Cyber Essentials Certification for London Businesses
The UK government-backed security baseline. We get your systems ready, walk you through the assessment, and only put you forward when we know you will pass.
- 5 controls
- Firewalls, secure settings, access control, malware, updates
- 12 months
- How long a certificate lasts before you recertify
- 2–4 weeks
- Typical time to certified, for a reasonably well-run network
- v3.3
- Current requirements — the Danzell question set, from April 2026
Key Requirements
Firewalls and Internet Gateways
Every device that touches the internet needs a properly configured firewall. Default passwords changed, services you do not use switched off, and the firewall built into each machine turned on — including the laptops people use at home.
Secure Configuration
Devices and software set up to remove easy openings. Take off software nobody uses, disable dormant accounts, change every default password. Since 2026 this explicitly covers your cloud platforms too, such as Microsoft 365 and Google Workspace.
User Access Control
People get access to what they need and nothing more. Admin accounts kept separate from everyday ones, leavers removed quickly, and multi-factor authentication switched on. Under v3.3, MFA on cloud services is required for every user.
Malware Protection
Every device runs anti-malware that updates itself and scans in real time, or uses application allow-listing instead. Endpoint detection and response (EDR) tools satisfy this control and are increasingly what assessors expect to see for Plus.
Security Update Management
Critical and high-severity patches applied within 14 days. Everything licensed and still supported by its vendor. Software past its end-of-life is an automatic fail unless it is properly cut off from the network.
Cloud Services in Scope
Anything your staff sign into with a work account that holds or handles your data — SaaS, IaaS and PaaS alike. The 2026 update closed a gap plenty of firms had been relying on, and now assesses cloud settings alongside everything on-premise.
What Cyber Essentials is
Cyber Essentials is the UK government’s baseline for cyber security. The National Cyber Security Centre created it, and IASME runs it.
The thinking behind it is straightforward. Most attacks are not clever. They find unpatched software, weak passwords, and devices left on default settings. Cyber Essentials sets out five technical controls that shut down the great majority of them.
Certification gives you an independently checked statement that those controls are in place. For a lot of London firms it is now the minimum their clients, insurers and partners expect to see.
It covers everything in scope — laptops, servers, phones, network equipment, and the cloud services your staff sign into. Any size of organisation can certify, from sole traders upwards.
What it actually gets you
Almost nobody certifies for the certificate. It earns you four things.
- Contracts. Public-sector tenders increasingly require it, and some require Plus. Without it you are filtered out before anyone reads your bid.
- Better insurance conversations. Many insurers now ask. Some make it a condition of cover, others improve the terms when you hold it.
- Faster procurement. Larger clients vet their suppliers. The certificate answers the security questionnaire before it lands.
- Fewer incidents. Beyond the paperwork, the controls genuinely reduce your exposure to phishing, ransomware and stolen credentials.
Cyber Essentials or Cyber Essentials Plus?
There are two levels, and the difference is simple.
Cyber Essentials is a self-assessment. You answer questions about how your systems are set up, and an accredited certification body checks your answers against the standard.
Cyber Essentials Plus covers the same five controls, then a qualified assessor tests them. They scan your devices, check patch levels, and confirm that MFA and malware protection work the way you said they do.
Cyber Essentials confirms what you say. Plus proves it.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| How it is checked | Self-assessment, reviewed by a certification body | An independent assessor tests your systems hands-on |
| Time to complete | Days, once you are ready | One to three days of audit, after preparation |
| Vulnerability scanning | None | Authenticated and unauthenticated scans on sampled devices |
| MFA | You declare it | The assessor tests it on your cloud services |
| Valid for | 12 months | 12 months |
| Usually asked for by | Insurers, general supply-chain checks | Public-sector contracts, MOD supply chain, sensitive client data |
| Prerequisite | None | You must hold Cyber Essentials first |
Which one do you need?
- Someone asked for “Cyber Essentials” with no qualifier. They almost always mean the standard certification. Do not over-buy.
- A tender or framework names it. Read the wording closely. “Plus” is written explicitly when it is required, and nothing else substitutes for it.
- Your insurer asked. Standard is usually enough, and often improves the premium. Check whether Plus earns you more before paying for it.
- You hold sensitive client data and want the assurance to be real. Plus. The audit finds the gap between what you believe is configured and what actually is.
You cannot go straight to Plus. The self-assessment comes first, and the Plus audit has to follow within three months of it — so the two are best planned as one run.
Not sure where you stand? Our free Cyber Essentials readiness checker walks through the five controls and tells you what you would fail today, before you spend anything.
What changed in April 2026
The Danzell question set was published on 13 February 2026 and applies to every assessment account created after 26 April 2026, replacing Willow. It is assessed against version 3.3 of the NCSC Requirements for IT Infrastructure.
Three changes matter most.
- MFA across all cloud services. If a service offers multi-factor authentication in any form, it has to be on for every user. One qualifying account without it fails the assessment.
- Cloud services are firmly in scope. Anything staff sign into with a work account that holds or handles your data — Microsoft 365, Google Workspace, your CRM, your accounting package — is assessed alongside everything on-premise.
- Passwordless is encouraged. The access control guidance now points to passkeys and FIDO2 security keys as a stronger option than passwords.
Accounts created before 26 April 2026 have six months to certify under the previous requirements. If you certified in the last 12 months, do not assume you will pass again without preparation — the standard you renew against has moved. We check your environment against v3.3 before you apply.
For the detail, read our guide to what changed in Cyber Essentials v3.3.
Why firms fail
Most failures come down to the same handful of things, and every one of them is fixable in advance.
