Living guide · Compliance & Cyber Essentials

Cyber Essentials for Small Businesses: What It Is, What It Costs and How to Pass First Time

The government-backed baseline for UK businesses, explained without the jargon: the five controls, Cyber Essentials versus Plus, the current question set, prices, the included insurance, and the mistakes that fail assessments.

Last reviewed 10 September 2026 Published 10 September 2026 12 min read
Book a Discovery Call
This guide is for you if
  • A customer, insurer or tender has asked whether you hold Cyber Essentials.
  • You want a recognised, affordable way to prove your business takes security seriously.
  • You have tried the questionnaire and got stuck on what the questions actually mean.
In this guide
  1. 1. What it is
  2. 2. The five controls
  3. 3. What changed in 2025
  4. 4. What it costs
  5. 5. Why bother
  6. 6. How to pass
  7. 7. How we help
  8. 8. FAQs
01

What Cyber Essentials is, and what it is not

Cyber Essentials is the UK government's baseline cyber security standard, run by the National Cyber Security Centre (NCSC) and delivered through its partner IASME. It certifies that your business has five basic technical controls in place. The NCSC's own description is that it is "the minimum standard of cyber security recommended by the Government for organisations of all sizes."

It comes in two levels:

  • Cyber Essentials is a self-assessment. You answer a questionnaire about your systems, a senior person signs it, and a qualified assessor reviews the answers. Most small businesses complete it in a few weeks.
  • Cyber Essentials Plus covers the same five controls, but an assessor tests them: vulnerability scans of your devices, checks that patches are actually installed, that malware protection works, and that a phishing email with a dodgy attachment is handled correctly. It must be completed within three months of passing the self-assessment.

What it is not: a guarantee against attack, a full security audit, or a replacement for backups, monitoring and staff awareness. It is a floor, not a ceiling. It is also not a legal requirement for most businesses; it is a contractual one when a customer, a public-sector buyer or the MOD asks for it.

Certificates are valid for 12 months, so it is an annual cycle.

02

The five controls, in plain English

ControlWhat the assessor wants to seeWhat it usually means in a Microsoft 365 business
FirewallsEvery device and your internet connection has a firewall on, with no unnecessary services open to the internet, and default passwords changed.Windows and macOS firewalls enabled by policy; the router's admin password changed; no remote desktop open to the world.
Secure configurationDevices and cloud services set up to minimise ways in: unused accounts and software removed, auto-run off, screen locks on.Intune baseline policies, admin accounts separated from everyday accounts, no shared logins.
Security update managementSupported software only, updates on, and high or critical vulnerability fixes applied within 14 days of release.Automatic updates for Windows, macOS, browsers and Office; a way to prove it (Intune or an RMM tool); no Windows 10 machines without paid extended updates.
User access controlEvery user has their own account, admin rights only where needed, MFA on cloud services, and a process for joiners and leavers.MFA enforced for all users in Entra ID; passwordless methods must be FIDO2 compliant; admins use separate accounts.
Malware protectionAnti-malware on every device, kept up to date, or an approved-apps-only model on phones.Microsoft Defender (included in Business Premium) managed centrally, or another product with evidence it is on everywhere.

Every device in scope counts: laptops, desktops, servers, phones and tablets that access company data, including staff-owned phones with work email on them. Remote workers are explicitly in scope under the current question set.

Not sure which of these applies to your business? Ask an engineer.

Book a Discovery Call
03

The current question set: what changed in 2025

The question set in force since 28 April 2025 is version 3.2, known as Willow. If you certified before then, three changes matter most:

  1. Vulnerability fixes, not just patches. The requirement is now to apply any fix the vendor recommends for a high or critical vulnerability within 14 days, whether that is a patch, a configuration change or a registry fix. "We are waiting for the next update cycle" is no longer an answer.
  2. Passwordless authentication is recognised. Biometrics, security keys, one-time codes and push notifications are all acceptable instead of a password, provided any passwordless method is FIDO2 compliant.
  3. Remote and home working is spelled out. Staff working from home, hotels and cafés on untrusted networks are in scope, and the controls have to reach their devices.

The other perennial: unsupported software fails you. Windows 10 reached the end of free support in October 2025. A business with Windows 10 machines and no paid Extended Security Updates cannot pass. This is the single most common reason we see a first attempt fail.

04

What it costs

IASME's assessment fee for Cyber Essentials is tiered by organisation size. NCSC states it starts at £320 + VAT; the published tiers are:

Organisation sizeAssessment fee (ex VAT)
Micro (0 to 9 staff)£320
Small (10 to 49)£440
Medium (50 to 249)£500
Large (250+)£600

Figures are IASME's list prices as reported in September 2026; confirm with your certification body when you book.

Cyber Essentials Plus is quoted individually because it depends on how many devices and locations have to be tested. UK certification bodies commonly charge in the low thousands of pounds for a small business, on top of the self-assessment fee.

The bigger cost is usually remediation: replacing unsupported machines, buying a licence that includes device management and Defender, and the engineering time to enforce MFA and patching properly. For a business already on Microsoft 365 Business Premium with devices in Intune, that work is mostly configuration. For a business on older kit with no management tooling, it can be the largest line.

Included insurance. A UK-domiciled organisation with turnover under £20m that certifies its whole organisation is automatically entitled to cyber liability insurance arranged through IASME, with a total liability limit of £25,000 and a 24-hour incident helpline. It is not a substitute for a proper cyber policy, but it is real cover for the price of the assessment.

