Skip to main content
UK Government-backed Certification

Cyber Essentials Certification

Cyber Essentials is the UK government-backed scheme that helps organisations guard against the most common cyber attacks. Whether you need certification to win contracts, reduce insurance premiums, or simply protect your business, SOC in a Box includes full Cyber Essentials support as standard.

View pricing How it works
80%
of attacks blocked by basic controls
£300
IASME self-assessment fee (+ VAT)
5
technical controls to implement
215,000+
certificates awarded to date
Step by step

How It Works
Your path to Cyber Essentials certification

1

Gap Analysis

Your named SOC analyst reviews your current environment against the five Cyber Essentials controls and identifies any gaps that need addressing before assessment.

2

Remediation

We provide practical, prioritised guidance to close any gaps — from firewall rules and patch schedules to access-control policies and secure configuration baselines.

3

Self-Assessment

Complete the IASME online questionnaire with hands-on support from your analyst, ensuring every answer accurately reflects your controls and environment.

4

Assessor Review

An IASME-licensed Certification Body reviews your submission, verifies your answers, and may ask follow-up questions. For Cyber Essentials Plus, a hands-on technical audit is also performed.

5

Certification

You receive your Cyber Essentials certificate, valid for 12 months. SOC in a Box provides ongoing monitoring and annual recertification support so you stay compliant year-round.

Pricing

Cyber Essentials Cost
for UK Businesses

Certification costs depend on your organisation size and the level of assurance you need. The table below shows the IASME assessment fees alongside the SOC in a Box plan that includes full certification support.

Business Size Micro
0–9 staff
Small
10–49 staff
Medium
50–249 staff
Large
250–999 staff
Enterprise
1,000+ staff
CE Self-Assessment
IASME assessment fee
£300 + VAT £300 + VAT £400 + VAT £500 + VAT Contact us
CE Plus Audit
Independent technical verification
From £1,500 From £1,500 From £2,500 From £3,500 Contact us
Typical Timeline
Assessment to certification
1–2 weeks 1–2 weeks 2–4 weeks 4–6 weeks 6–8 weeks
SOC in a Box Plan
Includes full CE support
£335/mo
25 assets
£335/mo
25 assets
£600/mo
50 assets
£1,000/mo
100 assets
Contact us
What's Included Gap analysis Remediation guidance Questionnaire support Named analyst 24/7 monitoring Annual recertification

IASME assessment fees are set by the IASME Consortium and paid directly to the Certification Body. CE Plus audit costs vary by environment complexity. All prices exclude VAT unless stated.

What Is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme, managed by IASME on behalf of the National Cyber Security Centre (NCSC). It defines five technical controls that, when implemented correctly, protect organisations against the most common internet-based threats.

The scheme is designed to be accessible to businesses of every size — from sole traders to large enterprises. For small businesses in particular, Cyber Essentials provides a clear, affordable baseline that demonstrates due diligence to customers, suppliers, and insurers.

Cyber Essentials certification overview showing the five key security controls required for UK government-backed compliance

Who Needs Cyber Essentials?

Cyber Essentials is relevant to every UK organisation, but it is mandatory for suppliers bidding on central government contracts that involve handling sensitive or personal information. Beyond government work, Cyber Essentials is increasingly required by:

  • NHS and healthcare supply chains — NHS Digital recommends Cyber Essentials for all suppliers.
  • Legal and financial services — the SRA and FCA expect demonstrable baseline security controls.
  • Education — the ESFA requires colleges to achieve Cyber Essentials during the current funding year.
  • Defence and engineering contractors — Tier-1 primes increasingly mandate it throughout the supply chain.
  • Any business seeking cyber insurance — many insurers require certification before issuing cover.

Cyber Essentials Requirements in 2026

The current Cyber Essentials requirements are defined in Requirements for IT Infrastructure v3.2, published by the NCSC. Key updates for 2026 include strengthened guidance on cloud services, home and remote working, and zero trust architecture principles. The 14-day patching window for critical and high-severity vulnerabilities (CVSS v3 score of 7 or above) remains unchanged.

The Five Technical Controls

Cyber Essentials is built around five controls that address the most common attack vectors:

  • Firewalls — boundary firewalls and internet gateways must be configured to restrict inbound and outbound traffic to only what is needed.
  • Secure Configuration — computers and network devices must be configured to reduce vulnerabilities, including removing unnecessary software and changing default passwords.
  • User Access Control — user accounts must follow least-privilege principles, with admin access limited to those who genuinely need it.
  • Malware Protection — anti-malware software must be installed and kept up to date, or application whitelisting must be in place.
  • Patch Management — software and operating systems must be kept up to date, with critical and high-severity patches applied within 14 days of release.

