Tel: 03333 200 222
Email: info@swiftcomm.co.uk

What is Cyber Essentials and Does My Business Need It?

10/06/2026
6 minute read
Cyber Essentials is one of the most practical and achievable steps a UK business can take to improve its security posture. Find out more about the two certification levels, what changed in the 2026 update, and how to determine if you business needs it in this guide.
By, Becky Mack
Share

Why Cyber Essentials matters more in 2026 than ever before

If you’ve been hearing more about Cyber Essentials recently, there’s a good reason for it. What was once considered a useful but optional certification for UK businesses is increasingly becoming an expectation — from cyber insurers, enterprise clients, public sector procurement teams, and regulated sectors across the board.

According to the UK government's own Cyber Security Breaches Survey 2025/2026, 43% of UK businesses experienced a cyber security breach or attack in the last 12 months — equivalent to over 600,000 businesses across the country.

In this guide we’ll explain what Cyber Essentials actually is, what the two certification levels involve, what changed in the 2026 update, and how to decide whether your business needs it.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme, managed by IASME on behalf of the National Cyber Security Centre (NCSC). It's designed to help businesses of all sizes protect themselves against the most common internet-based cyber attacks.

The scheme is built around five core technical controls. When properly implemented, these controls block around 80% of common cyber attacks — not because they are sophisticated, but because they address the vulnerabilities that the vast majority of opportunistic attackers exploit.

Think of it less as an exam and more as a recognised standard of proof. The certification doesn’t tell you anything your IT team wouldn’t recommend anyway — it gives you the independently recognised evidence that you’ve actually done it. The certificate is valid for 12 months and must be renewed annually to remain valid.

The 5 core controls

The five technical controls that underpin Cyber Essentials haven’t changed in the 2026 update. What has changed is how rigorously some of them are assessed — particularly around cloud services and authentication.

1. Firewalls and internet gateways

A correctly configured firewall controls the traffic that can enter and leave your network, blocking unauthorised access while allowing legitimate communications. Under Cyber Essentials, all internet-connected devices must be protected by a properly configured firewall or equivalent boundary control.

2. Secure configuration

Devices and software should be configured securely from the outset — default passwords changed, unnecessary software removed, and settings reviewed to minimise vulnerabilities. Many successful attacks exploit default or poorly configured systems that businesses have simply never revisited.

3. User access control

Access to systems and data should be limited to those who genuinely need it, with strong authentication in place. Under the updated v3.3 standard, multi-factor authentication (MFA) is now required for all cloud services where it is available — not just admin accounts. Read more about what MFA is and why it matters.

4. Malware protection

Anti-malware tools should be deployed across all devices to detect and block malicious software. This includes protection against ransomware, viruses and other threats that can compromise your data and systems. Read more about how ransomware affects UK businesses and how to protect against it.

5. Security update management

Software, operating systems and firmware should be kept up to date with the latest security patches. Under v3.3, businesses must be able to evidence that patching happens within 14 days of a security update being released — and failure to demonstrate this now results in an immediate assessment failure rather than an opportunity to remediate.

Cyber Essentials vs Cyber Essentials Plus: which level do you need?

The scheme has two levels, and understanding the difference is important before deciding which to pursue.

Cyber Essentials

The standard certification is a verified self-assessment. You complete a detailed questionnaire confirming that each of the five controls is in place across your organisation, and a certifying body reviews your responses. It is the right starting point for the vast majority of UK businesses — practical, achievable, and sufficient for most commercial requirements.

Cyber Essentials Plus

Cyber Essentials Plus covers the same five controls, but the assessment is carried out by a qualified external auditor who independently tests your systems rather than relying on self-declaration. It provides a higher level of assurance and is increasingly required for: central government and Ministry of Defence contracts, NHS supply chain work, and organisations where clients, regulators or insurers require independently verified security standards.

Many businesses start with Cyber Essentials and progress to Plus as their client base grows or their sector requirements evolve. The two certifications build on each other rather than being competing alternatives.

What changed in the April 2026 update?

The v3.3 update is the most consequential tightening of the Cyber Essentials standard in recent years. The five controls themselves have not changed, but several requirements have become significantly stricter.

