Monitor

Blog › Article

3 September 2026 · Article

What is Cyber Essentials?

Cyber Essentials is the UK government-backed scheme that certifies an organisation has five basic technical controls in place. It's deliberately simple, inexpensive, and aimed at the attacks that cause most of the damage: automated, opportunistic and looking for easy targets.

Who runs it

The scheme was set up by the UK government in 2014 and is backed by the National Cyber Security Centre. It's delivered by IASME, which licenses a network of certification bodies to carry out assessments. You don't buy Cyber Essentials from IASME directly; you go through one of those certification bodies.

What it covers

Five technical controls, applied to everything in scope:

None of these is sophisticated. That's the point: most successful attacks on small and medium organisations exploit something one of these controls would have stopped.

The two levels

Cyber Essentials is a self-assessment. You complete a questionnaire, a board-level director or equivalent signs it as true, and an assessor reviews it.

Cyber Essentials Plus has the same requirements but adds a technical audit: an assessor tests a sample of your devices and what faces the internet. You need Cyber Essentials first, and Plus has to follow within three months. See Cyber Essentials or Cyber Essentials Plus?

Why organisations get it

How to get it

  1. Decide your scope: usually the whole organisation. See Cyber Essentials scope.
  2. Check your estate against the five controls, starting with the automatic-fail items: MFA on cloud services and high-risk updates within fourteen days.
  3. Choose a certification body and complete the questionnaire.
  4. Have a board-level director or equivalent sign the declaration.
  5. Fix anything the assessor raises, and receive the certificate.

The certificate is valid for twelve months. The fee depends on organisation size; see what Cyber Essentials costs.

What it isn't. Cyber Essentials isn't a guarantee against attack, and it doesn't cover everything a mature security programme would. It's a floor, not a ceiling — and because it's certified on one day, it's only as good as how well the controls are kept up afterwards.

Quick answers

Is Cyber Essentials a legal requirement?

No. It's voluntary, but some contracts, including certain government contracts, require it.

How long does it take?

For a small, well-run organisation, the questionnaire can be completed in a day or two. The time goes into fixing whatever the questionnaire turns up.

How long does a certificate last?

Twelve months. It must be renewed each year.