Cyber Essentials has quietly stopped being optional. Insurers ask whether you hold it, and increasingly price your premium accordingly. Public sector contracts require it outright. Larger clients put it on tender documents as a tick-box, and a missing tick can be the end of the conversation.
The good news is that it is far less painful than it sounds, and most businesses are closer to passing than they expect.
What it actually is
Cyber Essentials is a UK government-backed scheme, run by IASME on behalf of the National Cyber Security Centre. It certifies that you have five basic technical controls in place:
- Firewalls — controlling what can reach your network from outside
- Secure configuration — devices and software set up sensibly rather than left on defaults
- Security update management — updates applied, in reasonable time
- User access control — people having the access they need and no more
- Malware protection — something competent watching for the obvious threats
None of that is exotic. It is the list of things you should be doing anyway. Which is why most businesses we assess are already most of the way there — they need the remaining gaps closed and the evidence assembled, not a wholesale rebuild.
What changed in April 2026
The scheme moved to version 3.3 for assessments started after 27 April 2026, and one change matters more than the rest.
Multi-factor authentication is now required on every cloud service that offers it. Not recommended — required. If a cloud service you use supports MFA and you have not switched it on, that is an automatic fail, however good the rest of your setup is.
Two related changes come with it. “Cloud service” now has a formal definition and cannot be left out of scope, so the mail platform or file-sharing tool somebody forgot to mention is in whether you like it or not. And the scoping language has been tightened, which in practice widens what counts as in-scope.
The update also leans harder towards passwordless sign-in — passkeys and hardware keys — as the preferred approach rather than passwords plus a code.
If you were certified before April, none of this bites until you renew. It will bite then, and MFA coverage is the thing worth checking first.
Most businesses fail on evidence and MFA, not on security. The security is usually fine.
How we work
We are not a Certification Body. We prepare you for certification, and an IASME-licensed body assesses the result.
We think that is the right way round. Doing the technical work and then marking the same homework is an awkward position for anyone to be in, and an independent assessment is worth more to you — and to whoever is asking you for the certificate.
What we actually do:
- An honest assessment of where you stand today, including what already passes
- The technical work to close the gaps — MFA rollout, update policies, account tidying, configuration
- Writing the policies you are asked for, at the length they actually need to be
- Getting your answers straight before submission, so the assessment is not a guessing game
- Staying with it if anything comes back needing clarification
No upselling tools you do not need. No fifty-page security policy nobody will ever read.
Cyber Essentials Plus
Cyber Essentials is a self-assessment, reviewed by the Certification Body. Cyber Essentials Plus adds an independent technical audit — someone checks your actual machines rather than taking your word for it.
Some contracts and some insurers specifically require Plus. If yours does, say so at the outset: the Plus audit has to follow on from your basic certification within a defined window, so it is much easier to plan for from the start than to bolt on afterwards. We prepare systems to pass it first time rather than discovering problems during the audit.
What it costs
The certification fee goes to IASME and depends on your headcount:
| Organisation size | Certification fee |
|---|---|
| 0–9 employees | £320 + VAT |
| 10–49 employees | £440 + VAT |
| 50–249 employees | £500 + VAT |
| 250+ employees | £600 + VAT |
Our work is separate and depends on how much closing the gaps takes — which is exactly what the initial assessment tells us. You get that figure before we start, not afterwards.
Certification lasts 12 months and is then renewed. Renewals are usually far quicker than the first time, because the hard part is already done.
Getting started
Tell us roughly how many staff and machines you have, and whether anyone has asked you for the certificate specifically. We will tell you where you stand and what it would take.
If it turns out you are already close, we will say so.