Skip to content

Cyber Essentials myths, debunked.

Ten common misconceptions about Cyber Essentials v3.3 (effective 27 April 2026), reviewed against current scheme and procurement guidance. Each answer links to its relevant source or published offer terms.

Ten myths

The myths buyers, suppliers, and partners hear most often

Each verdict is rated against the scheme as written. False claims are bold, where the answer is genuinely nuanced we say so.

Myth 01Verdict · False

Cyber Essentials requires you to encrypt every hard drive in your organisation.

What is actually true

Cyber Essentials v3.3 does not impose a general full-disk-encryption requirement. Encrypting portable devices can be sensible protection for lost or stolen equipment, and a customer or other standard may require it, but that is a separate decision from the five Cyber Essentials controls.

Source: NCSC Cyber Essentials v3.3 requirements

Myth 02Verdict · False

Cyber Essentials only requires multi-factor authentication on admin accounts.

What is actually true

Cyber Essentials v3.3 requires MFA for cloud services wherever it is available, including paid options. Apply the requirements to the authentication paths and accounts in your assessment scope; an admin-only cloud policy does not cover ordinary cloud users. The scheme has separate controls for local and administrative accounts.

Source: IASME April 2026 MFA update

Myth 03Verdict · False

Cyber Essentials is only needed for UK government contracts.

What is actually true

Cyber Essentials is useful beyond government procurement, but the actual buyer or insurer decides what evidence it requires. Current PPN 014 applies to specified procurements by central-government bodies and NHS bodies; controls must be relevant and proportionate, and equivalent controls can be accepted. It is not a blanket certification mandate for every contract.

Source: Cabinet Office PPN 014

Myth 04Verdict · False

Cyber Essentials takes 90 days to complete.

What is actually true

Preparation and assessment are separate stages. Fig Group publishes a six-working-hour Basic assessment guarantee for a complete, compliant submission received before midday UK time on a UK Business Day, subject to the certification terms. Clarification, remediation and Plus testing need separate planning.

Source: Fig Group certification terms

Myth 05Verdict · False

Cyber Essentials is only for large companies.

What is actually true

Cyber Essentials is open to organisations of different sizes. Fig Group publishes a Micro tier for 1-9 staff at £299.99 + VAT, with other tiers based on organisation size. Check the applicable band and scope before buying.

Source: Fig Group published tier prices

Myth 06Verdict · False

Cyber Essentials certification means your organisation cannot be hacked.

What is actually true

Cyber Essentials assesses five foundational technical control categories. It reduces exposure to many common internet-based attacks, but does not guarantee that an organisation cannot be breached or replace monitoring and incident response.

Source: IASME scheme overview

Myth 07Verdict · False

You need a consultant to complete Cyber Essentials.

What is actually true

No. Cyber Essentials is a verified self-assessment: an organisation completes the questionnaire and a licensed certification body reviews it. Consultancy can help with preparation, but is not required to apply. Fig Group provides a free readiness checker for planning; it does not inspect your live configuration.

Source: IASME certification process

Myth 08Verdict · Partly true

Home routers used by remote workers are in scope for Cyber Essentials under v3.3.

What is actually true

A home router that the organisation provides to a worker is in scope. Other home routers, such as those provided by the worker or their ISP, are outside scope. The work device and cloud services still need their applicable controls; a home-router exclusion does not exclude them.

Source: NCSC v3.3 scope requirements

Myth 09Verdict · False

You must get Cyber Essentials Plus to be meaningfully certified.

What is actually true

Cyber Essentials is a certification in its own right: an independent body verifies the self-assessment. Plus adds technical testing. A buyer, insurer or tender may ask for Basic, Plus or equivalent controls; current PPN 014 calls for a proportionate, contract-specific choice.

Source: Cabinet Office PPN 014 assurance levels

Myth 10Verdict · False

A Cyber Essentials certificate is valid permanently.

What is actually true

Cyber Essentials certification lasts 12 months. Check the expiry shown on your certificate and complete renewal before it expires if your buyer or contract requires continuous certification. The scheme does not make an expired certificate current through a general grace period.

Source: IASME certification and renewal guidance

Next step

Certification, done properly.

Published pricing and an eligible Basic six-working-hour guarantee, subject to our certification terms. Explore the requirements before you buy.