Cyber security is no longer something only large companies need to worry about. Small and medium-sized businesses across the UK also handle customer information, emails, online accounts, cloud systems and other digital services that can be targeted by cyber criminals.
Cyber Essentials Certification gives businesses a practical way to improve their basic cyber security and show customers that appropriate controls are in place. It is a UK government-backed scheme designed to help organisations protect themselves against common online threats.
But what exactly do you need to achieve Cyber Essentials Certification?
The answer is based around five key technical controls. In 2026, organisations preparing for certification should work against the current Cyber Essentials Requirements for IT Infrastructure v3.3, which came into effect on 27 April 2026.
Let's look at the main requirements in simple terms.
Cyber Essentials is designed to help organisations of different sizes and sectors develop pathways to address basic cyber risks with better security.
It is based on the reduction of the most common cyber risks.
The certification process involves filling out a self-assessment questionnaire that a third party reviews. Organisations must have an IT setup that meets Cyber Essentials requirements.
Cyber Essentials Plus verifies the same basic technical controls as the original, but carries out some technical tests to confirm that the controls are working.
For many organisations, Cyber Essentials is the first correct step in the right direction for improved cyber security.
The Five Main Cyber Essentials Requirements
The systems your business uses to connect to untrusted external networks, for example, the public internet, must be protected.
Firewalls help manage traffic in a network and help prevent unwanted connections to devices or services.
Your business should identify and manage the exposed services on the internet to allow only service connections that are required.
Organisations utilising remote access, cloud services, or internet-based systems must be the most secure.
Configure Securely
Computers, notebooks, mobile devices and networking systems must be configured securely.
The NCSC currently stipulates that organisations remove or disable accounts and software that they do not need and set non-default and guessable passwords. Considering these requirements, a secure configuration can include the removal of unnecessary software, the disabling of unused accounts, default password settings, and administrator privilege limiting, along with other security controls. The overall goal is to reduce opportunities for attack.
Software vulnerabilities offer attackers a simple route into a business network.
Therefore, organisations must have a formalised process for assessing and installing security updates for their operating systems, applications, and network equipment, among others.
You must know the technology your business relies on.
Leaving unsupported, old, and vulnerable software running provides a significant risk.
Not every employee needs every system.
Cyber Essentials stresses reducing user access and setting user permissions as needed.
Things to consider include:
User accounts
Administrator accounts
Access permissions
Password-based authentication
Multi-factor authentication
Revoking access when employees leave
Managing privileged accounts
Good access control means restricting user access to a given service.
This measure helps minimise the damage caused by compromised accounts.
Malware is a malicious program which can be used to either cause damage to a system, steal information, or even disrupt business operations.
Various active technical measures must be employed by businesses to minimise the risks imposed by malware; these may include built-in security features, antimalware software, application controls, or other measures.
Cyber Essentials involves more holistic protective measures for a business beyond just the installation of antivirus software. The overall goal is to ensure the organisation's devices and systems are adequately protected against commonly observed threats.
Passwords remain an important part of cybersecurity.
Businesses should avoid weak, predictable or reused passwords and ensure that default credentials are changed. The current technical requirements also address authentication and device access.
Multi-factor authentication can provide an additional layer of protection because a user needs more than just a password to access certain services.
Your organisation should review how employees authenticate to important systems and make sure the controls meet the requirements applicable to your environment.
Before starting the Cyber Essentials assessment, it helps to understand your IT environment.
You should have a clear picture of:
The NCSC provides a Cyber Essentials Readiness Tool and assessment questions to help organisations understand what they need to address before certification.
Good preparation can make the assessment much easier.
Cyber Essentials is not automatically mandatory for every UK business.
However, certification can be required for certain contracts and procurement opportunities. The UK Government's Procurement Policy Note 014 explains that Cyber Essentials or Cyber Essentials Plus may be required for certain government contracts, particularly where suppliers handle specified types of information or provide certain ICT services.
This means businesses looking to work with government departments or larger organisations should check the cyber security requirements included in their contracts and tenders.
Even when certification is not mandatory, having it can help demonstrate that your business takes cyber security seriously.
A sensible preparation process can be broken down into a few straightforward steps.
Start by reviewing the current Cyber Essentials requirements and assessment questions.
Identify the devices, software, users and services that fall within your assessment scope.
Check whether your current systems meet the five technical control areas.
Address weaknesses such as unsupported software, unnecessary accounts, poor configurations or inappropriate access permissions.
Once your organisation is ready, complete the verified self-assessment through an appropriate certification route.
Cyber security should not stop once you receive your certificate. Continue reviewing your systems and keeping your controls up to date.
Planning for Cyber Essentials Certification can seem daunting. That’s where SIA ACS Consulting steps in.
Intended to help UK companies plan and prepare for certification, SIA ACS Consulting’s services cover reviewing a company’s existing cyber security controls, assisting with documentation, and helping companies improve.
Certification and framework completion are signs of commitment to security, but implementing controls to protect your company after a framework’s completion is vital.
The Cyber Essentials framework has made improving basic cyber security easier by identifying key areas of basic cyber security and providing guidance to help companies identify them without overcomplicating the process.
The five key areas are Firewall and Internet Gateways, Secure Configuration, Management of Security Updates, Access Control, and Malware Protection. Organisations striving to address these key areas are likely to manage many common cyber risks, and do so in a way that will demonstrate an accountable and responsible information security stance.
Most UK organisations are especially interested in 2026, as the technical requirements' version has now been upgraded to 3.3. Organisations seeking certification need to rely on the latest version and not older ones.
If your company is attempting to achieve Cyber Essential certification and you want to ensure that your current systems comply with the requirements, SIA ACS Consulting can help.