Want a second opinion before you buy licences?

We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.

Book a Discovery Call
05

Why a small business bothers

  • Contracts. Central government contracts that involve handling personal or sensitive information require it, and the MOD requires it from suppliers handling its information. Increasingly, larger private-sector customers ask for it in supplier questionnaires.
  • Insurance. Some insurers price or condition cyber cover on it; all of them ask the same questions it answers.
  • It forces the basics. The five controls are the ones that stop the majority of commodity attacks: phishing that steals a password without MFA, ransomware that lands on an unpatched laptop, a leaver whose account is still active.
  • It is a credible badge. Unlike a self-declared "we take security seriously", a certificate is issued by a third party against a public standard and can be checked on the NCSC's register.

What it will not do is protect you from a targeted attack, recover your data after ransomware, or tell you that someone is inside your systems right now. Those need backups and monitoring, which are separate conversations.

06

How to pass first time

The sequence we use with clients:

  1. Scope. Decide whether the whole organisation is in scope (it should be, for the insurance and for credibility) and list every device, cloud service and user.
  2. Gap check. Compare each of the five controls with what is actually in place. The usual gaps: MFA not enforced for everyone, admin rights on everyday accounts, an unsupported PC in a corner, no evidence of patch timelines, staff phones with work email and no management.
  3. Fix the gaps. In a Microsoft 365 business this is largely Entra ID and Intune configuration, plus replacing anything unsupported.
  4. Answer the questionnaire from evidence, not memory. Assessors mark answers against the standard; vague answers are marked down. We answer on the client's behalf or alongside them.
  5. Book Plus within three months if you are going for it, so the self-assessment does not have to be repeated.

Common reasons for failing: unsupported operating systems, MFA not on every cloud service, no documented joiner and leaver process, personal devices in scope without controls, and answers that describe intentions rather than what is configured today.

Not sure which of these applies to your business? Ask an engineer.

Book a Discovery Call
07

How Black Sheep Support helps

We prepare businesses for Cyber Essentials and Cyber Essentials Plus as part of our managed service, and as a standalone project for businesses that just need to get over the line. In practice that means the gap check, the configuration work in Microsoft 365 and Intune, the evidence for patching and MFA, and the questionnaire answered properly.

The settings Cyber Essentials asks for are the same ones we put in place as standard for every client, which is why our clients tend to find the annual renewal uneventful. If you want to see how your Microsoft 365 setup measures up first, our Microsoft 365 licensing and security guide explains which licence gives you the tooling, and the free IT Health Check benchmarks where you stand today.

Want a second opinion before you buy licences?

We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.

Book a Discovery Call
08

Frequently asked questions

How much does Cyber Essentials cost?

IASME's assessment fee for the self-assessed Cyber Essentials starts at £320 + VAT for micro organisations and rises with size to £600 + VAT for large ones. Cyber Essentials Plus is quoted individually and typically costs a small business a few thousand pounds. Remediation work, such as replacing unsupported computers, is extra.

How long does Cyber Essentials take?

A prepared business can complete the self-assessment in a few days. A business that needs to fix gaps first usually takes four to eight weeks, most of it replacing unsupported kit and enforcing MFA and patching. Plus adds an assessment visit or remote test.

Is Cyber Essentials a legal requirement?

No. It is required for certain government and MOD contracts and increasingly requested by customers and insurers, but there is no general legal obligation to hold it.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Same five controls. Cyber Essentials is a verified self-assessment; Plus adds independent technical testing of a sample of your devices and must be completed within three months of passing the self-assessment.

Does Microsoft 365 Business Premium make Cyber Essentials easier?

Yes. Intune, Defender for Business and Conditional Access cover most of the device management, malware protection, patch evidence and MFA requirements, and give you something to show the assessor. Premium is not required, but it is the simplest route for a Microsoft 365 business.

Do staff phones count?

Yes, if they access company data such as email or Teams. They need a screen lock, a supported operating system, and either management through Intune or app protection policies that keep company data separate. Under the current question set, remote and personal devices are explicitly in scope.

What happens if we fail?

You get feedback on what was marked down and can resubmit. Most failures are unsupported software, MFA gaps or vague answers, all of which are fixable. We prepare businesses so that the first attempt passes.

How long is the certificate valid?

Twelve months. Renewal is an annual cycle, which is why building the controls into everyday IT management matters more than a one-off push.

Get Cyber Essentials without the guesswork

Whether a customer has asked for it or you want the badge on your own terms, we will tell you what stands between you and a pass, fix it, and handle the questionnaire.

  • A gap check against the five controls and the current question set.
  • A plain-English list of what needs fixing, and what it would cost.
  • Whether Plus is worth it for your situation.
  • A route to certification that fits how your business actually works.
Book a Cyber Essentials call

Sources

Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.

  1. 1.NCSC: Cyber Essentials overview (five controls, IASME, pricing from £320, insurance) · accessed 10 September 2026
  2. 2.IASME: Cyber Liability Insurance (turnover under £20m, £25,000 limit) · accessed 10 September 2026
  3. 3.IASME: Cyber Essentials frequently asked questions (validity, Plus window) · accessed 10 September 2026
  4. 4.NCC Group: Cyber Essentials April 2025 (Willow) update · accessed 10 September 2026

What has changed on this page

  • 10 September 2026Page published. Reflects the Willow (v3.2) question set in force since 28 April 2025 and IASME's current pricing tiers.

Related reading