traibcert whatsapp icon
Updated for April 2026 · v3.3 Danzell

Cyber Essentials
Certification

The UK Government's baseline standard for cyber security. A verified self-assessment that proves your organisation has the five core technical controls in place — protecting you, your clients, and your supply chain from the most common internet-based threats.

From £320 + VAT
Free Cyber Insurance Included
Assessed Within 3 Working Days
80%
of common attacks
prevented by the five controls
400+
certification bodies
in the IASME network
12
month validity
with annual renewal
£25k
free cyber insurance
for eligible UK organisations

What Is Cyber Essentials?

Cyber Essentials is a UK Government-backed certification scheme, developed by the National Cyber Security Centre (NCSC), that helps organisations of any size protect themselves against the most common internet-based cyber attacks.

The scheme is built around five technical controls that, when implemented correctly, prevent the vast majority of commodity attacks — the digital equivalent of a thief trying your front door to see if it's unlocked.

Certification is achieved through a verified self-assessment: you complete an online questionnaire, a board-level representative signs a declaration confirming accuracy, and a qualified assessor reviews your answers. There is no on-site audit — the entire process is completed online.

Your certificate is valid for 12 months and is publicly listed on the IASME portal. You receive a digital badge with the Crown & Tick mark for use on your website, proposals, and email signatures.

01

Firewalls & Internet Gateways

Control incoming and outgoing network traffic

02

Secure Configuration

Reduce attack surface on all devices and software

03

User Access Control

Restrict access to authorised personnel only

04

Malware Protection

Defend against viruses and malicious software

05

Patch Management

Apply critical security updates within 14 days of release

What Certification Gets You

📋

Win Government & Supply Chain Contracts

Cyber Essentials has been required for central government contracts involving personal data since 2014. The MOD and NHS mandate it. Private-sector supply chains increasingly expect it.

🛡️

Free Cyber Liability Insurance

UK organisations with turnover under £20 million that certify their entire organisation receive automatic cyber liability insurance through IASME — including 24/7 incident response up to £25,000.

📉

Measurable Risk Reduction

Government research confirms that Cyber Essentials certification is linked to a measurable reduction in successful attacks and insurance claims. The five controls address the most common vectors.

Demonstrate Due Diligence

An independently verified baseline of security controls is evidence to regulators, auditors, and clients that your organisation is taking cyber security seriously and acting responsibly.

Foundation for Cyber Essentials Plus

A valid Cyber Essentials certificate is the prerequisite for Plus — the hands-on technical audit that provides a higher level of assurance. You have 90 days to progress from CE to CE+.

🏷️

Crown & Tick Badge

Display the government-backed trust mark on your website, email signatures, and proposals. A visible, verifiable signal that your defences meet the national baseline.

What Changed in
April 2026

From 27 April 2026, all new assessments use the v3.3 "Danzell" question set. The five controls are unchanged, but verification is stricter. Our assessors are trained and ready.

The board-level declaration now explicitly commits the organisation to maintaining controls throughout the 12-month certification period — not just at the point of assessment.

MFA Is Now Mandatory Auto-Fail

If any cloud service offers MFA and you haven't enabled it for all users, you will automatically fail — no exceptions, even if MFA requires a paid upgrade.

Cloud Services Formally Defined New Scope

Any service accessed via credentials that stores or processes your data is now explicitly in scope. Cloud services can no longer be excluded.

Scoping Rules Tightened

All legal entities within scope must be declared. Exclusions must be justified. Scope descriptions now appear on the certificate itself.

14-Day Patching Enforced Strictly

High-risk and critical patches must be applied within 14 days. This applies to operating systems, applications, and network devices including routers and firewalls.

Answers Locked Before Plus Audit

Self-assessment answers can no longer be amended after the Plus technical audit begins. Declarations must be complete and accurate upfront.

Five Steps to Certification

The entire process is completed online. Most organisations achieve certification within one to two weeks of starting their self-assessment.

1

Register & Pay

Set up your assessment account and pay the fee for your organisation size.

2

Prepare

Review the five controls. Assess your current position. Use IASME's free readiness tool.

3

Complete & Sign

Answer the self-assessment questionnaire. A board-level representative signs the declaration.

4

Assessor Review

A qualified assessor reviews within 3 working days. You can update and resubmit if needed.

5

Certificate Issued

On success, your certificate is issued instantly. Publicly registered. Valid for 12 months.

Straightforward Pricing

Fees are set by IASME and scaled to your organisation's size. The price covers the assessment, assessor review, certificate, and public listing.

Micro
0 – 9 employees
£320
+ VAT
Get Started
Medium
50 – 249 employees
£500
+ VAT
Get Started
Large
250+ employees
£600
+ VAT
Get Started

Need help with the self-assessment? We offer expert support packages. Contact us for details.

Cyber Essentials vs. Cyber Essentials Plus

Both cover the same five controls. The difference is how compliance is verified — and the level of trust it provides to clients and supply chains.

Self-Assessment

Cyber Essentials

You complete the questionnaire. An assessor reviews your answers. Confirms controls are documented and declared.

  • Verified self-assessment questionnaire
  • Assessor review within 3 working days
  • Meets minimum for government contracts
  • Prerequisite for Cyber Essentials Plus
  • Free cyber insurance included
  • From £320 + VAT
Technical Audit

Cyber Essentials Plus

An independent assessor tests your actual systems. Confirms controls are working in practice — not just documented.

  • Hands-on technical audit of your systems
  • Vulnerability scanning & penetration tests
  • Higher assurance for sensitive data
  • Required by many private-sector supply chains
  • Free cyber insurance included
  • From £1,499 + VAT
Learn About CE+ →

Already hold ISO 27001? You may still need Cyber Essentials. ISO 27001 is a broad risk-based framework; Cyber Essentials is a specific NCSC-backed technical baseline. Many UK contracts require both — they are complementary, not interchangeable.

Frequently Asked

Both cover the same five technical controls. Cyber Essentials is a verified self-assessment — you answer questions and an assessor reviews your answers. Plus adds a hands-on technical audit where an assessor tests your actual systems, providing a higher level of assurance. You must pass CE before attempting Plus, and the Plus audit must be completed within 90 days.

Twelve months. We send a reminder before expiry to arrange renewal. If you do not renew, your organisation is removed from the certified organisations list.

Not legally, but it is required for many UK Government contracts involving personal data. The MOD, NHS, and an increasing number of private-sector organisations require it of their suppliers. Regulated sectors — legal, financial, healthcare — increasingly reference it as a baseline expectation.

Yes. The scheme is available to organisations of all sizes, including sole traders. Micro organisations (0–9 employees) pay £320 + VAT.

As an IASME-accredited Certification Body, we help you understand the assessment questions and how they apply to your organisation. We offer support packages ranging from basic guidance through to dedicated advisory sessions. Our assessors review your submission within three working days and provide detailed feedback if clarification is needed.

If your answers don't meet the standard, our assessor provides specific feedback explaining what needs to change. You have the opportunity to update and resubmit. Each resubmission is reviewed within three working days.

The main changes in v3.3 (Danzell) are: MFA is now mandatory on all cloud services that offer it — failure is an automatic fail. Cloud services are formally defined and cannot be excluded from scope. Scoping rules are tighter with mandatory legal entity declarations. The board-level declaration now commits to maintaining controls for the full 12-month period.

Yes. Cyber Essentials is available to organisations globally. The entire process is completed online.

Lock the Door on Cyber Threats

Start your Cyber Essentials certification today — or talk to our team about
preparing for the April 2026 changes and choosing the right level for your organisation.