top of page
Search

Cyber Essentials Certification: Your Complete Guide to Achieving CE and CE Plus

  • shaunflint
  • 3 hours ago
  • 9 min read

What Is Cyber Essentials?


Cyber Essentials is the UK government-backed cyber security certification scheme developed by the National Cyber Security Centre (NCSC) and delivered through IASME. It establishes the minimum baseline standard of protection that all organisations should implement to defend against the most common internet-based cyber threats.


Designed to be accessible for organisations of all sizes, from micro-businesses to large enterprises, Cyber Essentials provides a clear, cost-effective framework to demonstrate your commitment to cyber security.


The scheme is built around five fundamental technical controls that, when properly implemented, can protect against approximately 80% of common cyber attacks.


What Is Cyber Essentials Plus?


Cyber Essentials Plus represents the higher assurance level of the scheme. It includes all the protections of the standard Cyber Essentials certification but adds independent technical verification.


While Cyber Essentials relies on a verified self-assessment questionnaire, Cyber Essentials Plus requires a qualified assessor from an IASME-accredited Certification Body to conduct hands-on testing of your systems.


This independent audit confirms that your cyber security controls are not only documented but are actively implemented and functioning correctly across your IT infrastructure.


The Five Cyber Essentials Technical Controls


Both certification levels assess your organisation against the same five technical controls:


1. Firewalls

Create a security barrier between your internal networks and the internet. Proper firewall configuration prevents unauthorised access to your systems from external networks and limits the data that can flow in and out of your organisation.


2. Secure Configuration

Ensure all devices and software are configured to minimise vulnerabilities. This includes removing unnecessary user accounts, disabling default passwords, and applying secure settings to all devices, applications, and network equipment.


3. Security Update Management

Maintain up-to-date software across all devices. Regular security updates and patches are essential to protect against known vulnerabilities that cyber criminals could exploit to gain access to your systems.


4. User Access Control

Implement strict controls over who can access your data and services. This includes creating individual user accounts, providing the minimum level of access required for each role, and ensuring administrative privileges are only granted to those who absolutely need them.


5. Malware Protection

Deploy effective malware protection across all devices. This involves using anti-malware software that is kept up to date, configured to scan files automatically, and capable of detecting and removing malicious software before it can cause harm.


The Cyber Essentials Certification Process


Achieving Cyber Essentials certification follows a structured approach:


Step 1: Define Your Scope

Determine which parts of your organisation will be covered by the certification. The scope must include all devices, users, and systems that handle or store your organisation's data. As of April 2026, end-user devices cannot be excluded from the scope, and cloud services must be included.


Step 2: Prepare Your Systems

Review the official Cyber Essentials requirements and assessment questions, available for free download from the IASME website. Use the NCSC's Readiness Tool to assess your current security posture and receive a tailored action plan.


Step 3: Implement the Controls

Address any gaps identified in your preparation. Ensure all five technical controls are properly implemented across your entire scope. This may involve configuring firewalls, updating software, reviewing user access rights, and deploying malware protection.


Step 4: Choose Your Certification Route

You have two options for achieving Cyber Essentials certification:

Self-Led Certification: Register directly with IASME, pay the assessment fee (starting at £320 + VAT for organisations with 0-9 employees), and complete the verified self-assessment questionnaire online. A senior board member or equivalent must sign off on your answers, confirming their accuracy. Your submission is then reviewed and marked by a qualified assessor.

Supported Certification: Engage a Certification Body licensed by IASME. These organisations employ qualified assessors who can guide you through the process, help you understand the assessment questions, and provide support in implementing the required controls before submitting your self-assessment.


Step 5: Receive Your Certificate

Once your assessment is approved, you will receive your Cyber Essentials certificate, which is valid for 12 months. Your organisation will be listed on the official Cyber Essentials certificate register.


The Cyber Essentials Plus Certification Process


Cyber Essentials Plus follows a more rigorous process that builds on your Cyber Essentials certification:


Prerequisite: Achieve Cyber Essentials First


You must first obtain your Cyber Essentials certification through the verified self-assessment. Your Cyber Essentials certificate must be dated within three months of applying for Cyber Essentials Plus.


Step 1: Select a Certification Body

Contact an IASME-accredited Certification Body directly to arrange your Cyber Essentials Plus audit. These organisations employ qualified assessors who are authorised to conduct the technical testing required for CE Plus certification.


