Cyber Essentials Certification: Your Complete Guide to Achieving CE and CE Plus
- shaunflint
- 3 hours ago
- 9 min read
What Is Cyber Essentials?
Cyber Essentials is the UK government-backed cyber security certification scheme developed by the National Cyber Security Centre (NCSC) and delivered through IASME. It establishes the minimum baseline standard of protection that all organisations should implement to defend against the most common internet-based cyber threats.
Designed to be accessible for organisations of all sizes, from micro-businesses to large enterprises, Cyber Essentials provides a clear, cost-effective framework to demonstrate your commitment to cyber security.
The scheme is built around five fundamental technical controls that, when properly implemented, can protect against approximately 80% of common cyber attacks.
What Is Cyber Essentials Plus?
Cyber Essentials Plus represents the higher assurance level of the scheme. It includes all the protections of the standard Cyber Essentials certification but adds independent technical verification.
While Cyber Essentials relies on a verified self-assessment questionnaire, Cyber Essentials Plus requires a qualified assessor from an IASME-accredited Certification Body to conduct hands-on testing of your systems.
This independent audit confirms that your cyber security controls are not only documented but are actively implemented and functioning correctly across your IT infrastructure.
The Five Cyber Essentials Technical Controls
Both certification levels assess your organisation against the same five technical controls:
1. Firewalls
Create a security barrier between your internal networks and the internet. Proper firewall configuration prevents unauthorised access to your systems from external networks and limits the data that can flow in and out of your organisation.
2. Secure Configuration
Ensure all devices and software are configured to minimise vulnerabilities. This includes removing unnecessary user accounts, disabling default passwords, and applying secure settings to all devices, applications, and network equipment.
3. Security Update Management
Maintain up-to-date software across all devices. Regular security updates and patches are essential to protect against known vulnerabilities that cyber criminals could exploit to gain access to your systems.
4. User Access Control
Implement strict controls over who can access your data and services. This includes creating individual user accounts, providing the minimum level of access required for each role, and ensuring administrative privileges are only granted to those who absolutely need them.
5. Malware Protection
Deploy effective malware protection across all devices. This involves using anti-malware software that is kept up to date, configured to scan files automatically, and capable of detecting and removing malicious software before it can cause harm.
The Cyber Essentials Certification Process
Achieving Cyber Essentials certification follows a structured approach:
Step 1: Define Your Scope
Determine which parts of your organisation will be covered by the certification. The scope must include all devices, users, and systems that handle or store your organisation's data. As of April 2026, end-user devices cannot be excluded from the scope, and cloud services must be included.
Step 2: Prepare Your Systems
Review the official Cyber Essentials requirements and assessment questions, available for free download from the IASME website. Use the NCSC's Readiness Tool to assess your current security posture and receive a tailored action plan.
Step 3: Implement the Controls
Address any gaps identified in your preparation. Ensure all five technical controls are properly implemented across your entire scope. This may involve configuring firewalls, updating software, reviewing user access rights, and deploying malware protection.
Step 4: Choose Your Certification Route
You have two options for achieving Cyber Essentials certification:
Self-Led Certification: Register directly with IASME, pay the assessment fee (starting at £320 + VAT for organisations with 0-9 employees), and complete the verified self-assessment questionnaire online. A senior board member or equivalent must sign off on your answers, confirming their accuracy. Your submission is then reviewed and marked by a qualified assessor.
Supported Certification: Engage a Certification Body licensed by IASME. These organisations employ qualified assessors who can guide you through the process, help you understand the assessment questions, and provide support in implementing the required controls before submitting your self-assessment.
Step 5: Receive Your Certificate
Once your assessment is approved, you will receive your Cyber Essentials certificate, which is valid for 12 months. Your organisation will be listed on the official Cyber Essentials certificate register.
The Cyber Essentials Plus Certification Process
Cyber Essentials Plus follows a more rigorous process that builds on your Cyber Essentials certification:
Prerequisite: Achieve Cyber Essentials First
You must first obtain your Cyber Essentials certification through the verified self-assessment. Your Cyber Essentials certificate must be dated within three months of applying for Cyber Essentials Plus.
Step 1: Select a Certification Body
Contact an IASME-accredited Certification Body directly to arrange your Cyber Essentials Plus audit. These organisations employ qualified assessors who are authorised to conduct the technical testing required for CE Plus certification.
