Home › Guides › Cyber Essentials explained: the five controls and whether you need it

Cyber Essentials is the UK government’s recommended baseline for cyber security. It’s designed for organisations of all sizes, from one-person firms to large companies. The standard identifies five technical controls that prevent the most common internet-based attacks. Whether your small business needs formal certification depends on your size and who your customers are, but understanding the five controls is useful regardless.
What are the five controls?
Cyber Essentials is built on five technical controls, each addressing a common vulnerability:
1. Firewalls and network segmentation. A firewall filters traffic between your office network and the internet, blocking unauthorised connections. For a small office, this might be a router with a firewall built in. The control ensures that devices not needed to reach the internet can’t be accessed from the internet.
2. Secure configuration. Computers come with many features enabled by default; many of these create security risks. Secure configuration means removing unnecessary features, changing default passwords, disabling unused services, and updating system settings. An unsecured computer is like a house with the front door left open.
3. Security update management. Hackers exploit known vulnerabilities in software. When a security patch is released, applying it quickly closes the hole. This control requires a process for applying updates to operating systems and software on a schedule.
4. User access control. Not everyone needs access to everything. Limiting who can access sensitive files, databases, and admin settings reduces the damage if an account is compromised. This control also includes using strong passwords and multi-factor authentication (a second check beyond the password).
5. Malware protection. Running antivirus or anti-malware software detects and removes malicious software. The control requires malware protection to be installed and kept up to date.
Do these controls actually work?
Yes. The NCSC, the UK government’s cyber security agency, designed Cyber Essentials specifically to prevent the most common attacks: phishing, ransomware, data theft, and denial-of-service. An organisation following all five controls is far harder to breach than one neglecting them. The controls aren’t perfect—targeted attacks by skilled adversaries can sometimes bypass them—but they stop the majority of attacks.
Cyber Essentials vs. Cyber Essentials Plus
There are two levels of certification.
Cyber Essentials involves a self-assessment: you answer questions about whether you’ve implemented each control, and an auditor reviews your answers. It costs from £320 plus VAT for small organisations.
Cyber Essentials Plus includes everything in Cyber Essentials, plus hands-on technical testing. An assessor connects to your network and tests whether the controls actually work, not just whether you say they work. Plus certification costs more but provides higher assurance. It’s typically required when applying for government contracts or working with large organisations that are security-conscious.
Who needs Cyber Essentials certification?
Formal certification isn’t mandatory for all businesses, but certain situations make it important:
- Government contracts: If you bid for work with government or large public sector organisations, they often require Cyber Essentials certification.
- Large business customers: Organisations like banks, insurers, and healthcare providers require their suppliers to be certified.
- Regulated industries: Charities, schools, and firms in regulated sectors often need to demonstrate security baselines.
- Peace of mind: If you handle sensitive customer data (financial, health, personal), certification shows your customers you’re serious about security.
For a small business with no government contracts and no particularly sensitive data, formal certification isn’t essential. However, implementing the five controls themselves is always wise.
How to get certified
Self-assessment route: Register with IASME (the body that manages Cyber Essentials), pay the fee (from £320 plus VAT), complete a self-assessment questionnaire, and have an assessor review your answers. This takes a few weeks and costs less than the Plus route.
Supported route: Hire an IASME-licensed cyber security consultant to guide you through understanding and implementing the controls, then help with the assessment. This is more thorough and more expensive but useful if your organisation has no cyber security knowledge.
Implementing without certification
If you don’t need formal certification but want to implement the controls yourself:
- Check your firewall: Are you using a router with a built-in firewall? Is it enabled?
- Disable unnecessary features: Turn off services and features you don’t use on computers and servers.
- Apply updates: Enable automatic updates for your operating system and software, and check for updates monthly.
- Enforce strong passwords: Require passwords with uppercase, lowercase, numbers, and symbols. Length matters more than complexity; longer passwords are harder to crack.
- Install antivirus: Use Windows Defender (built into Windows) or a reputable third-party option.
Key points
- Cyber Essentials is the UK government’s recommended baseline, built on five technical controls: firewalls, secure configuration, security updates, user access control, and malware protection
- These controls prevent most common attacks like phishing, ransomware, and data theft
- Formal certification is necessary for government contracts and some large-business customers; smaller firms may implement the controls informally
- Cyber Essentials costs from £320 plus VAT; Cyber Essentials Plus (with hands-on testing) costs more
- Implementing the five controls yourself is free; hire a consultant if you want help or formal certification
Related: Find IT support near you