Step 2: Technical Audit Preparation

Work with your chosen Certification Body to prepare for the audit. Ensure all documentation is in order and that your systems are ready for testing. The assessor will need access to a representative sample of your devices and systems.


Step 3: Independent Technical Testing

A qualified assessor will conduct comprehensive technical tests, including:

  • External Vulnerability Scan: A scan of your internet-facing IP addresses to identify any clear vulnerabilities or misconfigurations

  • Internal Vulnerability Scan: Testing of a representative sample of your user devices (typically around 10%) to verify patching levels and configuration

  • Configuration Checks: Direct inspection of system configurations to confirm they meet the scheme requirements

  • Malware Delivery Test: Attempting to deliver simulated malicious files to test your endpoint defences and user awareness

  • Email and Browser Testing: Verification that your default email clients and web browsers are properly configured to prevent the execution of malicious content


Step 4: Address Any Findings

If the assessor identifies any issues during testing, you will typically have 30 days to remediate the problems. Once resolved, you can arrange a re-test of the failed components.


Step 5: Receive Your Cyber Essentials Plus Certificate

Upon successful completion of the technical audit, you will receive your Cyber Essentials Plus certificate, which provides a higher level of assurance to your customers, partners, and stakeholders.


How to Meet the Cyber Essentials Requirements

Meeting the Cyber Essentials requirements involves a systematic approach to implementing the five technical controls:


For Firewalls

  • Ensure all internet-facing devices have a firewall installed and properly configured

  • Block all incoming connections by default, allowing only those explicitly required for business operations

  • Configure firewalls to monitor and log traffic for security analysis

  • Regularly review firewall rules to remove any that are no longer necessary


For Secure Configuration

  • Remove or disable unnecessary user accounts, especially default accounts

  • Change all default passwords to strong, unique alternatives

  • Disable or remove unnecessary software, services, and features

  • Apply secure configuration baselines to all new devices before deployment

  • Maintain an inventory of all devices and software to ensure nothing is overlooked


For Security Update Management

  • Establish a process for identifying and deploying security updates within 14 days of release

  • Ensure all software, including operating systems, applications, and firmware, is kept up to date

  • Remove or replace software that is no longer supported by the vendor

  • Test updates in a non-production environment before widespread deployment

  • Maintain records of all updates applied and when they were installed


For User Access Control

  • Create individual user accounts for all employees

  • Implement the principle of least privilege, granting only the access rights necessary for each role

  • Use strong password policies and consider multi-factor authentication for administrative accounts

  • Regularly review user access rights, removing access when no longer required

  • Maintain a process for promptly revoking access when employees leave the organisation


For Malware Protection

  • Install anti-malware software on all devices

  • Ensure the software is kept up to date with the latest signatures and definitions

  • Configure the software to perform regular scans and real-time protection

  • Implement controls to prevent the execution of unauthorised software

  • Educate users on the risks of malware and how to identify suspicious content


Benefits of Cyber Essentials Certification


For Your Organisation

  • Protection Against Common Threats: Implementing the five controls significantly reduces your vulnerability to the most common cyber attacks

  • Government Recognition: Demonstrates that your organisation meets the UK government's minimum cyber security standard

  • Supply Chain Advantage: Increasingly required by larger organisations when selecting suppliers, particularly for contracts involving sensitive data

  • Competitive Differentiation: Sets your organisation apart from competitors who may not have achieved certification

  • Insurance Benefits: UK organisations with turnover under £20 million that achieve certification covering their whole organisation automatically receive free Cyber Liability Insurance arranged by IASME, including 24/7 incident response support


For Your Customers

  • Trust and Confidence: Provides assurance that you take cyber security seriously

  • Data Protection: Demonstrates your commitment to protecting customer data

  • Business Continuity: Shows that you have measures in place to maintain operations in the face of cyber threats


Cyber Essentials Costs

The cost of certification varies based on your organisation's size and the level of certification:


Cyber Essentials:

  • Pricing is tiered by organisation size, starting at £320 + VAT for micro organisations (0-9 employees)

  • The self-led route offers the most cost-effective path to certification


Cyber Essentials Plus:

  • Costs are determined by the size and complexity of your network

  • Includes the cost of the independent technical audit and testing

  • Contact Certification Bodies directly for quotes tailored to your organisation


How Long Does Certification Take?


The timeline for achieving certification depends on your organisation's current security posture and chosen route:

  • Cyber Essentials: Typically 1-2 weeks for organisations that are already well-prepared

  • Cyber Essentials Plus: Usually 2-4 weeks, including the time required for the technical audit and any remediation

Both certificates are valid for 12 months, after which you must renew your certification to maintain compliance.


