Cyber Essentials Certification
Cyber Essentials is the UK government-backed scheme that helps organisations guard against the most common cyber attacks. Whether you need certification to win contracts, reduce insurance premiums, or simply protect your business, SOC in a Box includes full Cyber Essentials support as standard.
How It Works
Your path to Cyber Essentials certification
Gap Analysis
Your named SOC analyst reviews your current environment against the five Cyber Essentials controls and identifies any gaps that need addressing before assessment.
Remediation
We provide practical, prioritised guidance to close any gaps — from firewall rules and patch schedules to access-control policies and secure configuration baselines.
Self-Assessment
Complete the IASME online questionnaire with hands-on support from your analyst, ensuring every answer accurately reflects your controls and environment.
Assessor Review
An IASME-licensed Certification Body reviews your submission, verifies your answers, and may ask follow-up questions. For Cyber Essentials Plus, a hands-on technical audit is also performed.
Certification
You receive your Cyber Essentials certificate, valid for 12 months. SOC in a Box provides ongoing monitoring and annual recertification support so you stay compliant year-round.
Cyber Essentials Cost
for UK Businesses
Certification costs depend on your organisation size and the level of assurance you need. The table below shows the IASME assessment fees alongside the SOC in a Box plan that includes full certification support.
| Business Size | Micro 0–9 staff |
Small 10–49 staff |
Medium 50–249 staff |
Large 250–999 staff |
Enterprise 1,000+ staff |
|---|---|---|---|---|---|
| CE Self-Assessment IASME assessment fee |
£300 + VAT | £300 + VAT | £400 + VAT | £500 + VAT | Contact us |
| CE Plus Audit Independent technical verification |
From £1,500 | From £1,500 | From £2,500 | From £3,500 | Contact us |
| Typical Timeline Assessment to certification |
1–2 weeks | 1–2 weeks | 2–4 weeks | 4–6 weeks | 6–8 weeks |
| SOC in a Box Plan Includes full CE support |
£335/mo 25 assets |
£335/mo 25 assets |
£600/mo 50 assets |
£1,000/mo 100 assets |
Contact us |
| What's Included | Gap analysis Remediation guidance Questionnaire support Named analyst 24/7 monitoring Annual recertification | ||||
IASME assessment fees are set by the IASME Consortium and paid directly to the Certification Body. CE Plus audit costs vary by environment complexity. All prices exclude VAT unless stated.
What Is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme, managed by IASME on behalf of the National Cyber Security Centre (NCSC). It defines five technical controls that, when implemented correctly, protect organisations against the most common internet-based threats.
The scheme is designed to be accessible to businesses of every size — from sole traders to large enterprises. For small businesses in particular, Cyber Essentials provides a clear, affordable baseline that demonstrates due diligence to customers, suppliers, and insurers.
Who Needs Cyber Essentials?
Cyber Essentials is relevant to every UK organisation, but it is mandatory for suppliers bidding on central government contracts that involve handling sensitive or personal information. Beyond government work, Cyber Essentials is increasingly required by:
- NHS and healthcare supply chains — NHS Digital recommends Cyber Essentials for all suppliers.
- Legal and financial services — the SRA and FCA expect demonstrable baseline security controls.
- Education — the ESFA requires colleges to achieve Cyber Essentials during the current funding year.
- Defence and engineering contractors — Tier-1 primes increasingly mandate it throughout the supply chain.
- Any business seeking cyber insurance — many insurers require certification before issuing cover.
Cyber Essentials Requirements in 2026
The current Cyber Essentials requirements are defined in Requirements for IT Infrastructure v3.2, published by the NCSC. Key updates for 2026 include strengthened guidance on cloud services, home and remote working, and zero trust architecture principles. The 14-day patching window for critical and high-severity vulnerabilities (CVSS v3 score of 7 or above) remains unchanged.
The Five Technical Controls
Cyber Essentials is built around five controls that address the most common attack vectors:
- Firewalls — boundary firewalls and internet gateways must be configured to restrict inbound and outbound traffic to only what is needed.
- Secure Configuration — computers and network devices must be configured to reduce vulnerabilities, including removing unnecessary software and changing default passwords.
- User Access Control — user accounts must follow least-privilege principles, with admin access limited to those who genuinely need it.
- Malware Protection — anti-malware software must be installed and kept up to date, or application whitelisting must be in place.
- Patch Management — software and operating systems must be kept up to date, with critical and high-severity patches applied within 14 days of release.
