How do I get Cyber Essentials Certified?
How do I get Cyber Essentials Certified?
Getting Cyber Essentials certified involves checking that your organisation meets five core technical security controls, completing an online verified self-assessment and having your answers reviewed by a qualified assessor working through an IASME-licensed Certification Body.
Cyber Essentials is the UK Government-recommended minimum cyber security standard for organisations. The National Cyber Security Centre developed the scheme around five technical controls designed to reduce exposure to common internet-based cyber threats. These controls cover firewalls, secure configuration, security update management, user access control and malware protection.
The process suits organisations of many different scales, including sole traders, charities, small companies, professional firms, technology providers and larger businesses. You do not need a large internal cyber security department to achieve certification, but you do need to understand your technology and meet the requirements accurately across the agreed assessment scope.
UK Cyber Security Group provides Cyber Essentials certification and is a registered Cyber Essentials Certification Body. The company supports organisations that want to complete the self-assessment independently as well as businesses that need additional help with the certification process.
Start by understanding what Cyber Essentials actually checks
Cyber Essentials does not attempt to assess every possible cyber security risk facing your organisation. Instead, it concentrates on a focused set of technical controls that address many of the common routes criminals use to attack businesses.
The NCSC describes Cyber Essentials as the minimum cyber security standard it recommends for organisations. The scheme aims to help businesses protect themselves from common internet-based threats and gives customers greater confidence that fundamental security controls are in place.
This focused approach makes Cyber Essentials particularly useful for smaller organisations. Instead of beginning with a large governance framework, the business starts with practical questions about the devices, accounts, software, networks and cloud services it uses.
Certification also provides external verification. You complete the assessment, but a qualified assessor reviews your answers against the official requirements before the certificate can be issued. IASME licenses Certification Bodies to perform that work.
The five controls form the foundation
Every Cyber Essentials applicant needs to understand the five technical controls.
Firewalls
Firewalls help control connections between your devices or networks and the internet.
The aim is to prevent unnecessary or unauthorised access while allowing legitimate business traffic.
An organisation should understand how its internet connections receive protection and who has authority to change relevant settings.
The NCSC describes this control as creating a security filter between the internet and your network.
Secure configuration
Computers, cloud services and other technology often arrive with settings that prioritise convenience rather than security.
Secure configuration focuses on reducing unnecessary exposure.
Businesses should remove or disable features they do not need, manage accounts appropriately and avoid leaving unsafe default settings in place.
The NCSC describes the aim as setting computers up securely to minimise opportunities for criminals to find a route into the organisation.
Security update management
Software vulnerabilities can give attackers a route into systems.
Security update management requires organisations to use supported software and manage relevant security updates in line with the current Cyber Essentials requirements.
Unsupported software creates a major issue. IASME states that an organisation cannot achieve Cyber Essentials when unsupported software remains within the assessment scope.
This is one of the areas worth checking before you start the formal application.
User access control
Not every employee needs access to every system.
Cyber Essentials expects organisations to control user access and limit privileges according to genuine business need.
Administrator accounts need particular attention because they provide greater control over devices and systems.
The NCSC describes this control as managing who can access organisational data and services and what level of access each person receives.
Malware protection
Malicious software can steal information, interfere with services or give criminals access to systems.
The malware protection control requires organisations to use appropriate measures to prevent malicious software from causing harm.
The NCSC describes this control as identifying and stopping viruses or other malicious software before they can damage the organisation.
What are the key requirements for achieving Cyber Essentials certification?
The first requirement is to meet the current Cyber Essentials technical standard across the agreed scope.
As of August 2026, the current Cyber Essentials Requirements for IT Infrastructure version is v3.3. The NCSC states that v3.3 became effective on 27 April 2026. Applications that started before that date may continue under the earlier requirements that applied when they began.
You need to identify the relevant technology used by your organisation and answer the assessment questions accurately.
The assessment looks at areas such as devices, operating systems, software, internet connections, user accounts, administrator privileges, cloud services, authentication, security updates and protection against malicious software.
You also need to ensure that unsupported software does not remain inside the assessment scope. IASME identifies unsupported software as an automatic reason that an organisation cannot achieve certification.
The assessment also requires senior management involvement. IASME states that a board member must sign a declaration confirming that the information submitted through the verified self-assessment is true.
