Cyber Essentials 2026: The Complete Certification Guide
Cyber Essentials remains the UK's benchmark for basic security. This comprehensive guide covers the v3.3 requirements, CE vs CE Plus, costs, certification timeline, and how to prepare.

Section 01
Cyber Essentials 2026: The Complete Certification Guide
Cyber Essentials is a UK government-backed cybersecurity certification scheme delivered by IASME on behalf of the NCSC. It defines five technical controls - firewalls, secure configuration, user access control, malware protection, and security update management - that every UK SME should have in place. The certificate is valid for 12 months.
Cyber Essentials remains the UK's most widely-adopted cybersecurity certification scheme. Originally launched in 2014 by GCHQ and the NCSC, it has evolved into a foundational standard for businesses across every sector and size. In 2026, understanding Cyber Essentials is essential not just for compliance, but for vendor qualification, insurance pricing, and customer trust.
This guide walks you through the requirements, certification levels, costs, and practical path to achieving and maintaining certification.
Section 02
What Is Cyber Essentials?
Cyber Essentials is a government-backed, IASME-delivered certification scheme that defines five core security controls required to protect organisational IT systems against common cyberattacks:
1. Boundary firewalls and internet gateways
2. Secure configuration of IT infrastructure
3. User access control and privilege management
4. Malware protection
5. Security update management
The scheme is deliberately simple - not because cybersecurity is simple, but because these five controls prevent the vast majority of attacks that target UK organisations. Cyber Essentials doesn't certify advanced security or compliance with complex frameworks like ISO 27001. Instead, it certifies that you've implemented the hygiene basics.
This focus on fundamentals explains its rapid adoption:
- Some government procurements require Cyber Essentials or Plus where the contract and risk make it proportionate; PPN 014 sets out the approach for in-scope buyers.
- An insurer may consider certification, but cover and pricing depend on its own underwriting terms.
- A customer may request certification from a supplier; check the required entity, scope and level.
Section 03
Cyber Essentials v3.3: What Changed
The v3.3 requirements apply to applications started from 27 April 2026. Earlier applications can continue under v3.2. Check the version on your assessment account rather than assuming every live account follows v3.3.
Cloud and hybrid environments
Map your in-scope cloud accounts and services to the five controls. The applicant and provider have different responsibilities depending on whether the service is IaaS, PaaS or SaaS; check each service rather than assuming the provider covers the applicant's settings.
- AWS, Azure, GCP - Shared Responsibility Model
- Hybrid on-prem + cloud setups
- SaaS applications with third-party storage
Privileged access and modern identity
v3.3 emphasises modern identity and access management beyond traditional Active Directory.
- MFA requirements depend on the account and service described in the current scheme requirements; apply them to in-scope cloud services and relevant administration.
- Passwordless authentication (Windows Hello, FIDO2) explicitly supported
- Inventory service accounts and API tokens and check the current question-set scope for each.
- Remove or disable accounts when no longer needed; scheduled access reviews are useful additional practice.
Third-party and supply chain risk
Supplier reviews are useful wider risk management; the following are examples of good practice, not separate mandatory Cyber Essentials control themes.
- Contracts must require suppliers to maintain compatible security standards
- Regular security assessments of critical suppliers (annual minimum)
- Incident notification requirements from suppliers
- Supply chain mapping for critical dependencies
Data handling and privacy
The following data-handling measures may be appropriate for your wider legal and risk obligations, but they are not universal Cyber Essentials pass criteria.
- Encrypted storage for sensitive data at rest
- Encrypted transmission in transit (TLS 1.2 minimum)
- Documented data classification and handling procedures
- Clear data retention and destruction policies
Section 04
Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?
Cyber Essentials comes in two certification levels:
Cyber Essentials (CE)
What it is: A self-assessment certification covering the five controls above.
