Skip to content
Compliance

Cyber Essentials for Small Business: A Practical Guide

A straightforward guide to Cyber Essentials for small businesses and micro organisations. What it costs, how long it takes, and why it matters for your business.

woman standing beside the table

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

7 min read

Share

Section 01

Cyber Essentials for Small Business: A Practical Guide

If you run a small business in the UK, you have probably heard of Cyber Essentials. Perhaps a client has asked for it, a tender requires it, or your insurance provider mentioned it. But what does it actually involve, what does it cost, and is it worth it for a small team?

This guide answers those questions plainly.

Section 02

What Is Cyber Essentials?

Cyber Essentials is a UK government-backed certification that proves your business has basic cybersecurity controls in place. It is developed by IASME and the National Cyber Security Centre (NCSC). The certification covers five areas:

1. Firewalls - Protecting your internet connection

2. Secure configuration - Setting up devices securely

3. Security updates - Keeping software up to date

4. Access control - Managing who has access to what

5. Malware protection - Preventing malicious software

For most small businesses, these are controls you should already have in place. Basic provides an independently verified self-assessment; Plus adds technical testing against the same control requirements. Neither guarantees protection from every attack.

Section 03

What Does It Cost?

For micro organisations (1-9 employees), Cyber Essentials costs £299.99 + VAT with Fig Group. This is a one-off annual fee that covers the assessment, up to three feedback rounds and the certificate following a successful assessment; preparation or remediation costs are separate. There are no hidden fees.

Swipe across the table to view all columns.

Organisation SizeEmployeesPrice
Micro1-9£299.99 + VAT
Small10-49£399.99 + VAT

For most small businesses, this is the total cost. You do not need to hire a consultant or purchase additional software unless you have specific gaps in your controls.

Section 04

How Long Does It Take?

The assessment itself can be completed in a few hours. You answer a questionnaire about your IT setup - your firewall configuration, how you manage updates, how access is controlled, and whether MFA is enabled.

Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.

If you are not sure you are ready, use Fig Group's free readiness checker first. Allow time to provide accurate answers; it highlights possible gaps and is not a certification decision.

Section 05

Do I Really Need It?

If you bid for government contracts - Check the tender. PPN 014 applies to specified procurements by in-scope public bodies and permits certification or equivalent controls where required; it is not a universal rule for every public contract.

If clients ask for it - Increasingly, yes. Larger organisations are requiring their suppliers to hold Cyber Essentials as part of supply chain risk management. If you are a small business supplying services to a larger company, expect this question to come up.

If you want better cyber insurance - Some insurers offer reduced premiums or require Cyber Essentials as a precondition for cyber insurance policies.

If you want to protect your business - The five controls address common cyber risks. Avoid treating a single attack-prevention percentage or average breach cost as a prediction for your business; impact and protection depend on the incident and implemented controls.

Section 06

Common Concerns for Small Businesses

"We do not have an IT department." - You do not need one. Cyber Essentials is designed for organisations of all sizes, including those without dedicated IT staff. If you use cloud services like Microsoft 365 or Google Workspace, many of the controls are already built in. You just need to confirm they are configured correctly.

"Our setup is too simple to need certification." - A small device estate can make preparation easier. For a business with five laptops, cloud email and a broadband router, gather the actual configuration and account evidence before completing the questionnaire; preparation and assessment times depend on readiness.

"We cannot afford it." - At £299.99 + VAT, Cyber Essentials is one of the most affordable certifications available. Compare this to the cost of losing a client because you cannot prove your security controls, or the cost of a cyber incident.

"We use a managed IT provider." - That is fine. Your IT provider can help you complete the questionnaire by providing details about your firewall configuration, update policies, and security settings. Some MSPs offer Cyber Essentials preparation as a service. Our guide to Cyber Essentials with outsourced IT explains how to divide the preparation work between your business and your provider.

Section 07

Getting Started

1. Run the readiness checker to see where you stand

2. Address any gaps (most commonly: enabling MFA for users of in-scope cloud services)

3. Purchase your Cyber Essentials certification at Fig Group's pricing page

4. Complete the questionnaire and submit

Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.

For small businesses, preparation usually focuses on cloud-user MFA, supported software and the five controls. Enable MFA for every user account accessing in-scope cloud services, including administrator and third-party accounts. Implement MFA where available on non-cloud systems and apply the separate administrative-access and password controls; do not assume v3.3 mandates MFA on every local account regardless of availability. Document non-interactive service identities separately rather than treating them as human logins.

Get Cyber Essentials certified today

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.

Request a demo

Related solutions

Continue exploring Fig Group