Skip to content
Glossary
Definition

Cyber Essentials

Cyber Essentials is a UK government-backed certification that confirms a business has five defined cybersecurity controls in place, covering firewalls, device setup, access, malware protection and security updates.

Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre. It confirms your organisation has five defined controls in place: firewalls, secure configuration of devices and software, user access control, malware protection and timely security updates. Two levels exist. The standard certificate is a verified questionnaire. Cyber Essentials Plus adds a hands-on technical audit. It's a twelve-month certificate and you renew it each year.

In practice you first decide the scope: which offices, devices, cloud services and people sit inside the assessment. An IT lead or your managed service provider then checks the five areas against the current requirements, including multi-factor authentication on cloud accounts and remote access. Gaps get fixed, then you submit the questionnaire to an approved body. For Plus, an assessor later tests sample devices and accounts. It's annual work, because the certificate expires.

Certification fails when the scope is narrower than the way people actually work. Home laptops and forgotten cloud apps sit outside the paperwork while staff still use them for company files. An unsupported operating system, or a cloud service still missing MFA, will fail the assessment. Critical updates left beyond fourteen days will fail it too. Passing once then leaving the controls unattended until next year's form is the operational failure. The certificate doesn't prove ongoing security. It records a point in time.

When it matters

  • A tender or government contract lists Cyber Essentials as a requirement.
  • An insurer or larger buyer has asked for a current certificate.
  • Staff use cloud email and remote access without MFA on every account.
  • The existing certificate expires this year and nobody owns recertification.

Cyber Essentials: common questions

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification that checks five cybersecurity controls: firewalls, secure configuration, user access control, malware protection and security update management. An approved certification body reviews a questionnaire you complete about those controls. If you pass, you receive a certificate valid for twelve months. It shows buyers and insurers that those controls have been independently reviewed. It doesn't replace a full security programme, incident response or more advanced monitoring.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The standard certificate is a verified self-assessment. You answer questions about the five controls and an approved body checks the submission. Cyber Essentials Plus uses the same questionnaire, then an assessor tests a sample of devices, accounts and configurations to confirm the answers match reality. Buyers that handle more sensitive work, and some public-sector contracts, ask for Plus. The extra step takes more time and costs more because someone is testing the live environment, not only the paperwork.

Is Cyber Essentials a legal requirement in the UK?

It isn't a general legal duty for every UK company. It becomes a requirement when a contract, tender or insurance policy says so. Central government has required it on many contracts that involve handling personal data or providing certain IT services since 2014. Larger private buyers often copy that condition into their supply chain. If nobody has asked for it, you can still use the five controls as a practical checklist. You don't have to certify until a buyer or insurer needs the certificate.

Ready to talk?

Book a free, no-obligation discovery call. We'll learn about your business and show you exactly how Wanzo can help — with a bespoke proposal within 48 hours.

No commitment. No sales pressure. Just honest advice.