How it works:
- You complete a detailed questionnaire covering each control
- Questions are specific and technical - not vague
- You submit evidence of implementation (policies, screenshots, logs)
- Certified assessors review your submission
- Certification is awarded if you meet the standard
Cost: Fig Group publishes Basic assessment prices from £299.99 + VAT for Micro. Compare like-for-like packages; preparation and remediation cost extra where needed.
Time to certification: Preparation and remediation vary. Fig Group's Basic guarantee applies after receipt of a complete, compliant submission before midday UK time on a UK Business Day, under its terms.
Renewal: Annual (every 12 months)
Who needs it: Most organisations. CE is suitable if you can accurately self-assess your security posture and are comfortable with the responsibility of ongoing compliance.
Cyber Essentials Plus (CE+)
What it is: CE followed by independent technical verification of a representative sample. Plus is not a full penetration test.
How it works:
- You complete the CE questionnaire as above
- An IASME-licensed assessor conducts a technical audit of your systems
- The assessor performs the technical checks specified by the Plus scheme and reports any failures for remediation.
- The assessor interviews key staff (IT manager, network admin)
- Certification is awarded if you meet the standard and pass the technical assessment
Cost: Check the chosen Plus package, scope and published or quoted price; Fig Group publishes its tiers on the Plus page.
Time to certification: Depends on readiness, assessor scheduling and technical results. The Basic six-working-hour guarantee does not cover Plus.
Renewal: Annual
Who needs it: Buyers whose tender, contract or own risk decision calls for independent technical verification. No sector label alone creates a universal Plus duty.
How to Choose
Swipe across the table to view all columns.
| Factor | CE | CE+ |
|---|---|---|
| Budget tight? | ✓ | |
| Simple IT setup? | ✓ | |
| Buyer specifically requires Plus? | ✓ | |
| Need independently tested controls? | ✓ | |
| Complex network? | Check the buyer and risk scope | Consider Plus |
| Need technical validation? | ✓ | |
| Insurance decision? | Ask the insurer | Ask the insurer |
Our recommendation: Check the exact buyer requirement first. Basic may meet a request for Cyber Essentials; choose Plus where the buyer specifies it or independent technical verification is worth the additional assessment for your risk.
Section 05
The Five Controls: Practical Requirements
The NCSC technical requirements define the pass criteria. The examples below help with preparation; each assessment must follow its account version and agreed scope.
1. Firewalls
Control the boundary between in-scope devices or networks and the internet. Remove unnecessary inbound access, change default administrative passwords and document any permitted remote administration. An ordinary privately owned home router is outside the scheme boundary; an organisation-supplied router is in scope. A VPN, a particular appliance and universal outbound allow-listing are not mandatory architecture choices.
2. Secure configuration
Remove or disable unnecessary software, services and accounts, change default credentials and use supported settings on in-scope devices and services. Configuration baselines and drift monitoring can help at scale, but a named configuration-management product is not required. Document what is in scope and what you actually checked.
3. User access control
Give each user an appropriate account and restrict administrative privileges to those who need them. Apply the current scheme's MFA requirements to in-scope services and accounts, including cloud services; check how the service offers MFA and whether a paid option is required. Separate routine and administrative activity where applicable. PAM and quarterly access reviews are useful additional practices, not universal scheme tests.
4. Malware protection
Use an allowed malware protection approach on in-scope devices and keep it effective. Endpoint detection, web filtering and central alerting can add protection, but no named product or SIEM is a prerequisite for Basic certification.
5. Security update management
Keep in-scope operating systems, applications, firmware and devices supported. Apply high-risk or critical security updates within the scheme's 14-day window after release; address unsupported products and other applicable update questions under the account version. A monthly-only patch window cannot replace the 14-day requirement where it applies. Vulnerability scans can help find gaps but are not a universal Basic assessment test.
Logging, incident response, supplier reviews, encryption and data classification may be essential to an organisation's wider security or legal obligations. They should not be presented as extra Cyber Essentials control themes. Cyber Essentials Plus adds independent technical checks of the baseline; it is not a comprehensive penetration test.
