Cyber Essentials is a UK government backed certification scheme designed to help organisations protect themselves against the most common cyber threats. It was developed by the National Cyber Security Centre (NCSC) and has been mandatory for suppliers handling government contracts since 2014. But for the thousands of small businesses it wasn't designed for and is it actually worth doing?
The short answer: for most businesses under 100 people, yes and but not for the reasons most people expect.
- What Cyber Essentials actually tests and what it doesn't
- The difference between Cyber Essentials and Cyber Essentials Plus
- How much it costs and how long it takes
- The three reasons most SMEs don't realise they need it
- How SolvvSpace manages the process for you
What does Cyber Essentials actually cover?
The scheme tests your organisation against five technical controls and the areas where the vast majority of cyber breaches occur:
- Firewalls and are your network boundaries properly protected?
- Secure configuration and have you removed unnecessary features and changed default passwords?
- User access control and do staff only have access to what they actually need?
- Malware protection and are your devices protected against malicious software?
- Patch management and are your systems and software kept up to date?
It doesn't test everything. It won't protect you against a sophisticated nation state attack or a determined insider threat. What it does do is close the door on the opportunistic, automated attacks that account for the vast majority of breaches affecting small businesses.
The NCSC estimates that Cyber Essentials can prevent around 80% of the most common cyber attacks. For most small businesses, that's where the risk actually sits.
Cyber Essentials vs Cyber Essentials Plus and what's the difference?
Cyber Essentials is a self assessment. You fill in a questionnaire, an assessor reviews your answers, and if you pass, you receive certification. It's the starting point for most organisations.
Cyber Essentials Plus goes further. An assessor actually tests your systems and running vulnerability scans, checking your patch status, and verifying that your technical controls do what you say they do. It carries more credibility and is increasingly required by larger procurement teams.
If you're primarily looking to reduce risk and have a defensible security posture, Cyber Essentials is usually the right starting point. If you're selling to enterprise clients or tendering for larger contracts, Cyber Essentials Plus signals a higher level of assurance.
How much does it cost and how long does it take?
The certification fee itself varies by assessor but typically ranges from £300–£500 for Cyber Essentials and £1,500–£3,000 for Cyber Essentials Plus, depending on the size of your organisation and the scope being assessed.
The real cost is the time and remediation work required to pass. Most organisations have at least some gaps and a device running an outdated OS, a shared admin account, a firewall policy that hasn't been reviewed. Fixing these before assessment is where most of the effort goes.
Working with SolvvSpace, organisations typically achieve certification in four to six weeks from starting the process. We handle the pre assessment gap analysis, the remediation work, and the submission and so your team's time is minimal.
Three reasons SMEs need Cyber Essentials that aren't about cyber attacks
1. Cyber insurance is getting harder to obtain without it
Cyber insurance underwriters are tightening their requirements. Many now ask detailed questions about your technical controls as part of the application process and and some explicitly offer better terms or lower premiums to organisations with Cyber Essentials certification. Getting certified before you renew your policy is increasingly good financial sense.
2. Your clients and prospects are starting to ask for it
Enterprise procurement teams and NHS trusts, local authorities, housing associations, larger corporates and are increasingly including cyber security requirements in their supplier questionnaires. Cyber Essentials gives you a credible, standardised answer. Without it, you're relying on narrative responses that carry less weight.
3. Government contracts require it
If you supply to any UK government body and directly or as a subcontractor and Cyber Essentials has been a contractual requirement since 2014. This applies to contracts involving the handling of personal data or the provision of certain technical services. If you're in this space and don't hold certification, you're already out of scope for a significant proportion of public sector work.
SolvvSpace offers a free pre assessment review and we'll look at your current setup against the five Cyber Essentials controls and tell you exactly what needs to change before you apply. No commitment required.
How SolvvSpace manages the process
Most organisations attempt Cyber Essentials in-house and either take far longer than expected or fail on their first attempt because the gap analysis wasn't thorough enough. Our approach removes both problems:
- Week 1–2: Pre assessment gap analysis and we review your infrastructure, policies, and configurations against all five controls and produce a prioritised remediation list.
- Week 2–4: Remediation and we handle the technical fixes directly, or provide your IT team with clear instructions if you prefer to manage this internally.
- Week 4–6: Assessment and submission and we complete the questionnaire with you, submit to the certification body, and manage any follow up queries from the assessor.
After certification, we track your renewal date and flag it in advance so your certificate never lapses without notice.