Cyber Essentials vs Cyber Essentials Plus

Cyber Essentials

  • Self-assessment questionnaire
  • Verified by a licensed assessor
  • Covers the five technical controls
  • From £300 + VAT
  • Suitable for most small businesses
  • Required for many government contracts

Cyber Essentials Plus

  • Independent technical audit of your systems
  • Includes vulnerability scans and phishing tests
  • Verifies controls are working in practice
  • Typically £1,500–£3,000
  • Stronger assurance for clients and insurers
  • Required for contracts handling sensitive data

Many small businesses start with Cyber Essentials and progress to Plus when clients, supply-chain requirements, or insurance conditions demand the higher assurance level. SOC in a Box supports both levels.

Cyber Essentials and Insurance Benefits

Holding Cyber Essentials certification can directly reduce the cost of cyber liability insurance — and in some cases is a prerequisite for obtaining cover. UK insurers increasingly require evidence that baseline controls are in place before they will issue or renew a policy.

  • Lower premiums — insurers recognise that certified organisations have a smaller attack surface and are less likely to suffer a breach.
  • Easier underwriting — the certificate provides third-party verification that fundamental controls are in place, streamlining the application process.
  • NCSC-backed insurance offer — some insurers offer free cyber liability cover (up to £25,000) to organisations that achieve Cyber Essentials certification, in partnership with the NCSC.

SOC in a Box goes further by providing 24/7 monitoring, incident response, and a named analyst — giving insurers additional confidence in your security posture. Read our guide on what UK insurers actually want to see.

Is Cyber Essentials Enough for a Small Business?

Cyber Essentials is an excellent starting point. The five controls address around 80% of the most common attacks, and certification demonstrates to customers, partners, and regulators that you take security seriously.

However, Cyber Essentials is a point-in-time assessment — it confirms your controls were in place on the day you were assessed. It does not provide:

  • Continuous monitoring of your network and endpoints
  • Detection of advanced or targeted threats
  • Incident response when something goes wrong
  • Dark web monitoring for leaked credentials
  • Data loss prevention controls

For genuine, ongoing protection, small businesses need to pair Cyber Essentials with continuous security monitoring. That is exactly what SOC in a Box delivers — 24/7 analyst coverage, AI-augmented detection with EmilyAI, deception technology via DecoyPulse, and full Cyber Essentials support, all from £335/month.

How SOC in a Box Helps You Get Certified

Cyber Essentials support is built into every SOC in a Box tier. Here is what that means in practice:

  • Gap analysis — your named analyst reviews your current environment against the five controls and identifies what needs to change.
  • Remediation guidance — practical, prioritised advice to close any gaps before you submit your self-assessment.
  • Questionnaire support — help with completing the IASME self-assessment accurately and completely.
  • Ongoing compliance — continuous monitoring ensures your controls stay in place year-round, not just on assessment day.
  • Recertification — annual support to maintain your certification without starting from scratch.

Frequently Asked Questions

How much does Cyber Essentials cost for a UK small business?

The IASME self-assessment fee for Cyber Essentials is £300 + VAT for micro and small organisations. Cyber Essentials Plus, which includes an independent technical audit, typically costs between £1,500 and £3,000 depending on the size and complexity of your environment.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment questionnaire covering five technical controls. Cyber Essentials Plus adds an independent hands-on technical audit that verifies those controls are working in practice, including vulnerability scans and simulated phishing tests.

Is Cyber Essentials enough for a small business?

Cyber Essentials is an excellent starting point and covers the most common attack vectors. However, it does not replace ongoing monitoring, incident response, or advanced threat detection. Pairing certification with a managed security service like SOC in a Box provides continuous protection beyond the baseline.

Does Cyber Essentials help with cyber insurance?

Yes. Many UK insurers offer lower premiums or require Cyber Essentials certification as a condition of cover. Certification demonstrates that baseline controls are in place, reducing your risk profile and making your business more insurable.

How long does it take to get Cyber Essentials certified?

Most small businesses can complete the Cyber Essentials self-assessment in one to two weeks once the five technical controls are in place. Cyber Essentials Plus typically takes an additional two to four weeks to schedule and complete the technical audit.

Do I need Cyber Essentials to work with the UK government?

Yes — since 2014, Cyber Essentials certification has been mandatory for suppliers bidding on UK government contracts that involve handling sensitive or personal information. Many private-sector organisations now also require it from their supply chain.

Cyber Essentials included

Ready to get certified?

Every SOC in a Box tier includes Cyber Essentials support, 24/7 monitoring, a named analyst, and cyber liability insurance — from £335/month.

View pricing Contact us