UK IT & website support · plans from £25/month · £45/hour ad-hoc01623 650333 · Client login
Get help

Cyber Essentials Explained: What It Is and How to Pass

Cyber Essentials is the UK Government-backed certification proving your business has five basic security controls in place. Since April 2026, missing MFA on cloud services or late critical patches mean automatic failure. dijitul support gets your IT ready before you apply, at £45 an hour + VAT, with larger remediation quoted.

Updated 2026-10-10 · by the dijitul support team, Mansfield, UK

Key facts

  • Cyber Essentials covers five controls: firewalls, secure configuration, security update management, user access control and malware protection.
  • The scheme is run by the NCSC with IASME as its Cyber Essentials delivery partner.
  • The NCSC lists Cyber Essentials from £320 + VAT for the smallest organisations, with fees tiered by size.
  • From 27 April 2026, the new Danzell question set and requirements v3.3 apply.
  • Under v3.3, not using MFA on a cloud service that offers it is an automatic fail.
  • High-risk and critical updates must be installed within 14 days of release.
  • Cyber Essentials Plus adds independent technical testing of the same controls.

What Cyber Essentials is

Cyber Essentials is a UK certification scheme backed by the Government and run by the National Cyber Security Centre (NCSC). It checks that you have five basic technical controls in place, the kind that stop most everyday attacks such as phishing, password guessing and exploiting unpatched software. IASME is the NCSC's official delivery partner and works with a network of certification bodies who do the assessments.

There are two levels:

  • Cyber Essentials: you complete an online self-assessment questionnaire, which a certification body assesses.
  • Cyber Essentials Plus: the same controls, plus an independent assessor technically tests your devices and systems.

Certification lasts a year, so you need to renew annually. Many public sector contracts and some larger customers require it, and it is a useful health check even if nobody asks for it.

The five controls in plain English

  1. Firewalls. Every device that connects to the internet sits behind a firewall, including laptops used at home. Router admin passwords are changed from the default and remote admin is off.
  2. Secure configuration. Remove software and accounts you do not use, change default passwords, turn off auto-run, and lock devices with a PIN, password or biometrics.
  3. Security update management. Operating systems, apps and router or firewall firmware must be supported by the vendor and patched. Unsupported software, such as Windows 10 without Extended Security Updates, is out.
  4. User access control. Everyone has their own account, admin rights are only used for admin tasks, leavers are removed promptly, and MFA protects cloud services.
  5. Malware protection. Antivirus such as Microsoft Defender is active and up to date, or applications are restricted to an approved list.

What changed in April 2026 (Danzell and v3.3)

From 27 April 2026, assessments use a new question set called Danzell, which goes with version 3.3 of the NCSC's Requirements for IT Infrastructure. The biggest changes for small businesses are:

  • MFA is now an automatic fail. If a cloud service you use offers multi-factor authentication and you have not turned it on, the whole assessment fails. That covers Microsoft 365, Google Workspace, Xero, your website admin and any other cloud service that stores or processes business data.
  • The 14-day patching rule is an automatic fail too. High-risk and critical updates for operating systems, applications and router or firewall firmware must be installed within 14 days of release.
  • Cloud services cannot be excluded. If your organisation's data sits in a cloud service, it is in scope.

These details come from IASME and certification bodies' published summaries of the 2026 update. Always check the current requirements document on the NCSC website before you apply, as the scheme is reviewed regularly.

How to get ready yourself

  1. Make an inventory of every device (including personal phones used for work email), the operating system version, and every cloud service you use.
  2. Remove unsupported systems. Upgrade or replace anything out of support; see our guide on Windows 10 end of support.
  3. Turn on MFA everywhere it is offered, starting with Microsoft 365 or Google Workspace. Our password and MFA setup service can do this for you.
  4. Set automatic updates for Windows, macOS, browsers and Office, and check the router firmware.
  5. Remove day-to-day admin rights from staff accounts.
  6. Check antivirus is on and reporting on every device.
  7. Read the free question set from IASME and answer it honestly as a dry run before you pay.

When to call dijitul support

dijitul is not a certification body and does not certify you. What we do is the work beforehand: we review your devices, Microsoft 365 settings, MFA, patching and router configuration against the current requirements, fix the gaps, and help you answer the questionnaire accurately so you pass first time. Readiness work is £45 an hour + VAT; bigger remediation, such as replacing out-of-support PCs or rolling out Intune, is quoted.

See Cyber Essentials readiness, device management with Intune and our small business cyber security checklist.

Frequently asked questions

How much does Cyber Essentials cost?

The NCSC lists Cyber Essentials from £320 + VAT for the smallest organisations, with fees rising by organisation size. Cyber Essentials Plus is priced separately by certification bodies. Any IT work to get ready, such as dijitul's readiness help at £45 an hour + VAT, is extra.

What is an automatic fail in Cyber Essentials?

Since the April 2026 Danzell update, not using MFA on a cloud service that offers it, or not installing high-risk and critical updates within 14 days, fails the whole assessment regardless of your other answers.

Is Cyber Essentials a legal requirement?

No, it is voluntary for most businesses. It is required for many UK central government contracts that handle personal or sensitive information, and some customers and insurers ask for it.

How long does Cyber Essentials certification last?

Certification lasts 12 months, after which you complete a new assessment against the requirements in force at that time. Requirements change, so check the current NCSC version before each renewal.

Can dijitul certify my business for Cyber Essentials?

No. dijitul is not a certification body. dijitul prepares your IT so you meet the controls, fixes gaps like missing MFA or unsupported devices, and helps you answer the questionnaire accurately before you apply to a certification body.

Do personal phones count for Cyber Essentials?

Yes, if they access business email or data, they are in scope and must meet the same rules: a supported operating system, updates applied within 14 days, a screen lock and no jailbreaking.

Related

Tell us what you need

We scope it, give you a clear fixed quote and do the work. No jargon.

Call usGet help now