Accurate answers matter. Cyber Essentials is not about selecting whichever answer sounds most secure. Your responses need to describe what the organisation genuinely does.
Get your scope right before answering the questions
Scope defines which parts of your organisation the Cyber Essentials assessment covers.
Getting this wrong can create unnecessary difficulty later.
Start by understanding your business technology. Identify the devices employees use, the networks they connect through, the cloud services that support business activity and the software that falls within the assessment.
Remote working also matters.
A company may operate from one office while employees access cloud services from home, client sites or other locations. Those arrangements can still form part of the Cyber Essentials environment.
Cloud services deserve particular attention because modern businesses rely heavily on hosted applications. Email, file storage, accounting platforms, customer management systems and collaboration services may all affect the assessment.
Do not assume that a service sits outside the assessment simply because another company hosts it.
A Certification Body can help clarify scope before you submit the formal assessment.
Build an accurate technology inventory
One of the easiest ways to make the certification process harder is to start without knowing what technology your organisation uses.
Create an accurate record of relevant devices and services.
Identify laptops, desktops, servers, mobile devices, routers, firewalls, operating systems, business applications and cloud services.
You should also know which software versions remain in use and whether the suppliers still support them.
This information helps with several assessment questions.
It makes security update management easier.
It helps identify unsupported systems.
It supports user access reviews.
It gives your assessor a clearer picture of the environment.
The inventory does not need unnecessary complexity. It needs enough reliable information for you to answer the Cyber Essentials questions accurately.
How can I prepare my small business for Cyber Essentials assessment?
A small business should begin with a readiness review before opening or submitting the formal assessment.
Start by identifying your devices, software, cloud services and internet connections.
Check whether all software within scope still receives security support.
Review employee accounts and remove accounts belonging to people who no longer work for the business.
Look at administrator access and ask whether each person genuinely needs elevated permissions.
Review multi-factor authentication on cloud services and important accounts.
Check your security update processes.
Confirm that devices use appropriate malware protection.
Review firewall arrangements and remove unnecessary exposure.
The NCSC provides free Cyber Essentials resources, including the current assessment questions and technical requirements.
IASME also provides a free Cyber Essentials Readiness Tool. It uses interactive questions to help organisations understand how their current security compares with the certification requirements and produces guidance for the next steps.
Preparing before you purchase the formal assessment gives you time to resolve issues without placing unnecessary pressure on your team.
Download the questions before starting
You do not need to begin the formal assessment without knowing what you will face.
IASME makes the self-assessment questions available in advance. It specifically recommends downloading the question set and preparing responses before applying.
This approach provides several benefits.
You can identify information that needs input from your IT provider.
You can find unsupported software before the assessor does.
You can check cloud services.
You can review user accounts.
You can ask management for information while you still have plenty of time.
You can also gather evidence for answers that may need additional explanation.
Treat the question set as a practical readiness exercise rather than an exam that you should attempt without preparation.
Choose an official Certification Body
Cyber Essentials certification comes through an IASME licensed Certification Body.
IASME describes Certification Bodies as specially trained cyber security companies that it licenses and assures to provide assessment and certification services. Qualified Cyber Essentials Assessors work through those organisations.
A good provider should explain the assessment process clearly and help you understand how questions relate to your organisation.
Certification Bodies can also provide consultancy support. IASME confirms that applicants can approach them for help understanding assessment questions and how those requirements apply to their company.
UK Cyber Security Group is a registered Cyber Essentials certification body and offers self-assessment certification together with additional support options.
Complete the verified self-assessment
Once you feel ready, you complete the online assessment.
The questions ask about the way your organisation manages the five Cyber Essentials controls.
Answer them according to your current environment.
Do not answer according to what your IT provider intends to configure next month.
Do not assume that a written policy proves a technical control operates.
If the assessment asks whether multi-factor authentication protects a service, the answer needs to reflect the actual configuration.
If it asks whether software receives support, check the relevant vendor information.
If it asks about administrator access, review the actual accounts.
Accurate answers reduce delays and make assessor feedback more useful.
IASME allows six months from the date of application for an organisation to complete and submit the assessment.
Your assessor reviews the submission
Submitting the form does not automatically produce a certificate.
A qualified assessor reviews your answers.