- MFA missing on a cloud service or an admin account. Under the 2026 rules that is an automatic fail.
- Unsupported software — an operating system past end-of-life, or an old line-of-business application still sitting on the network.
- Patching that has drifted, where critical updates slip past the 14-day window.
- Cloud services nobody listed, and which therefore never got checked.
- Default settings left untouched on a router, firewall or cloud tenant.
None of these are hard to fix beforehand. All of them are hard to fix on assessment day, which is why the pre-assessment audit is the single biggest factor in passing first time.
How we get you through first time
We do the technical work that decides whether you pass.
We start with a pre-assessment audit and turn it into a prioritised list of what needs fixing. Then we deploy and configure MFA across every account and cloud service, review and harden cloud platform settings such as Microsoft 365, verify patching across every endpoint, and confirm firewall and device settings meet the standard. For Plus, we run the same five test cases the assessor will run — the specification is public, so there is no reason to be surprised on the day.
On assessment day we handle the documentation and answer the certification body’s technical questions. We do not put an organisation forward until we are confident it will pass.
Certification is also easier to keep than to regain. Our cybersecurity services and managed IT support in London keep the controls in place all year, not just at assessment time.
What happens, step by step
- Scoping. We agree what is in scope — every device, user and cloud service that touches your data.
- Pre-assessment audit. We measure your environment against the current requirements and find every gap.
- Remediation. We close them: MFA, hardened settings, patching, access control.
- Assessment. We support your self-assessment submission, and for Plus we prepare for and sit alongside the technical audit.
- Certification and renewal. You pass, the certificate runs 12 months, and we keep you ready for the next one.
Most reasonably well-run environments take two to four weeks end to end. Legacy systems, bring-your-own-device, or a cloud estate nobody has mapped will push that towards six — not because the work is hard, but because there is more of it to find first.
Talk to us
Whether you need Cyber Essentials to win a contract, satisfy an insurer, or simply raise your baseline, we can take you from where you are now to a first-time pass.
Start with the free readiness checker if you want to see where you stand, or read about our full certification service. When you are ready, speak to our London team and we will scope it properly.
If you supply the NHS, see our DSPT compliance service too — Cyber Essentials Plus and DSPT are separate requirements, and both may apply.
Last updated:
FAQ
Frequently asked questions
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme. It was created by the National Cyber Security Centre (NCSC) and is run by IASME. It shows that an organisation has five baseline technical controls in place to defend against the most common internet-based attacks. It is one of the most widely recognised security certifications among UK businesses.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment that a certification body checks. Cyber Essentials Plus covers the same five controls, but a qualified assessor tests them hands-on — scanning your devices, checking patch levels, and confirming that MFA and malware protection genuinely work. Cyber Essentials confirms what you say; Plus proves it. Plus is often the version named in public-sector contracts and sensitive supply chains.
Can we go straight to Cyber Essentials Plus?
No. Cyber Essentials Plus is not a standalone route. You need to pass the verified self-assessment first, and the Plus audit has to be completed within three months of it — otherwise the self-assessment stage has to be done again. In practice it is best to plan both as one piece of work rather than two separate projects.
How long does Cyber Essentials certification take?
If your systems are already in good order, the self-assessment moves quickly and the Plus technical audit usually takes one to three days. Preparation is the bigger variable, typically two to six weeks depending on where you are starting from. The usual hold-ups are legacy systems, patching that has drifted, and MFA missing on a cloud service.
Do we have to have Cyber Essentials?
It is not a universal legal requirement, but it is contractually required in a growing number of situations. Since 2014 it has been mandatory for certain UK government contracts involving personal data or specific ICT services, and private-sector clients, insurers and supply-chain partners increasingly ask for it before they will work with a supplier.
What happens if we fail the assessment?
We would rather that did not happen, which is why we run your environment against the requirements before you apply and fix what we find. It matters more under Plus: since April 2026, if the security update test fails, the retest covers both the original sample of devices and a fresh random sample — and a second failure removes the certificate. A rushed submission is the expensive route, not the fast one.
What changed in Cyber Essentials for 2026?
The Danzell question set was published on 13 February 2026 and applies to all assessment accounts created after 26 April 2026, replacing Willow. It is assessed against version 3.3 of the NCSC Requirements for IT Infrastructure. The main changes are stricter multi-factor authentication across all cloud services, a clearer definition that brings cloud services firmly into scope, and updated guidance pointing towards passwordless methods such as passkeys. Accounts created before that date have six months to certify under the previous requirements.
Is MFA mandatory for Cyber Essentials?
Yes, and the 2026 update tightened it. If a cloud service offers multi-factor authentication in any form — built in, free or paid — it has to be switched on for every user. If a qualifying account is missing it at the time of assessment, the application fails. The current guidance also points to passwordless methods such as passkeys and FIDO2 security keys as a stronger option than passwords.
How often do we need to recertify?
Certification lasts 12 months, so you recertify annually. Each recertification is assessed against the current version of the standard, not the one you passed last time — so anything renewing under the Danzell question set is measured against v3.3.
We already have IT support. Can you still help?
Yes. Plenty of the work we do is alongside an existing IT provider or an internal team. We handle the certification: scoping, the pre-assessment audit, the remediation plan, and the submission itself. If it turns out your day-to-day IT is what is holding the certification back, we will tell you plainly rather than work around it.
Related compliance services
Need compliance guidance?
Book a free compliance review and we'll assess your readiness against the latest requirements.
- 30-day rolling contracts
- No callout fees
- Free assessment