Section 06
The Certification Process: Step by Step
1. Define scope and account version. Identify the legal entity, devices, networks and cloud services covered. Applications started before 27 April 2026 can continue under v3.2; newer applications use v3.3.
2. Prepare against the five controls. The free NCSC question set helps identify questions and possible gaps. Time and remediation depend on the actual environment.
3. Choose a route and package. Check the IASME certification-body finder for licence scope, or use an official self-led purchase route. Compare assessment fees separately from preparation, consultancy and tooling.
4. Submit and sign off. Complete the assessment portal questionnaire. An authorised senior person provides the required declaration. An assessor may ask for clarification or corrections.
5. Complete Plus testing if required. Plus needs a valid matching Basic certificate and technical assessment within the scheme window. Agree sample, access and scheduling with the Plus body; a combined package can include the Basic step.
6. Check the award and renewal date. Use the IASME certificate search to verify a certificate and its exact dates. Plan renewal and ongoing control maintenance separately.
Section 07
Costs Breakdown: What to Budget
The assessment fee is only one component. Fig Group's current Basic Micro fee starts at £299.99 + VAT, and Plus has its own published tiers. Other providers and supported packages may have different prices. Ask for a written quote showing VAT, organisation size, support, feedback and Plus scope.
Readiness work, remediation, staff time and optional tools depend on your starting position. A sole trader with supported devices may have little additional expenditure; a complex estate may need substantial changes. There is no defensible universal year-one investment, renewal cost or preparation duration. Budget from your inventory and identified gaps rather than a generic range.
Section 08
Getting Started in 2026
Check the five controls and your account version, identify gaps, choose the right Basic or Plus route for your buyer requirement, then submit when the answers and controls are ready. Fig Group's Basic guarantee starts after receipt of a complete, compliant submission before midday UK time on a UK Business Day, subject to certification terms. Preparation, remediation, feedback on non-compliant answers and Plus scheduling are separate from that clock.
Section 09
How Fig Group Supports Cyber Essentials
Fig Group's platform simplifies Cyber Essentials compliance through:
Automated evidence collection
Use available connected evidence to support control review. Confirm each integration's actual coverage, refresh interval and export before relying on it for an assessment.
Assessment readiness
Use the readiness questions and available checks to identify possible gaps before submission. They do not guarantee an assessor will find no further issues.
Continuous monitoring
Post-certification monitoring can help teams spot changes in connected systems. A valid certificate does not prove continuous compliance between assessments.
Renewal readiness
Keep a current inventory and records for annual renewal. Confirm which evidence can be reused and which controls need fresh review.
Use ongoing security hygiene to prepare for the next point-in-time certification assessment.
Section 10
The Bottom Line
Cyber Essentials is a useful baseline and is required by some specific buyers and contracts. Check the applicable tender and insurer terms before treating certification as a procurement or pricing condition.
Start with the current question set and your actual scope. Preparation time depends on the controls and remediation needed; the assessment clock begins only under the chosen provider's stated conditions.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
See how Fig Group simplifies certification and framework alignment for your organisation.
Request a demoRelated solutions
Continue exploring Fig Group
Related guides
Continue reading
Pricing
Cyber Essentials vs Cyber Essentials Plus: Cost Comparison (2026)
Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds a hands-on technical audit, which is why it costs more. This guide compares the cost of both certifications across every organisation size and explains which one your budget and your buyers actually require.
Read articleFrameworks
Cyber Essentials to ISO 27001: Building Your Compliance Journey
Cyber Essentials is a foundation, but ISO 27001 is the gold standard for comprehensive security. This guide walks you through the progression path, explains when to move up, and outlines the practical steps to advance from basic compliance to certification.
Read articleCompliance
Cyber Essentials Cost 2026: Complete UK Pricing Guide
How much does Cyber Essentials certification cost in 2026? See every organisation-size tier, what Fig Group includes, renewal costs and additional expenses to check before buying.
Read article

