Cyber Essentials Explained: A Plain-English Guide for UK Small Businesses
Cyber Essentials is a UK government-backed scheme that checks five basic security controls every business should have. It reassures customers, is often required to win public-sector and larger contracts, and can support insurance. This guide explains the controls, the difference between Cyber Essentials and Cyber Essentials Plus, and how to get certified without the jargon.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
What Cyber Essentials actually is
Cyber Essentials is a UK government-backed certification scheme. It was created by the National Cyber Security Centre (NCSC) and is run day-to-day by IASME, the NCSC’s delivery partner. In plain terms, it is a checklist of five basic security controls that every business should have in place, plus a way to prove to other people that you have them.
That second part matters. Plenty of businesses do sensible things already but have no way to show a customer, a bank or an insurer that they take security seriously. Cyber Essentials gives you a recognised badge that says: we have covered the basics.
It is deliberately not complicated. The scheme targets the common, opportunistic attacks that hit small businesses every day, rather than the rare, highly targeted ones you see in the news. Get the five controls right and you close the doors that most attacks walk straight through.
Cyber Essentials is not about turning your business into a fortress. It is about closing the open doors that opportunistic attacks walk through every day.
The five controls, in plain English
Cyber Essentials checks five areas. Here is what each one means for a normal small business.
1. Firewalls
A firewall sits between your devices and the internet and decides what traffic is allowed in and out. Every business needs one. In practice this usually means the firewall built into your internet router and the software firewall built into Windows or macOS. The scheme wants these switched on and configured properly, not left on factory defaults with the admin password still set to “admin”.
2. Secure configuration
Devices and software often ship with settings chosen for convenience, not safety: default passwords, extra accounts, features you will never use. Secure configuration means tightening these up. Remove or disable what you do not need, change default passwords, and lock down the settings that could be abused.
3. User access control
People should only have access to what they actually need to do their job. That means everyone has their own account (no shared logins), administrator accounts are used only for admin tasks, and access is removed promptly when someone leaves. Strong, unique passwords and multi-factor authentication are central here. A password manager makes this realistic for a busy team; we often set staff up with Proton Pass, which lets everyone use long, unique passwords without trying to remember them.
4. Malware protection
You need a way to stop malicious software running on your devices. For most small firms this is the anti-malware protection built into Windows (Microsoft Defender) or a reputable equivalent, kept switched on and up to date. On phones and tablets it also means only installing apps from official app stores.
5. Security update management (patching)
Software makers release updates that fix security holes. Attackers actively hunt for machines that have not applied them. This control means keeping operating systems and applications updated, turning on automatic updates where you can, and removing software that is no longer supported and can no longer be patched.
Cyber Essentials vs Cyber Essentials Plus
There are two levels, and the difference is simple.
- Cyber Essentials is a verified self-assessment. You answer a set of questions about how your systems are set up, and a qualified assessor reviews your answers. It confirms that you have the five controls in place.
- Cyber Essentials Plus covers exactly the same five controls, but an assessor also carries out a hands-on technical audit. They test a sample of your devices and check that what you said in the questionnaire is genuinely true in practice.
Think of standard Cyber Essentials as “we declare we have the controls, and that declaration is checked”, and Cyber Essentials Plus as “an independent expert has verified it themselves”. Plus costs more and takes longer because of the testing involved.
Which do you need? Often the contract or framework you are chasing will tell you. Many buyers accept standard Cyber Essentials; some, particularly in the public sector and larger supply chains, specifically require Plus. A sensible route is to achieve standard certification first and step up to Plus when a client asks for it.
Why bother? Contracts, insurance and trust
There are three practical reasons small businesses get certified.
It wins and keeps contracts. Cyber Essentials is mandatory for many UK government contracts that involve handling certain information, and larger private companies increasingly require it from their suppliers before they will work with them. If you sell to the public sector, to accountants, to solicitors or into any regulated supply chain, being certified can be the difference between making the shortlist and being ruled out on paper.
It can support your insurance. Many cyber insurance policies now ask about your security controls, and having Cyber Essentials makes those conversations far simpler. The scheme also includes cyber liability insurance for eligible smaller UK organisations that certify to the whole company, subject to the scheme’s terms. Always read the specifics, but it is a genuine benefit.
It builds trust. The badge tells customers, partners and staff that you take protecting their data seriously. In sectors where you handle sensitive information, that reassurance has real commercial value.
How to get certified: the practical steps
Here is what the journey usually looks like.
- Understand the scope. Decide what is being certified. Best practice is to cover your whole organisation, including staff laptops, phones, servers and the cloud services you use.
- Do a readiness check. Compare your current setup against the five controls and find the gaps. Common failures are missing multi-factor authentication, unsupported software still in use, and updates not being applied.
- Fix the gaps. Turn on multi-factor authentication, remove old software, sort out your update process and tidy up user accounts. This is usually the part that takes the most time.
- Complete the self-assessment. Answer the official questionnaire honestly and submit it to a certification body for review.
- Add Plus if required. If you need Cyber Essentials Plus, an assessor then carries out the hands-on technical audit.
- Re-certify each year. Certification lasts 12 months, so plan to keep the controls in place and renew.
None of this is beyond a small business, but it can be fiddly if IT is not your day job, and one wrong answer can mean a failed submission and wasted fees.
How Dacros helps
We help businesses across Leeds and Yorkshire get Cyber Essentials-ready and stay that way. That means running the readiness check for you, fixing anything that would fail, guiding you through the questionnaire, and preparing you properly if you need Cyber Essentials Plus. Because we manage the underlying cyber security and IT support too, the controls stay in place all year rather than being scrambled together the week before renewal.
If you are not sure where you stand today, book a free IT and security review. We will tell you honestly how close you are and what it would take to get certified. You can also see straightforward pricing for ongoing support.
Frequently asked questions
How long does Cyber Essentials take to get?
If your systems are already in reasonable shape, the self-assessment can be completed and submitted in a matter of days. Where fixes are needed first (such as enabling multi-factor authentication or removing old software), allow a few weeks. Cyber Essentials Plus takes longer because it adds a hands-on technical audit.
Do I need Cyber Essentials or Cyber Essentials Plus?
Cyber Essentials (the self-assessment) is enough for many businesses and to satisfy a lot of contract requirements. Cyber Essentials Plus is required when a client or framework specifically asks for the independently tested version. Check the contract wording before you decide.
Does Cyber Essentials expire?
Yes. Certification lasts 12 months, then you re-certify. This keeps your controls current as your systems and staff change over the year.
Will Cyber Essentials stop us being hacked?
No single scheme guarantees that. Cyber Essentials is designed to stop the common, opportunistic attacks that make up the bulk of incidents against small firms. It is a strong, sensible baseline, not a promise of total protection.
Can Dacros help us get certified?
Yes. We help Leeds and Yorkshire businesses get ready for Cyber Essentials and Cyber Essentials Plus, fix anything that would fail, and support you through submission. Book a free review to see where you stand.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.