Cyber Essentials Explained: Requirements, Costs and the 2026 Changes

17th September 2026
InCyber SecurityHow-To

The short answer: Cyber Essentials is a UK government-backed certification showing your organisation has five basic security controls in place. You complete a self-assessment, which an independent certification body checks. Cyber Essentials Plus covers the same controls but adds hands-on technical testing. Certificates last 12 months. Since April 2026, missing multi-factor authentication on a cloud service, or missing the 14-day deadline for critical updates, is an automatic fail.

Cyber Essentials vs Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
How it's assessedSelf-assessment questionnaire, verified by a certification bodyThe same controls, plus remote and on-site vulnerability testing
CostFixed fee by organisation size (see below)Quoted; IASME suggests roughly £2,000–£3,000
Valid for12 months12 months

The five controls

  1. Firewalls: every internet-connected device is protected by a firewall, whether a boundary firewall, a software firewall or, for cloud services, a virtual one.
  2. Secure configuration: unused software and accounts are removed, default passwords changed, and auto-run turned off.
  3. Security update management: all software is licensed and supported, and critical or high-risk updates are installed within 14 days of release.
  4. User access control: people only get the access they need, administrators use separate admin accounts, and multi-factor authentication is used, always for cloud services.
  5. Malware protection: anti-malware software or application allow-listing is in place.

What changed in April 2026

The current standard is Cyber Essentials: Requirements for IT Infrastructure v3.3, used with the Danzell question set for assessments started from late April 2026. The changes that matter most:

  • MFA on cloud services is an automatic fail if missing, where the service offers it. That includes Microsoft 365. Our guide to turning on MFA for Microsoft 365 walks through it.
  • The 14-day update rule is now an automatic fail for operating systems, firmware and applications.
  • Cloud services can't be left out of scope.
  • Passwordless sign-in with FIDO2 passkeys counts as MFA.
  • Out-of-scope areas must be documented, and each legal entity must be identified (and can have its own certificate).

The 14-day rule, precisely

Software on in-scope devices must be updated within 14 days of release where the update fixes vulnerabilities the vendor calls "critical" or "high risk", has a CVSS v3 score of 7 or above, or where the vendor gives no details of severity. In practice, that means automatic updates wherever possible, and a clear process for anything that can't update itself.

It also means unsupported software fails, such as a PC still running Windows 10 without Extended Security Updates.

What's in scope

  • All devices used for work that can access organisational data or services, including laptops used at home.
  • Personal devices (BYOD) that access work email or files. Devices used only for calls, texts or an MFA app are out of scope.
  • Home workers: a router the organisation supplies is in scope. Other home routers aren't, so each device needs its own software firewall. A corporate VPN moves the boundary back to the company firewall.
  • Cloud services such as Microsoft 365, always.

What it costs

Organisation sizeEmployeesIASME fee (excluding VAT)
Micro0–9£320
Small10–49£440
Medium50–249£500
Large250+£600

If an assessment fails, IASME allows two working days to correct answers without paying again. You have six months from purchase to submit.

Included cyber insurance

UK organisations with turnover under £20 million that certify their whole organisation can opt in to cyber liability insurance with a total limit of £25,000, including a 24-hour incident response helpline. It has exclusions and an excess, and higher cover can be bought. Check IASME's page for the current terms.

Do you need it for government work?

Often, yes. Under Procurement Policy Note 014, central government departments, their agencies and NHS bodies require Cyber Essentials from suppliers who handle citizens' or staff personal data, or ICT systems holding OFFICIAL-level information. Certification must be renewed every year of the contract. Many private-sector customers now ask for it too.

How to prepare

  1. Define the scope: list every device, user, cloud service and network.
  2. Turn on MFA for every cloud service that offers it.
  3. Automate updates, and remove or replace anything unsupported.
  4. Separate admin accounts from everyday accounts.
  5. Check firewalls and anti-malware on every device, including home workers' laptops.
  6. Remove what isn't used: old accounts, software and default passwords.
  7. Answer the questionnaire carefully, and keep evidence for each answer.

Help from Apaxon

Apaxon holds Cyber Essentials certification itself, and helps businesses prepare for Cyber Essentials and Cyber Essentials Plus through its cyber security services and managed IT services. get in touch to talk it through.

Sources

Get the latest IT insights

Expert tips, infrastructure news, and product updates — delivered weekly.

No spam. Unsubscribe any time.

Technology Partners

Powered by Industry LeadersTier-2 Vendor & Distribution Ecosystem

Authorised partnerships with the world's leading technology manufacturers and distributors — giving you direct access to enterprise-grade solutions and pricing.

  • Dell Technology Solutions Partner
  • HPE Enterprise Infrastructure Partner
  • Cisco Networking Partner
  • Lenovo Technology Partner
  • Intel Technology Partner
  • Microsoft Technology Partner
  • IBM Enterprise Solutions Partner
  • Arrow Electronics Enterprise Partner
  • Ingram Micro UK Distribution Partner
  • West Coast IT Distribution Partner
  • Ubuntu Open Source Partner
Cyber Essentials Explained: Requirements, Costs and the 2026 Changes | Apaxon® IT Support