SECURITY
Cyber Essentials: A Complete Guide for UK Businesses
Cyber Essentials is the UK government-backed baseline for security. It is required for some public-sector contracts and increasingly expected in supply chains. This page explains what it covers, the two levels, and how to get certified.
Book a conversationWhat Cyber Essentials is
Cyber Essentials is a UK government-backed certification scheme, delivered through the IASME consortium on behalf of the National Cyber Security Centre. It sets a baseline of five technical controls that protect against the most common internet-based attacks. It is deliberately not a comprehensive security standard like ISO 27001; it is a credible minimum that demonstrates you have the basics in place, which is exactly why buyers and government bodies increasingly ask for it.
The five control themes
- Firewalls: control the traffic entering and leaving your networks and devices
- Secure configuration: remove default passwords and unnecessary features that create easy entry points
- User access control: give people only the access they need, and protect accounts, especially administrator ones
- Malware protection: prevent and detect malicious software before it can run
- Security update management: keep software and devices patched, since unpatched flaws are a leading route in
Cyber Essentials versus Cyber Essentials Plus
There are two levels. Cyber Essentials is a self-assessment: you answer a set of questions about your controls and they are reviewed. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit, where an assessor independently tests that the controls actually work. Plus carries more weight because it is verified rather than declared, and some contracts specifically require it. Our readiness check shows which you are likely to pass before you apply.
Who needs it
Cyber Essentials is mandatory for some UK government contracts, particularly those handling personal or sensitive information, and it is increasingly a condition of doing business in commercial supply chains. Beyond the contractual driver, it is a low-cost way to close the gaps that most real-world attacks exploit, and a visible signal to customers and insurers that you take security seriously. For most SMEs it is the sensible first step, ahead of a fuller security programme.
How to get certified
The path is straightforward: confirm the scope of what you are certifying, check your controls against the five themes, close any gaps, and complete the assessment. The work is usually less about buying new tools and more about configuring and evidencing what you already have. Getting the scope and the evidence right first time is where a little senior guidance saves a failed assessment.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Daniel has stood up the baseline controls Cyber Essentials tests inside real businesses, and can get you certification-ready without the false starts, then help you decide whether Plus or a fuller programme is the right next step.
Frequently asked questions
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme, run through IASME for the National Cyber Security Centre. It sets a baseline of five technical controls that protect against the most common internet-based attacks, and acts as a credible minimum standard of security.
What are the five Cyber Essentials controls?
Firewalls, secure configuration, user access control, malware protection and security update management. Together they close the gaps that most everyday attacks exploit, such as default passwords, over-privileged accounts and unpatched software.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment of your controls. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit, where an assessor independently tests that they work. Plus carries more weight because it is verified rather than declared.
Do we need Cyber Essentials?
It is mandatory for some UK government contracts and increasingly expected in commercial supply chains. Even where it is not required, it is a low-cost way to close the gaps most attacks exploit and to signal credible security to customers and insurers.
How long does it take to get certified?
For a well-run small business, Cyber Essentials can be achieved in a few weeks, since the work is mostly configuring and evidencing existing controls rather than buying new ones. Cyber Essentials Plus takes longer because of the independent technical audit.
NEXT STEP
Would you pass Cyber Essentials today?
The free Cyber Essentials Readiness check predicts whether you would pass against the five control themes, and shows the gaps to close first. When you want to talk it through, a conversation is the next step.
Cyber Essentials Readiness check Book a conversation