Cyber Essentials, in plain English: what it is, what it costs you in effort, and why customers ask for it
23 July 2026 · 7 min read · Optimum IT Solutions

Most businesses meet Cyber Essentials because someone else asked for it. This is the practical side: what it will actually take from you, and what usually gets in the way.
Cyber Essentials is a UK government backed scheme run under the National Cyber Security Centre. It checks that five basic technical controls are in place across your business: your internet connection is protected by a properly configured firewall, your devices and software are set up securely rather than left on factory defaults, people have only the access their job requires, something is actively protecting machines against malicious software, and everything is kept updated.
That is the what, and it is genuinely not complicated. The part firms are rarely told in advance is the how much: how much of your own time it takes, which bits get awkward, and why it keeps coming up in conversations with customers who never used to mention it.
Why the requests keep arriving
Three things are driving it, and none of them are going away.
The first is procurement. Larger organisations are increasingly held to account for the security of their suppliers, so the requirement travels down the chain. A certificate that a big customer needs becomes a question on the form they send you, and eventually a condition of the contract.
The second is insurance. Cyber insurance underwriters ask far more detailed questions than they used to, and a recognised baseline certification is an easy way for both sides to answer several of them at once.
The third is simply that the scheme has become the common language. When a customer wants to know whether you are sensible about security, asking for Cyber Essentials is quicker than trying to assess you themselves. It is not a perfect measure of safety, and it is a widely understood one, which is usually what a buyer actually needs.
What it costs you in effort, honestly
The certification fee is the small part. The real cost is your attention, and it lands in a few specific places.
- Deciding the scope. You have to define what is in and what is out, and be able to defend it. Whole organisation scope is cleanest and is often what customers expect, so carving pieces out to make life easier can create a certificate that does not satisfy the person who asked.
- Building a list of what you actually have. Every laptop, desktop, phone, tablet and server used for business work, with the operating system and version. Most firms have never written this down and are surprised by what turns up.
- Chasing the awkward devices. Personal phones and home computers used for work are in scope in ways people do not expect, and this is usually the conversation that takes the longest.
- Getting updates under control. The scheme expects high risk and critical security updates to be applied promptly, within a short and defined window, across everything. If patching has been ad hoc, this is real work.
- Tidying accounts and admin rights. Removing accounts belonging to people who have left, and separating everyday accounts from administrative ones, is dull and unavoidable.
- Answering the questionnaire accurately. It is long, the questions are specific, and vague answers get sent back. Someone in the business has to know the real answers, not the hoped for ones.
The things that usually hold firms up
Almost every delay we see comes from the same short list, and every one of them is easier to deal with before you start rather than halfway through.
- Software or operating systems that are no longer supported by their maker. Anything past end of support cannot simply be declared acceptable, so it has to be updated, replaced, or genuinely removed from scope. This is the single most common blocker and the one with the longest lead time.
- Multi factor authentication missing on cloud services, particularly on administrator accounts. Expectations here have tightened, and it is no longer something you can leave for later.
- Routers supplied by an internet provider, sitting on default settings with a default administrator password nobody has ever changed.
- Staff using personal devices for email with no controls and no clear policy, which nobody wants to raise but which the questionnaire raises anyway.
- Everyone running as an administrator on their own machine because it was easier when the business was smaller.
- One person holding all the knowledge and no time. This is not a technical blocker and it delays more certifications than any of the others.
Essentials or Essentials Plus
Standard Cyber Essentials is a self assessment. You answer for your own setup, it is submitted, and it is verified externally. The effort is mostly in getting the answers to be true.
Cyber Essentials Plus adds a hands on technical audit, where an assessor tests a sample of your actual machines and accounts rather than taking your word for it. The controls being checked are the same. The difference is proof, and the practical difference to you is that anything you fudged will be found.
Which one you need is a commercial question rather than a technical one, and the answer is whatever the contract, tender or insurer in front of you is asking for. Many buyers ask for the standard certificate. Some larger and public sector buyers want Plus. Ask the person requesting it before deciding, because paying for Plus you did not need is as wasteful as certifying at the wrong level and having to do it twice.
How long it takes, and what happens afterwards
For a small business with reasonably tidy IT, the work is usually measured in a few weeks rather than months, and most of that time is spent fixing things rather than filling in forms. If unsupported software or hardware has to be replaced, the timeline is set by that, not by the paperwork.
Certification lasts a year. That matters more than people expect, because it means the tidy state you reach is not a one off. Updates keep needing to be applied, leavers keep needing to be removed, and new devices keep arriving. Firms that treat certification as an annual scramble find each renewal painful. Firms that fold the five controls into normal routine find the renewal is largely a formality.
What it is not
It is worth being straight about the limits. Cyber Essentials is a baseline, not a guarantee, and holding the certificate does not mean you cannot be breached. It means the ordinary, automated, opportunistic attacks that make up the bulk of what hits small businesses have a much harder time, because the doors they usually walk through are shut.
It also says nothing about your staff, which is where a large share of real incidents start. Someone can be perfectly certified and still authorise a payment to a criminal on a Thursday afternoon. The certificate and the training are different jobs, and both are worth doing.
And it is possible to answer the questionnaire cleverly enough to pass while leaving the real problems in place. We would rather fix what is genuinely weak and certify the fixed version, because the point is to be harder to hurt, not to hold a document. If you want to know roughly where you would land today before committing to anything, a short gap check will tell you, and sometimes the honest answer is that you are closer than you think.
Want a straight answer on this?
Tell us the job that is costing you the most time. We will look at it and tell you honestly what, if anything, is worth doing about it. The first conversation is free.
Get a quote