Who Needs Cyber Essentials?


Cyber Essentials certification is particularly valuable for:

  • Organisations bidding for UK government contracts that involve handling sensitive data

  • Businesses looking to demonstrate their cyber security commitment to customers and partners

  • Companies operating in supply chains where cyber security assurance is required

  • Any organisation that wants to protect itself against common cyber threats


Cyber Essentials Plus is often required for:

  • Ministry of Defence (MOD) contracts

  • Organisations handling particularly sensitive data

  • Businesses seeking the highest level of cyber security assurance


Common Challenges and How to Overcome Them


Many organisations face similar challenges when preparing for Cyber Essentials certification:


Challenge: Legacy Systems

Some organisations have older systems that cannot be updated or may not support modern security controls.

Solution: Identify these systems early in the process. You may need to isolate them from the rest of your network or implement compensating controls. In some cases, it may be necessary to upgrade or replace outdated systems.


Challenge: BYOD (Bring Your Own Device) Policies

Organisations that allow employees to use personal devices for work may struggle to ensure these devices meet the scheme requirements.

Solution: As of April 2026, all devices used for business purposes, including BYOD and home/remote working devices, must be included in the certification scope. Implement mobile device management solutions and clear policies for personal device usage.


Challenge: Cloud Services

Understanding shared responsibility models for cloud services can be complex.

Solution: Recognise that while cloud providers may implement some controls, your organisation remains responsible for ensuring all Cyber Essentials requirements are met. Work with your cloud provider to understand their security implementations and your responsibilities.

Challenge: Documentation

Some organisations lack the necessary documentation to demonstrate compliance.

Solution: Start documenting your security policies, procedures, and configurations early in the process. The NCSC provides guidance and templates to help organisations create the necessary documentation.


Preparing for Your Cyber Essentials Assessment

To ensure a smooth certification process:

  1. Download the Official Resources: Access the free Cyber Essentials question set and Requirements for IT Infrastructure document from the IASME website

  2. Use the Readiness Tool: Complete the NCSC's Cyber Essentials Readiness Tool to receive a tailored action plan

  3. Conduct a Gap Analysis: Compare your current security measures against the five technical controls

  4. Implement Necessary Changes: Address any gaps identified in your analysis

  5. Test Your Systems: Verify that all controls are working as intended before submitting your assessment

  6. Gather Documentation: Collect evidence of your security implementations, policies, and procedures

  7. Engage Stakeholders: Ensure senior management understands and supports the certification process


Maintaining Your Certification

Cyber Essentials certification is not a one-time achievement but an ongoing commitment to cyber security:

  • Annual Renewal: Both Cyber Essentials and Cyber Essentials Plus certificates expire after 12 months

  • Continuous Compliance: Maintain all five technical controls throughout your certification period

  • Regular Reviews: Periodically assess your security posture to ensure ongoing compliance

  • Stay Informed: Keep up to date with any changes to the scheme requirements or best practices


Why Choose Point Click Solutions for Your Cyber Essentials Certification?


As an IASME-licensed Certification Body, we offer comprehensive support to help your organisation achieve both Cyber Essentials and Cyber Essentials Plus certification.

Our experienced assessors provide:


  • Expert Guidance: Clear, practical advice on implementing the five technical controls

  • Personalised Support: Tailored assistance based on your organisation's specific needs and current security posture

  • Efficient Processes: Streamlined certification pathways to minimise disruption to your business

  • Ongoing Assistance: Support throughout the entire certification process and beyond


Whether you are new to cyber security certification or looking to upgrade from Cyber Essentials to Cyber Essentials Plus, our team is here to help you navigate the process successfully.


Get Started with Your Cyber Essentials Journey Today


Achieving Cyber Essentials certification is a straightforward process that delivers significant benefits for your organisation. Whether you choose the self-assessment route for Cyber Essentials or the independent audit path for Cyber Essentials Plus, the investment in time and resources is minimal compared to the protection it provides against cyber threats.


Take the first step towards enhancing your organisation's cyber security posture. Download the free assessment questions, use the Readiness Tool, or contact us to discuss how we can support your certification journey.


Ready to begin? Contact us today to start your Cyber Essentials certification process or to learn more about how we can help your organisation achieve and maintain this important cyber security standard.

 
 
 

Comments


bottom of page