

3

Remediate

Fix the things that fail you first. They are not weighted; they are absolute, and no amount of strength elsewhere offsets them.

You should see: The outright failures are closed. Everything else is ordinary work.

4

Then open the assessment account

This is the step organisations reverse, and it is the expensive one. Opening the account before you know your answers spends the window you may need.

You should see: You open it knowing the answers, not hoping.

Scope, and why it decides everything

Scope is settled before a single control is considered, and it determines how much work the other four steps are.

The instinct is to make it small. That instinct is usually wrong for two reasons. A scope narrow enough to be easy is often narrow enough to be useless to the customer who asked for the certificate, and a scope that excludes the messy part of the estate excludes precisely the part an attacker would use. The certificate then says something true about a fragment of the organisation and something misleading about the whole.

The question worth asking early is what the person requesting the certificate believes it covers. If they believe it covers the organisation and it covers one business unit, that gap surfaces during a procurement exercise rather than during the assessment, which is a much worse moment to discover it.

Cyber Essentials Plus, and what the test actually involves

Plus is the same five controls and the same requirements. It does not raise the bar. It verifies that the answers you gave in the self-assessment were true.

An assessor tests a sample of your devices directly rather than reading your description of them. Expect a vulnerability scan of in-scope systems, checks on a sample of end-user devices covering patch levels and configuration, tests of malware protection behaviour, and checks that MFA is genuinely enforced rather than merely available.

This has a useful consequence for how you prepare. Because Plus tests the same claims, there is no separate preparation for it. An honest self-assessment is the preparation, and an optimistic one is the reason Plus assessments fail. The organisations that struggle are the ones whose self-assessment described the intended state of the estate rather than the actual one.

Plus must be completed within three months of the self-assessment being awarded, so the sequencing point above applies with more force if Plus is the destination.

Where it sits next to ISO 27001

Cyber Essentials

  • Five technical controls, prescriptive.
  • Pass or fail, self-assessed under declaration.
  • Days to weeks once remediation is done.
  • Mandatory for some UK government contracts.
  • A floor: basic hygiene, evidenced.

ISO 27001

  • A management system, risk-driven.
  • Certified by an accredited body after Stage 1 and Stage 2.
  • Six to twelve months from a standing start.
  • Asked for by enterprise customers internationally.
  • A system: how you decide what to protect and prove it runs.

They answer different questions and neither substitutes for the other. Cyber Essentials asks whether five specific technical controls are in place. ISO 27001 asks whether you have a process for deciding what to protect and evidence that the process runs.

A reasonable path for a smaller organisation is Cyber Essentials first, because it is achievable, it forces the basics, and it is frequently the thing a UK buyer actually asks for. ISO 27001 follows when a customer requires it, and the work is not wasted: the technical hygiene Cyber Essentials forces is assumed by the later standard rather than replaced by it.

What it costs

The certification fee itself is set by tier according to organisation size and is modest, in the low hundreds of pounds for a small organisation, rising with headcount. IASME publishes the current figures and they are worth checking directly rather than taking from a reseller.

That fee is rarely the real cost. The real cost is remediation, and it varies enormously depending on how much of the estate is already managed. An organisation with centralised device management, enforced MFA and a working patch process may pay little beyond the fee. An organisation discovering its router firmware has not been updated in three years is buying a project, and the certificate is the smaller part of it.

Certification lasts twelve months, so this is a recurring cost rather than a one-off. That is worth planning for deliberately, because the second year is cheap if the controls stayed in place and expensive if the estate drifted back. The organisations for whom Cyber Essentials becomes routine are the ones that treated the first certification as the point at which the controls started, rather than as the point at which the project finished.

Where to go next

The free readiness check on this site separates the answers that fail you outright from the ones that are ordinary remediation, which is the distinction every other free checker leaves out. Nothing you enter leaves your browser.

Common questions

What are the five Cyber Essentials controls?

Firewalls, secure configuration, user access control, malware protection, and security update management. Each addresses a category of attack the NCSC identified as responsible for the majority of successful commodity attacks on UK organisations. All five have to be implemented across everything in your defined scope.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The same five controls and the same requirements. Cyber Essentials is a self-assessment answered under declaration by a board-level representative. Plus adds an independent technical test on a sample of your devices. Plus does not raise the bar; it verifies that the answers you gave were true, which is why an honest self-assessment is the right preparation for it.

What fails a Cyber Essentials assessment outright?

Leaving multi-factor authentication switched off on any cloud service that offers it, and missing the 14-day window for high-risk or critical security updates. The update requirement splits across two questions: A6.4 for operating systems, routers and firewall firmware, and A6.5 for applications including extensions and plug-ins. Answering no to any of these fails the assessment whatever else is true.

How long does Cyber Essentials take?

The questionnaire itself can be completed in a day. The time goes into remediation beforehand, and the sequencing catches people out: the six-month window starts when the assessment account is created, not when you submit. Remediating first and opening the account second is slower to start and considerably faster to finish.

Do we need Cyber Essentials?

It is mandatory for suppliers on certain UK government contracts handling sensitive information, which is why most organisations first encounter it through procurement. Beyond that it is voluntary, and it is a reasonable floor to hold yourself to. It is not a substitute for ISO 27001: one certifies basic technical hygiene, the other certifies a management system.

What changed in the 2026 update?

The requirements moved to v3.3 for assessment accounts created from late April 2026. The headline change is that MFA became mandatory wherever a cloud service offers it, regardless of whether the feature is free or paid, and leaving it off now fails the assessment. A cloud service is also formally defined for the first time and cloud services can no longer be scoped out.

Where to go next

Share this guide

Useful to someone learning this? Pass it on.

← All guides