IASME says most assessors aim to return results within three days after submission. Where an answer does not provide enough information, the assessor can return it and ask for clarification.
This review gives the scheme independent assurance.
The assessor looks at whether your answers demonstrate that the organisation meets the Cyber Essentials criteria.
You may receive feedback explaining areas that do not comply.
Treat that feedback as useful security information.
The goal should not simply be changing wording until an answer passes. If the assessor identifies a genuine weakness, correct the security issue itself.
What happens if the first submission does not pass?
An unsuccessful first submission does not always mean starting the entire process again immediately.
IASME states that an applicant receives feedback about areas that do not fully comply. The organisation receives two working days to examine the feedback, address straightforward issues and resubmit its answers for another assessment.
The scheme therefore gives businesses an opportunity to deal with smaller problems identified during assessment.
However, this period should not become your main implementation plan.
Complex issues may take longer than two working days to resolve.
Unsupported systems, major account changes or significant infrastructure weaknesses are better addressed before the formal submission.
Good preparation remains the easiest route.
What software solutions support compliance with Cyber Essentials standards?
No single software solution automatically makes an organisation Cyber Essentials compliant.
Different technologies can support different requirements.
Device management systems can help you understand which computers and mobile devices the business uses.
Identity platforms can help manage users, administrators and multi-factor authentication.
Endpoint security tools can support malware protection.
Update management systems can help organisations monitor whether devices receive security updates.
Asset management platforms can help identify unsupported applications.
Cloud administration dashboards can provide information about accounts, authentication and configuration.
Password managers can help employees maintain unique credentials.
Security monitoring platforms can provide additional visibility around devices and accounts.
The key issue is not whether you own a particular product. The organisation needs to operate the required controls effectively across the agreed scope.
Choose technology based on the security requirement rather than attempting to build an unnecessary collection of tools.
Why Cyber Essentials matters to UK businesses
Cyber threats continue to affect organisations throughout the UK.
The Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber security breach or attack during the previous 12 months. This represented approximately 612,000 UK businesses.
The survey found that smaller and larger organisations all faced incidents, although reported prevalence increased among larger organisations. It found breaches or attacks among 42 per cent of micro businesses, 46 per cent of small businesses, 65 per cent of medium businesses and 69 per cent of large businesses.
Phishing remained the most common problem, affecting 38 per cent of businesses.
These figures reinforce the value of strong basic controls.
Cyber Essentials does not make a company immune from attack. It provides a structured way to address many common weaknesses before criminals can exploit them.
Certification can help with customers and tenders
Cyber Essentials provides more than an internal security review.
The certificate gives customers and partners an externally verified signal that your organisation has addressed the five technical controls within the assessed scope.
The NCSC states that a growing number of organisations require suppliers to hold Cyber Essentials before they can bid for work.
This makes certification particularly relevant for organisations working in supply chains where customers want stronger cyber assurance.
A small company may find that Cyber Essentials gives it a simple way to demonstrate basic security without asking customers to rely solely on internal claims.
Cyber Essentials or Cyber Essentials Plus?
Cyber Essentials and Cyber Essentials Plus assess the same fundamental controls, but they provide different levels of assurance.
Cyber Essentials uses the verified self-assessment process.
Cyber Essentials Plus adds an independent technical audit.
IASME explains that Plus includes technical testing of systems within the Cyber Essentials scope. The audit examines a representative sample of user devices together with relevant internet gateways and servers accessible to unauthenticated internet users.
An organisation normally starts with Cyber Essentials and can then progress to Cyber Essentials Plus when it needs stronger independent assurance.
If a customer or tender specifically requires Plus, check that requirement before beginning so you can plan the certification journey correctly.
Keep evidence while you prepare
Cyber Essentials focuses heavily on technical configuration, but maintaining useful records can still simplify the process.
Keep information relating to your asset inventory, software support, administrator accounts, cloud services and authentication arrangements.
Retain reports from tools that help demonstrate your current position.
If an external IT provider manages relevant systems, make sure you can obtain accurate information from them.
The organisation applying for certification remains responsible for its answers even when another provider manages the technology.
Do not allow your application to depend on assumptions about what an external supplier has configured.
Ask for evidence where necessary.
