If you’ve been hearing more about Cyber Essentials recently, there’s a good reason for it. What was once considered a useful but optional certification for UK businesses is increasingly becoming an expectation — from cyber insurers, enterprise clients, public sector procurement teams, and regulated sectors across the board.
According to the UK government's own Cyber Security Breaches Survey 2025/2026, 43% of UK businesses experienced a cyber security breach or attack in the last 12 months — equivalent to over 600,000 businesses across the country.
In this guide we’ll explain what Cyber Essentials actually is, what the two certification levels involve, what changed in the 2026 update, and how to decide whether your business needs it.
Cyber Essentials is a UK government-backed certification scheme, managed by IASME on behalf of the National Cyber Security Centre (NCSC). It's designed to help businesses of all sizes protect themselves against the most common internet-based cyber attacks.
The scheme is built around five core technical controls. When properly implemented, these controls block around 80% of common cyber attacks — not because they are sophisticated, but because they address the vulnerabilities that the vast majority of opportunistic attackers exploit.
Think of it less as an exam and more as a recognised standard of proof. The certification doesn’t tell you anything your IT team wouldn’t recommend anyway — it gives you the independently recognised evidence that you’ve actually done it. The certificate is valid for 12 months and must be renewed annually to remain valid.
The five technical controls that underpin Cyber Essentials haven’t changed in the 2026 update. What has changed is how rigorously some of them are assessed — particularly around cloud services and authentication.
A correctly configured firewall controls the traffic that can enter and leave your network, blocking unauthorised access while allowing legitimate communications. Under Cyber Essentials, all internet-connected devices must be protected by a properly configured firewall or equivalent boundary control.
Devices and software should be configured securely from the outset — default passwords changed, unnecessary software removed, and settings reviewed to minimise vulnerabilities. Many successful attacks exploit default or poorly configured systems that businesses have simply never revisited.
Access to systems and data should be limited to those who genuinely need it, with strong authentication in place. Under the updated v3.3 standard, multi-factor authentication (MFA) is now required for all cloud services where it is available — not just admin accounts. Read more about what MFA is and why it matters.
Anti-malware tools should be deployed across all devices to detect and block malicious software. This includes protection against ransomware, viruses and other threats that can compromise your data and systems. Read more about how ransomware affects UK businesses and how to protect against it.
Software, operating systems and firmware should be kept up to date with the latest security patches. Under v3.3, businesses must be able to evidence that patching happens within 14 days of a security update being released — and failure to demonstrate this now results in an immediate assessment failure rather than an opportunity to remediate.
The scheme has two levels, and understanding the difference is important before deciding which to pursue.
The standard certification is a verified self-assessment. You complete a detailed questionnaire confirming that each of the five controls is in place across your organisation, and a certifying body reviews your responses. It is the right starting point for the vast majority of UK businesses — practical, achievable, and sufficient for most commercial requirements.
Cyber Essentials Plus covers the same five controls, but the assessment is carried out by a qualified external auditor who independently tests your systems rather than relying on self-declaration. It provides a higher level of assurance and is increasingly required for: central government and Ministry of Defence contracts, NHS supply chain work, and organisations where clients, regulators or insurers require independently verified security standards.
Many businesses start with Cyber Essentials and progress to Plus as their client base grows or their sector requirements evolve. The two certifications build on each other rather than being competing alternatives.
The v3.3 update is the most consequential tightening of the Cyber Essentials standard in recent years. The five controls themselves have not changed, but several requirements have become significantly stricter.
For businesses approaching renewal, the practical implication is clear: review your MFA coverage across all cloud services and confirm your patching processes are documented and able to be evidenced before beginning the assessment.
Cyber Essentials is not currently mandatory for all UK businesses — but the situations in which it is either required or strongly expected are expanding rapidly.
Cyber Essentials is sometimes viewed as a compliance exercise — something you do because a client asked for it. In practice, the benefits extend well beyond the certificate itself.
Cyber Essentials is one of the most practical and achievable steps a UK business can take to improve its security posture — and with the v3.3 update now in effect, the standard is more rigorous and more credible than ever.
Whether you’re considering certification for the first time, approaching renewal under the new standard, or looking to move from Cyber Essentials to Plus, the right preparation makes the process significantly smoother.
Ready to get certified, or want to understand where your business currently stands? Find out more about how Swiftcomm supports businesses through Cyber Essentials certification — including fully managed options and guaranteed certification. Explore our Cyber Essentials service today.