Cyber security requirements for UK businesses
How to protect your business from cyber threats and comply with UK cyber security requirements. Includes Cyber Essentials …
How to achieve Cyber Essentials certification for your business. Covers the five technical controls, certification levels and costs, the assessment process, and requirements for government contracts.
Get Cyber Essentials certified to protect your business from cyber attacks. Choose between Basic (£300-£600) or Plus (£999-£3,000) certification. You must complete a self-assessment questionnaire for Basic or a technical audit for Plus. Certification is mandatory for some government contracts.
How to protect your business from cyber threats and comply with UK cyber security requirements. Includes Cyber Essentials …
Practical, low-cost steps to protect your small business from cyber attacks. Covers the five Cyber Essentials controls, free …
Government-backed scheme helping organisations guard against common cyber attacks. Required for many government contracts involving handling of sensitive …
How to complete the NHS Data Security and Protection Toolkit (DSPT) annual self-assessment if you handle NHS patient …
Understanding what cyber insurance covers, when your business needs it, and how UK GDPR obligations create financial exposure …
Cyber Essentials is the UK government's baseline cyber security certification scheme. It helps you protect your organisation against approximately 80% of common cyber attacks and demonstrates to customers, suppliers, and insurers that you take security seriously.
Getting certified is straightforward for most businesses. The basic level involves a self-assessment questionnaire that you can complete in a few hours if your systems are already reasonably secure. The Plus level adds an independent technical verification.
Certification provides several benefits:
There are two levels of Cyber Essentials certification. Choose based on your risk profile, contract requirements, and the sensitivity of data you handle.
Choose basic Cyber Essentials if you:
Choose Cyber Essentials Plus if you:
Note: You must achieve basic Cyber Essentials before you can apply for Cyber Essentials Plus.
Cyber Essentials certification requires you to implement five core technical controls. These address the most common attack vectors and provide a solid foundation for cyber security.
The most frequent reasons for assessment failure are:
Review these areas before starting your assessment to avoid delays and additional costs.
The certification process is managed through IASME-accredited Certification Bodies. There are over 350 Certification Bodies across the UK.
Review the five technical controls against your current setup. Identify any gaps before starting the formal process. The NCSC provides free guidance on each control area to help you prepare.
Select an IASME-accredited Certification Body to conduct your assessment. Compare prices and turnaround times - costs vary between providers. Check they are listed on the official IASME directory.
For basic Cyber Essentials, you complete an online questionnaire about your IT systems and security controls. Answer honestly - providing false information invalidates your certificate and could have legal consequences for government contracts.
Your Certification Body reviews your answers. They may ask clarifying questions. For straightforward applications, expect a decision within 1-3 business days. Complex IT environments may take longer.
If successful, you receive your Cyber Essentials certificate, valid for 12 months. You can display the Cyber Essentials badge on your website and marketing materials. Your certification is listed on a public register.
If pursuing Cyber Essentials Plus, the Certification Body schedules an independent technical audit including authenticated vulnerability scanning and verification that controls are working as described.
Cyber Essentials certification is mandatory for suppliers bidding on certain government contracts. The requirement applies to contracts that involve:
Which level is required?
Contract specifications state which level is required. If in doubt, check with the contracting authority before bidding.
Supply chain implications: If you are a subcontractor on a government contract, you may also need certification. Prime contractors increasingly require Cyber Essentials from their supply chain.
Cyber Essentials certificates are valid for 12 months. You must renew annually to maintain your certified status.
Annual renewal process:
What changes each year:
The Cyber Essentials requirements are updated periodically to address evolving threats. The April 2025 "Willow Question Set" introduced strengthened requirements for multi-factor authentication and faster patching timescales. Review the current requirements before each renewal.
If your certificate expires:
Direct costs:
Time investment:
Hidden costs to consider:
For most small businesses with modern, cloud-based systems, the hidden costs are minimal. Businesses with legacy systems or complex IT environments may need more preparation.