Cyber Essentials is a UK government-backed certification scheme covering five basic technical controls. Having the certification demonstrates that a business has those five controls in place. It does not demonstrate much else, which is not a criticism of the scheme — it is just worth understanding before you decide to pursue it.
The five controls are: firewalls, secure configuration, user access control, malware protection, and patch management. These are, broadly, the right five controls to address first. They close a meaningful slice of the attack surface that small businesses most commonly expose.
What each control actually means in practice
Firewalls, in this context, refers to boundary firewalls between your network and the internet, as well as software firewalls on individual devices. The requirement is that they are enabled, configured to block incoming connections that are not explicitly needed, and that the default admin credentials have been changed.
Secure configuration means devices are set up with security in mind: unnecessary software removed, default accounts disabled or renamed, automatic locking enabled, and so on. This is often the control where the most gap-filling needs to happen, because devices are frequently set up with convenience rather than security as the priority.
User access control covers who can do what on your systems. The key requirements are that admin-level access is only given to people who need it for admin tasks, and that all users have their own individual accounts rather than sharing credentials.
Malware protection requires that all devices have either up-to-date antivirus or application whitelisting in place. For most small businesses this means antivirus, and the question is whether it is installed, active, and updating automatically.
Patch management means keeping software up to date. The requirement is that security patches are applied within fourteen days of release, and that software which is no longer receiving security updates is removed or managed carefully.
What it deliberately leaves out
Cyber Essentials does not cover email security controls (SPF, DKIM, DMARC). It does not cover staff awareness training. It does not address physical security, backup procedures, incident response, or data handling practices.
None of this is a flaw in the scheme — it would be a very different beast if it tried to cover all of these. But businesses that obtain the certification sometimes assume they have addressed their security comprehensively. They have addressed five things. Those five things matter. They are not everything.
The gaps most commonly left open after Cyber Essentials certification, in our experience: email domain configuration that allows spoofing; no staff procedure for suspicious emails; backups that have never been tested; access that was not removed when staff left.
Self-assessment versus Plus
The standard Cyber Essentials is a self-assessment. A business completes a questionnaire describing their controls and, if the answers meet the scheme requirements, receives the certificate. The questionnaire is checked by a certification body, but there is no independent verification that what the business has described is accurate.
Cyber Essentials Plus involves an independent technical assessment: a certification body checks the controls are actually in place by testing them. The certificate carries more weight accordingly, and it is required for certain government contracts.
For most small businesses pursuing the certification for the first time, the self-assessment route is the sensible starting point. The Plus assessment makes most sense once you have completed the self-assessment and addressed any gaps it identified, or when procurement requirements specifically require it.
Whether it's worth pursuing
If the five controls it covers are genuinely in place, the certification is a reasonable way of demonstrating that to clients and procurement teams, and costs relatively little. If the controls are not in place, working through the certification process is a useful way to identify and address them systematically.
It should not be treated as a security strategy. It is a floor, not a ceiling. Businesses that pursue it should understand what sits above the floor and address those things separately.