  • MFA is now mandatory for all cloud services: Where any cloud service offers MFA, it must be enabled. Partial implementation — for example, only applying MFA to admin accounts while leaving standard user accounts unprotected — is no longer sufficient for certification.
  • Cloud service scope has expanded: Any cloud service that stores or processes your business data is now in scope for the assessment. Businesses that previously excluded cloud services from their certification boundary will need to review this.
  • Patch management is stricter: Security updates must be applied within 14 days of release. Under the previous standard, assessors could allow time to remediate. Under v3.3, failure to evidence timely patching results in an immediate assessment failure.
  • Application development section renamed: The section previously called “Web Applications” has been renamed to “Application Development” and now references the UK Government’s Software Security Code of Practice. For most businesses using off-the-shelf software, this change is unlikely to have significant practical impact.

For businesses approaching renewal, the practical implication is clear: review your MFA coverage across all cloud services and confirm your patching processes are documented and able to be evidenced before beginning the assessment.

Does your business need Cyber Essentials?

Cyber Essentials is not currently mandatory for all UK businesses — but the situations in which it is either required or strongly expected are expanding rapidly.

It is mandatory if:

  • You bid for UK central government contracts involving the handling of personal or sensitive data (a requirement in place since 2014) ·
  • You supply to organisations — particularly in the public sector — that require certification as a condition of their own supply chain compliance

It is increasingly expected if:

  • You work with enterprise clients who are tightening their supplier due diligence requirements
  • You are applying for cyber insurance — many insurers now require certification as a condition of cover, or offer meaningfully better premiums to certified businesses
  • You operate in a regulated sector: legal, financial services, healthcare and fintech clients and investors are increasingly asking for evidence of certification as part of procurement and due diligence processes

It is strongly recommended if:

  • Your business holds customer data, processes payments, or relies on IT systems to operate — which describes the vast majority of UK SMEs
  • You want a recognised, structured baseline for your cyber security that goes beyond informal good intentions
  • You are building toward more advanced security frameworks such as ISO 27001, where Cyber Essentials provides a solid foundation

The benefits beyond the badge

Cyber Essentials is sometimes viewed as a compliance exercise — something you do because a client asked for it. In practice, the benefits extend well beyond the certificate itself.

  • Closes the most common attack vectors: The five controls directly address the vulnerabilities exploited in the majority of opportunistic attacks. Certification is the evidence; the controls themselves are the protection.
  • Builds client and partner confidence: The Cyber Essentials badge is increasingly recognisable. Displaying it signals to clients, suppliers and partners that your business takes security seriously — without them needing to ask.
  • Supports insurance applications: Certified businesses are in a stronger position when applying for cyber insurance, and may qualify for lower premiums or broader coverage.
  • Opens government and public sector opportunities: Certification is a prerequisite for many public sector tenders and NHS framework contracts.
  • Provides a foundation for growth: Many businesses use Cyber Essentials as the starting point for a broader security strategy, building toward Cyber Essentials Plus, ISO 27001, or sector-specific compliance frameworks as their needs evolve. Find out more about Swiftcomm’s wider cyber security services.

Next steps

Cyber Essentials is one of the most practical and achievable steps a UK business can take to improve its security posture — and with the v3.3 update now in effect, the standard is more rigorous and more credible than ever.

Whether you’re considering certification for the first time, approaching renewal under the new standard, or looking to move from Cyber Essentials to Plus, the right preparation makes the process significantly smoother.

Ready to get certified, or want to understand where your business currently stands? Find out more about how Swiftcomm supports businesses through Cyber Essentials certification — including fully managed options and guaranteed certification. Explore our Cyber Essentials service today.

More from Swiftcomm

Managed IT Support vs In-House IT: What’s Right for a Growing UK Business?
When your business is growing, the question of whether to hire in-house IT staff or outsource to a managed IT provider is one of the most important decisions you'll face. Both options have genuine merit — and for some businesses, a hybrid of the two makes the most sense. In this guide, we break down all three models honestly, covering the trade-offs, cost considerations, and the five questions to ask before you decide.
Full Article
right-chevron
What is Ransomware and How Can UK Businesses Protect Against It?
In this guide, we’ll cover exactly what ransomware is, how it gets into a business, what happens during an attack, and — most importantly — the practical steps you can take to protect against it.
Full Article
right-chevron
grey-tick-icon
Trusted by 100s of businesses already
grey-tick-icon
Uniquely tailored approach
grey-tick-icon
Outstanding customer service
swift-tag

Talk with us

We pride ourselves on being an honest trustworthy business communications provider
phone-icon
Telephone
Call 03333 200 222 or if you would prefer us to call you.
Schedule a call
email-icon
Email
We love emails, to send us one use info@swiftcomm.co.uk or fill in our
Contact Form
chat-icon
Live Chat
Got a question? Our live chat is open and ready to assist
Chat Now
Contact a specialist
crosschevron-down