← Back to Blog
Cybersecurity

Cyber Essentials Certification: Costs, Pass Rates, and What's Involved

10 September 2026 · By Ethan Fernandes

Cyber Essentials Certification: Costs, Pass Rates, and What's Involved

Everything you need to know about Cyber Essentials certification — the five controls, costs, CE vs CE Plus, pass rates, and common reasons businesses fail.

Cyber Essentials is a UK government-backed cybersecurity certification scheme. It's designed to help organisations protect themselves against the most common cyber attacks — and to prove to clients, partners, and insurers that they've done so. If you've been asked about it by a client, seen it in a tender requirement, or your insurer has mentioned it, here's everything you need to know.

Cyber Essentials covers five technical controls that protect against roughly 80% of common cyber attacks. It's not a guarantee of security, but it's a solid, practical baseline — and increasingly a requirement for doing business.

What Is Cyber Essentials?

Cyber Essentials is a certification scheme backed by the UK's National Cyber Security Centre (NCSC) and administered by IASME, the appointed accreditation body. It comes in two levels:

Cyber Essentials (CE): A self-assessment questionnaire. You answer questions about your security controls, an assessor reviews your answers, and if everything meets the standard, you're certified. No technical testing of your systems.

Cyber Essentials Plus (CE+): Everything in CE, plus a hands-on technical audit. An assessor actually tests your systems — vulnerability scans, phishing simulations, and verification that the controls you claimed are actually in place and working.

The Five Controls

Both levels of certification are built around five technical control themes:

1. Firewalls

Your internet-facing devices and network must be protected by a properly configured firewall. This includes your office router, any cloud services, and individual devices that connect to public networks. Default passwords must be changed, unnecessary ports must be closed, and admin interfaces must not be accessible from the internet.

2. Secure Configuration

Devices and software must be configured securely. That means removing unnecessary software, disabling unused accounts, changing default credentials, and ensuring only needed services are running. The principle is simple: reduce the attack surface.

3. User Access Control

User accounts must follow least privilege — people should only have access to what they need for their job. Admin accounts must be separate from day-to-day accounts, and MFA must be enabled wherever it's available. Password policies must meet minimum standards.

4. Malware Protection

You need active malware protection on all devices. This can be traditional antivirus, a next-gen endpoint detection and response (EDR) tool, or application whitelisting — but it needs to be running, updated, and configured to scan automatically.

5. Security Update Management

Software and operating systems must be kept up to date. Critical and high-severity patches must be applied within 14 days of release. Unsupported software (anything no longer receiving security updates) must be removed or isolated.

14 days — the maximum time allowed to apply critical or high-severity security patches under Cyber Essentials requirements

Costs

The IASME assessment fee for Cyber Essentials self-assessment is £300 + VAT for micro and small businesses (under 250 employees). Larger organisations pay more on a tiered scale.

That's the assessment fee alone. In practice, most small businesses also need some preparation work — fixing gaps, configuring controls properly, documenting their setup. If your IT is already well-managed, preparation might take a few hours. If there are significant gaps, it could take days or weeks.

Cyber Essentials Plus costs more because it involves an on-site or remote technical audit by a qualified assessor. Expect to pay £1,500 to £3,000+ for the assessment, depending on the size and complexity of your organisation. Again, that's just the assessment — remediation of any issues found is separate.

CE vs CE Plus: Which Do You Need?

For most small businesses, Cyber Essentials (standard) is the right starting point. It demonstrates you've met the baseline, it satisfies most contract requirements, and it's achievable without massive expense.

Cyber Essentials Plus is worth pursuing if:

  • A specific contract or framework requires it (some government contracts specify CE+ rather than CE)
  • You handle particularly sensitive data and want independent verification
  • Your cyber insurance requires or discounts for CE+
  • You want to demonstrate a higher level of commitment to clients

CE Plus is not "better" in the sense that it covers different controls. It tests the same five controls — it just verifies them independently rather than taking your word for it.

Pass Rates and Common Failures

The overall pass rate for Cyber Essentials self-assessment is relatively high — most organisations that prepare properly pass on their first attempt. But "prepare properly" is doing a lot of work in that sentence.

Common reasons for failure include:

  • Unsupported software. Running Windows 10 devices past end-of-life (October 2025), or using old versions of macOS, browsers, or office software that no longer receive security updates.
  • Missing MFA. Multi-factor authentication is now required on all cloud services and admin accounts. If you haven't enabled it on Microsoft 365, Google Workspace, or your other cloud tools, you'll fail.
  • Default passwords on routers or firewalls. The admin password on your office router that's still set to "admin" or "password" is an automatic fail.
  • Unpatched devices. Laptops or phones that haven't been updated in months. The 14-day patching requirement catches a lot of organisations off guard.
  • BYOD without management. If staff use personal devices to access work email and files, those devices are in scope. If you can't demonstrate they meet the five controls, they'll cause a failure.

The BYOD trap: Many businesses don't realise that personal phones accessing work email bring those devices into scope for Cyber Essentials. If staff check email on an unmanaged Android phone running an outdated OS, that's a fail — even if your office systems are perfect.

How Long Does It Take?

The self-assessment questionnaire itself takes a few hours to complete. But that assumes you already have the controls in place and can accurately describe your setup.

For a well-managed small business with an MSP already handling security, the whole process (preparation, questionnaire, submission, assessment) can be done in 2-4 weeks.

For a business starting from scratch — needing to implement MFA, update devices, configure firewalls, sort out BYOD — budget 4-8 weeks depending on complexity.

CE Plus takes longer because the technical audit needs to be scheduled with the assessor, and any issues found during the audit need to be remediated and re-tested.

Who Needs Cyber Essentials?

Cyber Essentials is technically voluntary, but it's increasingly a practical requirement:

  • Government contracts: Since 2014, most central government contracts involving the handling of sensitive or personal data require Cyber Essentials. See our detailed guide on Cyber Essentials and government contracts.
  • Supply chain requirements: Large organisations increasingly require their suppliers to hold CE certification.
  • Cyber insurance: Many insurers offer lower premiums for CE-certified businesses, and some require it as a condition of cover.
  • Client confidence: The certificate shows clients you take security seriously, backed by an independent standard rather than just your word.

Key takeaway: Cyber Essentials is achievable, affordable, and increasingly essential. The five controls are genuinely useful security measures, not bureaucratic box-ticking. If your IT is well-managed, certification is straightforward. If it isn't, the process of getting certified will fix the gaps that are putting your business at risk anyway.

We help businesses prepare for and achieve both Cyber Essentials and Cyber Essentials Plus certification — from initial gap assessment through to successful certification. If you're not sure where you stand, we can tell you in a quick call.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.