London, United Kingdom
info@siaacsconsulting.co.uk

What Are the Requirements for Cyber Essentials Certification in the UK?

What Are the Requirements for Cyber Essentials Certification in the UK?

Cyber security is no longer something only large companies need to worry about. Small and medium-sized businesses across the UK also handle customer information, emails, online accounts, cloud systems and other digital services that can be targeted by cyber criminals.

Cyber Essentials Certification gives businesses a practical way to improve their basic cyber security and show customers that appropriate controls are in place. It is a UK government-backed scheme designed to help organisations protect themselves against common online threats.

But what exactly do you need to achieve Cyber Essentials Certification?

The answer is based around five key technical controls. In 2026, organisations preparing for certification should work against the current Cyber Essentials Requirements for IT Infrastructure v3.3, which came into effect on 27 April 2026.

Let's look at the main requirements in simple terms.

What is Cyber Essentials Certification?

Cyber Essentials is designed to help organisations of different sizes and sectors develop pathways to address basic cyber risks with better security.

It is based on the reduction of the most common cyber risks.

The certification process involves filling out a self-assessment questionnaire that a third party reviews. Organisations must have an IT setup that meets Cyber Essentials requirements.

Cyber Essentials Plus verifies the same basic technical controls as the original, but carries out some technical tests to confirm that the controls are working.

For many organisations, Cyber Essentials is the first correct step in the right direction for improved cyber security.

The Five Main Cyber Essentials Requirements

Five main control areas build on the requirements.

  1. Firewalls and internet gateways
  2. Secure config
  3. Update management
  4. Access control
  5. Malware Protection

These areas address areas common to most cyberattacks.

1. Firewalls

The systems your business uses to connect to untrusted external networks, for example, the public internet, must be protected.

Firewalls help manage traffic in a network and help prevent unwanted connections to devices or services.

Your business should identify and manage the exposed services on the internet to allow only service connections that are required.

Organisations utilising remote access, cloud services, or internet-based systems must be the most secure.

2. Secure Configuration

Configure Securely

Computers, notebooks, mobile devices and networking systems must be configured securely.

The NCSC currently stipulates that organisations remove or disable accounts and software that they do not need and set non-default and guessable passwords. Considering these requirements, a secure configuration can include the removal of unnecessary software, the disabling of unused accounts, default password settings, and administrator privilege limiting, along with other security controls. The overall goal is to reduce opportunities for attack.

3. Security Update Management

Software vulnerabilities offer attackers a simple route into a business network.

Therefore, organisations must have a formalised process for assessing and installing security updates for their operating systems, applications, and network equipment, among others.

You must know the technology your business relies on.

Leaving unsupported, old, and vulnerable software running provides a significant risk.

4. User Access Control

Not every employee needs every system.

Cyber Essentials stresses reducing user access and setting user permissions as needed.

Things to consider include:

  • User accounts

  • Administrator accounts

  • Access permissions

  • Password-based authentication

  • Multi-factor authentication

  • Revoking access when employees leave

  • Managing privileged accounts

Good access control means restricting user access to a given service.

This measure helps minimise the damage caused by compromised accounts.

5. Protection from Malware

Malware is a malicious program which can be used to either cause damage to a system, steal information, or even disrupt business operations.

Various active technical measures must be employed by businesses to minimise the risks imposed by malware; these may include built-in security features, antimalware software, application controls, or other measures.

Cyber Essentials involves more holistic protective measures for a business beyond just the installation of antivirus software. The overall goal is to ensure the organisation's devices and systems are adequately protected against commonly observed threats.

What About Passwords and Multi-Factor Authentication?

Passwords remain an important part of cybersecurity.

Businesses should avoid weak, predictable or reused passwords and ensure that default credentials are changed. The current technical requirements also address authentication and device access.

Multi-factor authentication can provide an additional layer of protection because a user needs more than just a password to access certain services.

Your organisation should review how employees authenticate to important systems and make sure the controls meet the requirements applicable to your environment.

What Information Does a Business Need to Prepare?

Before starting the Cyber Essentials assessment, it helps to understand your IT environment.

You should have a clear picture of:

  • Computers and laptops
  • Mobile devices
  • Servers
  • Network equipment
  • Cloud services
  • Software applications
  • User accounts
  • Internet-facing services
  • Remote working arrangements
  • Security controls

The NCSC provides a Cyber Essentials Readiness Tool and assessment questions to help organisations understand what they need to address before certification.

Good preparation can make the assessment much easier.

Is Cyber Essentials Mandatory in the UK?

Cyber Essentials is not automatically mandatory for every UK business.

However, certification can be required for certain contracts and procurement opportunities. The UK Government's Procurement Policy Note 014 explains that Cyber Essentials or Cyber Essentials Plus may be required for certain government contracts, particularly where suppliers handle specified types of information or provide certain ICT services.

This means businesses looking to work with government departments or larger organisations should check the cyber security requirements included in their contracts and tenders.

Even when certification is not mandatory, having it can help demonstrate that your business takes cyber security seriously.

How Do You Prepare for Cyber Essentials Certification?

A sensible preparation process can be broken down into a few straightforward steps.

Step 1: Understand the Requirements

Start by reviewing the current Cyber Essentials requirements and assessment questions.

Step 2: Review Your IT Systems

Identify the devices, software, users and services that fall within your assessment scope.

Step 3: Find Security Gaps

Check whether your current systems meet the five technical control areas.

Step 4: Fix the Issues

Address weaknesses such as unsupported software, unnecessary accounts, poor configurations or inappropriate access permissions.

Step 5: Complete the Assessment

Once your organisation is ready, complete the verified self-assessment through an appropriate certification route.

Step 6: Maintain Your Controls

Cyber security should not stop once you receive your certificate. Continue reviewing your systems and keeping your controls up to date.

How SIA ACS Consulting Can Help

Planning for Cyber Essentials Certification can seem daunting. That’s where SIA ACS Consulting steps in.

Intended to help UK companies plan and prepare for certification, SIA ACS Consulting’s services cover reviewing a company’s existing cyber security controls, assisting with documentation, and helping companies improve.

Certification and framework completion are signs of commitment to security, but implementing controls to protect your company after a framework’s completion is vital.

Understanding Cyber Essentials

The Cyber Essentials framework has made improving basic cyber security easier by identifying key areas of basic cyber security and providing guidance to help companies identify them without overcomplicating the process.

The five key areas are Firewall and Internet Gateways, Secure Configuration, Management of Security Updates, Access Control, and Malware Protection. Organisations striving to address these key areas are likely to manage many common cyber risks, and do so in a way that will demonstrate an accountable and responsible information security stance.

Most UK organisations are especially interested in 2026, as the technical requirements' version has now been upgraded to 3.3. Organisations seeking certification need to rely on the latest version and not older ones.

If your company is attempting to achieve Cyber Essential certification and you want to ensure that your current systems comply with the requirements, SIA ACS Consulting can help.