Step 2: Technical Audit Preparation
Work with your chosen Certification Body to prepare for the audit. Ensure all documentation is in order and that your systems are ready for testing. The assessor will need access to a representative sample of your devices and systems.
Step 3: Independent Technical Testing
A qualified assessor will conduct comprehensive technical tests, including:
External Vulnerability Scan: A scan of your internet-facing IP addresses to identify any clear vulnerabilities or misconfigurations
Internal Vulnerability Scan: Testing of a representative sample of your user devices (typically around 10%) to verify patching levels and configuration
Configuration Checks: Direct inspection of system configurations to confirm they meet the scheme requirements
Malware Delivery Test: Attempting to deliver simulated malicious files to test your endpoint defences and user awareness
Email and Browser Testing: Verification that your default email clients and web browsers are properly configured to prevent the execution of malicious content
Step 4: Address Any Findings
If the assessor identifies any issues during testing, you will typically have 30 days to remediate the problems. Once resolved, you can arrange a re-test of the failed components.
Step 5: Receive Your Cyber Essentials Plus Certificate
Upon successful completion of the technical audit, you will receive your Cyber Essentials Plus certificate, which provides a higher level of assurance to your customers, partners, and stakeholders.
How to Meet the Cyber Essentials Requirements
Meeting the Cyber Essentials requirements involves a systematic approach to implementing the five technical controls:
For Firewalls
Ensure all internet-facing devices have a firewall installed and properly configured
Block all incoming connections by default, allowing only those explicitly required for business operations
Configure firewalls to monitor and log traffic for security analysis
Regularly review firewall rules to remove any that are no longer necessary
For Secure Configuration
Remove or disable unnecessary user accounts, especially default accounts
Change all default passwords to strong, unique alternatives
Disable or remove unnecessary software, services, and features
Apply secure configuration baselines to all new devices before deployment
Maintain an inventory of all devices and software to ensure nothing is overlooked
For Security Update Management
Establish a process for identifying and deploying security updates within 14 days of release
Ensure all software, including operating systems, applications, and firmware, is kept up to date
Remove or replace software that is no longer supported by the vendor
Test updates in a non-production environment before widespread deployment
Maintain records of all updates applied and when they were installed
For User Access Control
Create individual user accounts for all employees
Implement the principle of least privilege, granting only the access rights necessary for each role
Use strong password policies and consider multi-factor authentication for administrative accounts
Regularly review user access rights, removing access when no longer required
Maintain a process for promptly revoking access when employees leave the organisation
For Malware Protection
Install anti-malware software on all devices
Ensure the software is kept up to date with the latest signatures and definitions
Configure the software to perform regular scans and real-time protection
Implement controls to prevent the execution of unauthorised software
Educate users on the risks of malware and how to identify suspicious content
Benefits of Cyber Essentials Certification
For Your Organisation
Protection Against Common Threats: Implementing the five controls significantly reduces your vulnerability to the most common cyber attacks
Government Recognition: Demonstrates that your organisation meets the UK government's minimum cyber security standard
Supply Chain Advantage: Increasingly required by larger organisations when selecting suppliers, particularly for contracts involving sensitive data
Competitive Differentiation: Sets your organisation apart from competitors who may not have achieved certification
Insurance Benefits: UK organisations with turnover under £20 million that achieve certification covering their whole organisation automatically receive free Cyber Liability Insurance arranged by IASME, including 24/7 incident response support
For Your Customers
Trust and Confidence: Provides assurance that you take cyber security seriously
Data Protection: Demonstrates your commitment to protecting customer data
Business Continuity: Shows that you have measures in place to maintain operations in the face of cyber threats
Cyber Essentials Costs
The cost of certification varies based on your organisation's size and the level of certification:
Cyber Essentials:
Pricing is tiered by organisation size, starting at £320 + VAT for micro organisations (0-9 employees)
The self-led route offers the most cost-effective path to certification
Cyber Essentials Plus:
Costs are determined by the size and complexity of your network
Includes the cost of the independent technical audit and testing
Contact Certification Bodies directly for quotes tailored to your organisation
How Long Does Certification Take?