Make senior management part of the process
Cyber Essentials should not sit entirely with one IT employee.
Senior management needs to understand what the organisation is declaring.
IASME requires a board member to sign a declaration verifying the information provided within the assessment.
That requirement reinforces accountability.
Leaders should understand the scope, major gaps and any significant work required before submission.
Management involvement also helps when the organisation needs time or resources to replace unsupported software, strengthen access control or resolve another issue.
Can I renew my Cyber Essentials certification through an online service?
Yes. Cyber Essentials uses an online assessment process and certification needs annual renewal.
IASME states that Cyber Essentials certification remains valid for 12 months. Organisations must recertify each year if they want to maintain current status.
Renewal involves completing the information again.
IASME explains that this annual resubmission acts as a review of the organisation’s cyber security and notes that assessment questions may change between certification periods.
Do not simply assume that last year’s answers still apply.
Review new devices.
Check cloud services added during the year.
Remove old accounts.
Confirm software remains supported.
Review administrator privileges.
Check current authentication.
An organisation that maintains the five controls throughout the year should find renewal far easier than one that only looks at Cyber Essentials shortly before expiry.
Which companies provide Cyber Essentials certification services in the UK?
Official Cyber Essentials certification comes through Certification Bodies licensed by IASME.
IASME maintains a directory of recognised Certification Bodies throughout the UK and Crown Dependencies. These organisations employ qualified assessors and can assess whether applicants meet the Cyber Essentials requirements.
UK Cyber Security Group provides Cyber Essentials certification and states that it is a registered Cyber Essentials certification body. Its service supports self-assessment certification and organisations that require additional assistance.
When choosing a provider, look beyond the certificate itself.
Consider whether the company communicates clearly, understands cloud services, can help clarify scope and can provide useful guidance when a security gap appears.
If you may later need Cyber Essentials Plus, ask whether the provider can also support the technical audit.
Which UK-based firms offer Cyber Essentials consultancy services?
UK organisations can obtain support from Cyber Essentials Certification Bodies, cyber security consultancies, managed service providers and NCSC Assured Cyber Advisors.
IASME specifically states that Certification Bodies can help organisations understand assessment questions and how those requirements apply to their business.
Cyber Advisors provide another route for smaller organisations that need practical help implementing the Cyber Essentials controls before certification. IASME describes these advisers as NCSC assured professionals who help micro, small and medium organisations prepare for Cyber Essentials.
UK Cyber Security Group provides Cyber Essentials certification together with wider cyber security and compliance support.
The best consultancy support should improve your security rather than merely help you phrase questionnaire answers.
Your organisation should understand what needs fixing and why.
A straightforward route to certification
A practical Cyber Essentials journey begins before you open the assessment portal.
Understand the five controls first.
Download the current assessment questions.
Identify your devices, software and cloud services.
Confirm that software remains supported.
Review user and administrator accounts.
Check multi-factor authentication.
Review security updates, malware protection and internet exposure.
Resolve gaps before submission.
Choose an IASME licensed Certification Body.
Complete the online verified self-assessment accurately.
Respond promptly when your assessor requests clarification.
Correct genuine weaknesses rather than trying to work around them.
Once the assessor confirms that you meet the scheme requirements, your Certification Body can issue your Cyber Essentials certificate.
Keep the controls working after certification
Receiving the certificate should not mark the end of the security work.
Your business continues changing.
Employees join and leave.
New devices enter the organisation.
Cloud services get added.
Software support ends.
Criminal techniques evolve.
Maintain the controls as part of normal business activity.
Review accounts when employees change roles.
Remove access promptly when people leave.
Keep software supported.
Apply security updates.
Continue using multi-factor authentication.
Monitor your technology inventory.
When renewal approaches, you should already have most of the information you need.
UK Cyber Security Group provides Cyber Essentials certification and support for businesses that want a straightforward route through the process.
For most organisations, achieving Cyber Essentials comes down to three things: understand the current requirements, make sure the controls genuinely operate and submit accurate information for independent assessment.
Cyber Essentials offers a practical starting point for improving business security. By working through the five controls carefully and maintaining them after certification, your organisation gains more than a certificate. It gains a clearer understanding of its technology, stronger protection against common threats and a recognised way to demonstrate that security commitment to customers and partners.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










