The short answer: Cyber Essentials is a UK government-backed certification showing your organisation has five basic security controls in place. You complete a self-assessment, which an independent certification body checks. Cyber Essentials Plus covers the same controls but adds hands-on technical testing. Certificates last 12 months. Since April 2026, missing multi-factor authentication on a cloud service, or missing the 14-day deadline for critical updates, is an automatic fail.
Cyber Essentials vs Cyber Essentials Plus
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| How it's assessed | Self-assessment questionnaire, verified by a certification body | The same controls, plus remote and on-site vulnerability testing |
| Cost | Fixed fee by organisation size (see below) | Quoted; IASME suggests roughly £2,000–£3,000 |
| Valid for | 12 months | 12 months |
The five controls
- Firewalls: every internet-connected device is protected by a firewall, whether a boundary firewall, a software firewall or, for cloud services, a virtual one.
- Secure configuration: unused software and accounts are removed, default passwords changed, and auto-run turned off.
- Security update management: all software is licensed and supported, and critical or high-risk updates are installed within 14 days of release.
- User access control: people only get the access they need, administrators use separate admin accounts, and multi-factor authentication is used, always for cloud services.
- Malware protection: anti-malware software or application allow-listing is in place.
What changed in April 2026
The current standard is Cyber Essentials: Requirements for IT Infrastructure v3.3, used with the Danzell question set for assessments started from late April 2026. The changes that matter most:
- MFA on cloud services is an automatic fail if missing, where the service offers it. That includes Microsoft 365. Our guide to turning on MFA for Microsoft 365 walks through it.
- The 14-day update rule is now an automatic fail for operating systems, firmware and applications.
- Cloud services can't be left out of scope.
- Passwordless sign-in with FIDO2 passkeys counts as MFA.
- Out-of-scope areas must be documented, and each legal entity must be identified (and can have its own certificate).
The 14-day rule, precisely
Software on in-scope devices must be updated within 14 days of release where the update fixes vulnerabilities the vendor calls "critical" or "high risk", has a CVSS v3 score of 7 or above, or where the vendor gives no details of severity. In practice, that means automatic updates wherever possible, and a clear process for anything that can't update itself.
It also means unsupported software fails, such as a PC still running Windows 10 without Extended Security Updates.
What's in scope
- All devices used for work that can access organisational data or services, including laptops used at home.
- Personal devices (BYOD) that access work email or files. Devices used only for calls, texts or an MFA app are out of scope.
- Home workers: a router the organisation supplies is in scope. Other home routers aren't, so each device needs its own software firewall. A corporate VPN moves the boundary back to the company firewall.
- Cloud services such as Microsoft 365, always.
What it costs
| Organisation size | Employees | IASME fee (excluding VAT) |
|---|---|---|
| Micro | 0–9 | £320 |
| Small | 10–49 | £440 |
| Medium | 50–249 | £500 |
| Large | 250+ | £600 |
If an assessment fails, IASME allows two working days to correct answers without paying again. You have six months from purchase to submit.
Included cyber insurance
UK organisations with turnover under £20 million that certify their whole organisation can opt in to cyber liability insurance with a total limit of £25,000, including a 24-hour incident response helpline. It has exclusions and an excess, and higher cover can be bought. Check IASME's page for the current terms.
Do you need it for government work?
Often, yes. Under Procurement Policy Note 014, central government departments, their agencies and NHS bodies require Cyber Essentials from suppliers who handle citizens' or staff personal data, or ICT systems holding OFFICIAL-level information. Certification must be renewed every year of the contract. Many private-sector customers now ask for it too.
How to prepare
- Define the scope: list every device, user, cloud service and network.
- Turn on MFA for every cloud service that offers it.
- Automate updates, and remove or replace anything unsupported.
- Separate admin accounts from everyday accounts.
- Check firewalls and anti-malware on every device, including home workers' laptops.
- Remove what isn't used: old accounts, software and default passwords.
- Answer the questionnaire carefully, and keep evidence for each answer.
Help from Apaxon
Apaxon holds Cyber Essentials certification itself, and helps businesses prepare for Cyber Essentials and Cyber Essentials Plus through its cyber security services and managed IT services. get in touch to talk it through.
Sources
Get the latest IT insights
Expert tips, infrastructure news, and product updates — delivered weekly.