The timeline for achieving certification depends on your organisation's current security posture and chosen route:
Cyber Essentials: Typically 1-2 weeks for organisations that are already well-prepared
Cyber Essentials Plus: Usually 2-4 weeks, including the time required for the technical audit and any remediation
Both certificates are valid for 12 months, after which you must renew your certification to maintain compliance.
Who Needs Cyber Essentials?
Cyber Essentials certification is particularly valuable for:
Organisations bidding for UK government contracts that involve handling sensitive data
Businesses looking to demonstrate their cyber security commitment to customers and partners
Companies operating in supply chains where cyber security assurance is required
Any organisation that wants to protect itself against common cyber threats
Cyber Essentials Plus is often required for:
Ministry of Defence (MOD) contracts
Organisations handling particularly sensitive data
Businesses seeking the highest level of cyber security assurance
Common Challenges and How to Overcome Them
Many organisations face similar challenges when preparing for Cyber Essentials certification:
Challenge: Legacy Systems
Some organisations have older systems that cannot be updated or may not support modern security controls.
Solution: Identify these systems early in the process. You may need to isolate them from the rest of your network or implement compensating controls. In some cases, it may be necessary to upgrade or replace outdated systems.
Challenge: BYOD (Bring Your Own Device) Policies
Organisations that allow employees to use personal devices for work may struggle to ensure these devices meet the scheme requirements.
Solution: As of April 2026, all devices used for business purposes, including BYOD and home/remote working devices, must be included in the certification scope. Implement mobile device management solutions and clear policies for personal device usage.
Challenge: Cloud Services
Understanding shared responsibility models for cloud services can be complex.
Solution: Recognise that while cloud providers may implement some controls, your organisation remains responsible for ensuring all Cyber Essentials requirements are met. Work with your cloud provider to understand their security implementations and your responsibilities.
Challenge: Documentation
Some organisations lack the necessary documentation to demonstrate compliance.
Solution: Start documenting your security policies, procedures, and configurations early in the process. The NCSC provides guidance and templates to help organisations create the necessary documentation.
Preparing for Your Cyber Essentials Assessment
To ensure a smooth certification process:
Download the Official Resources: Access the free Cyber Essentials question set and Requirements for IT Infrastructure document from the IASME website
Use the Readiness Tool: Complete the NCSC's Cyber Essentials Readiness Tool to receive a tailored action plan
Conduct a Gap Analysis: Compare your current security measures against the five technical controls
Implement Necessary Changes: Address any gaps identified in your analysis
Test Your Systems: Verify that all controls are working as intended before submitting your assessment
Gather Documentation: Collect evidence of your security implementations, policies, and procedures
Engage Stakeholders: Ensure senior management understands and supports the certification process
Maintaining Your Certification
Cyber Essentials certification is not a one-time achievement but an ongoing commitment to cyber security:
Annual Renewal: Both Cyber Essentials and Cyber Essentials Plus certificates expire after 12 months
Continuous Compliance: Maintain all five technical controls throughout your certification period
Regular Reviews: Periodically assess your security posture to ensure ongoing compliance
Stay Informed: Keep up to date with any changes to the scheme requirements or best practices
Why Choose Point Click Solutions for Your Cyber Essentials Certification?
As an IASME-licensed Certification Body, we offer comprehensive support to help your organisation achieve both Cyber Essentials and Cyber Essentials Plus certification.
Our experienced assessors provide:
Expert Guidance: Clear, practical advice on implementing the five technical controls
Personalised Support: Tailored assistance based on your organisation's specific needs and current security posture
Efficient Processes: Streamlined certification pathways to minimise disruption to your business
Ongoing Assistance: Support throughout the entire certification process and beyond
Whether you are new to cyber security certification or looking to upgrade from Cyber Essentials to Cyber Essentials Plus, our team is here to help you navigate the process successfully.
Get Started with Your Cyber Essentials Journey Today
Achieving Cyber Essentials certification is a straightforward process that delivers significant benefits for your organisation. Whether you choose the self-assessment route for Cyber Essentials or the independent audit path for Cyber Essentials Plus, the investment in time and resources is minimal compared to the protection it provides against cyber threats.
Take the first step towards enhancing your organisation's cyber security posture. Download the free assessment questions, use the Readiness Tool, or contact us to discuss how we can support your certification journey.
Ready to begin? Contact us today to start your Cyber Essentials certification process or to learn more about how we can help your organisation achieve and maintain this important cyber security standard.

Comments