Cyber Essentials vs Cyber Essentials Plus
Cyber Essentials
- Self-assessment questionnaire
- Verified by a licensed assessor
- Covers the five technical controls
- From £300 + VAT
- Suitable for most small businesses
- Required for many government contracts
Cyber Essentials Plus
- Independent technical audit of your systems
- Includes vulnerability scans and phishing tests
- Verifies controls are working in practice
- Typically £1,500–£3,000
- Stronger assurance for clients and insurers
- Required for contracts handling sensitive data
Many small businesses start with Cyber Essentials and progress to Plus when clients, supply-chain requirements, or insurance conditions demand the higher assurance level. SOC in a Box supports both levels.
Cyber Essentials and Insurance Benefits
Holding Cyber Essentials certification can directly reduce the cost of cyber liability insurance — and in some cases is a prerequisite for obtaining cover. UK insurers increasingly require evidence that baseline controls are in place before they will issue or renew a policy.
- Lower premiums — insurers recognise that certified organisations have a smaller attack surface and are less likely to suffer a breach.
- Easier underwriting — the certificate provides third-party verification that fundamental controls are in place, streamlining the application process.
- NCSC-backed insurance offer — some insurers offer free cyber liability cover (up to £25,000) to organisations that achieve Cyber Essentials certification, in partnership with the NCSC.
SOC in a Box goes further by providing 24/7 monitoring, incident response, and a named analyst — giving insurers additional confidence in your security posture. Read our guide on what UK insurers actually want to see.
Is Cyber Essentials Enough for a Small Business?
Cyber Essentials is an excellent starting point. The five controls address around 80% of the most common attacks, and certification demonstrates to customers, partners, and regulators that you take security seriously.
However, Cyber Essentials is a point-in-time assessment — it confirms your controls were in place on the day you were assessed. It does not provide:
- Continuous monitoring of your network and endpoints
- Detection of advanced or targeted threats
- Incident response when something goes wrong
- Dark web monitoring for leaked credentials
- Data loss prevention controls
For genuine, ongoing protection, small businesses need to pair Cyber Essentials with continuous security monitoring. That is exactly what SOC in a Box delivers — 24/7 analyst coverage, AI-augmented detection with EmilyAI, deception technology via DecoyPulse, and full Cyber Essentials support, all from £335/month.
How SOC in a Box Helps You Get Certified
Cyber Essentials support is built into every SOC in a Box tier. Here is what that means in practice:
- Gap analysis — your named analyst reviews your current environment against the five controls and identifies what needs to change.
- Remediation guidance — practical, prioritised advice to close any gaps before you submit your self-assessment.
- Questionnaire support — help with completing the IASME self-assessment accurately and completely.
- Ongoing compliance — continuous monitoring ensures your controls stay in place year-round, not just on assessment day.
- Recertification — annual support to maintain your certification without starting from scratch.
Frequently Asked Questions
How much does Cyber Essentials cost for a UK small business?
The IASME self-assessment fee for Cyber Essentials is £300 + VAT for micro and small organisations. Cyber Essentials Plus, which includes an independent technical audit, typically costs between £1,500 and £3,000 depending on the size and complexity of your environment.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment questionnaire covering five technical controls. Cyber Essentials Plus adds an independent hands-on technical audit that verifies those controls are working in practice, including vulnerability scans and simulated phishing tests.
Is Cyber Essentials enough for a small business?
Cyber Essentials is an excellent starting point and covers the most common attack vectors. However, it does not replace ongoing monitoring, incident response, or advanced threat detection. Pairing certification with a managed security service like SOC in a Box provides continuous protection beyond the baseline.
Does Cyber Essentials help with cyber insurance?
Yes. Many UK insurers offer lower premiums or require Cyber Essentials certification as a condition of cover. Certification demonstrates that baseline controls are in place, reducing your risk profile and making your business more insurable.
How long does it take to get Cyber Essentials certified?
Most small businesses can complete the Cyber Essentials self-assessment in one to two weeks once the five technical controls are in place. Cyber Essentials Plus typically takes an additional two to four weeks to schedule and complete the technical audit.
Do I need Cyber Essentials to work with the UK government?
Yes — since 2014, Cyber Essentials certification has been mandatory for suppliers bidding on UK government contracts that involve handling sensitive or personal information. Many private-sector organisations now also require it from their supply chain.
Ready to get certified?
Every SOC in a Box tier includes Cyber Essentials support, 24/7 monitoring, a named analyst, and cyber liability insurance — from £335/month.