Cyber Essentials Requirements UK 2026: What You Must Do to Get Certified
25 August 2026
Everything you need to know about Cyber Essentials requirements in 2026: five controls, certification process, costs, who needs it, and how to pass.
What Are Cyber Essentials Requirements? A UK Overview
Cyber Essentials is a UK Government-backed certification scheme, developed by the National Cyber Security Centre (NCSC) and governed by IASME. It sets out the minimum cybersecurity controls that every organisation should have in place to protect itself from common internet-borne threats. The requirements are designed to be practical and cost-effective, focusing on five core technical areas rather than complex security policies. For UK businesses, Cyber Essentials is not just a badge: it's a prerequisite for many central government contracts and increasingly expected by local authorities and private-sector supply chains. The scheme gives customers and partners confidence that your organisation has implemented basic cyber hygiene. In 2026, the underlying requirements remain aligned with the NCSC's risk management framework, but the assessment process, self-declaration integrity checks, and certification bodies have been refined to reduce fraud and improve trust, especially for remote and hybrid working environments.
The Five Technical Controls You Must Implement
To pass Cyber Essentials, you must fully implement five technical controls. First, boundary firewalls and internet gateways: your network must be protected by a firewall, with inbound and outbound connections restricted to those needed for business. Second, secure configuration: you must change default passwords, remove or disable unused software and user accounts, and ensure devices are hardened before deployment. Third, user access control: each user should have their own account, with the principle of least privilege applied; administrator accounts must be separated from day-to-day accounts and only used when required. Fourth, malware protection: you need to install and maintain anti-malware solutions on all devices, including desktops, laptops, and servers, and prevent users from disabling it. Fifth, patch management: all software and operating systems must be kept up to date, with critical security patches applied within 14 days. These five controls are the non-negotiable baseline for certification.
Scope, Eligibility, and Who Needs Cyber Essentials in 2026
Cyber Essentials requirements apply to any organisation that processes or stores personal data over the internet, regardless of size or sector. The scope includes all devices, including company laptops, desktops, tablets, and smartphones, as well as servers and cloud services used to access company data or email. Mobile devices used solely for making calls and sending SMS texts are generally outside scope, but any device that accesses business data or email is in scope, including employee-owned BYOD devices. The scheme is especially relevant if you bid for UK government contracts requiring Cyber Essentials as part of the procurement process. For larger organisations or those handling more sensitive data, Cyber Essentials Plus involves independent external testing of your implementation. In 2026, even small businesses are seeing customers request certification, as cyber liability insurers increasingly offer discounted premiums to certified companies. If you outsource IT, you are still responsible for ensuring your suppliers' systems meet the requirements.
How to Get Certified: Process, Timeline, and Costs in the UK
To become Cyber Essentials certified, you work with an accredited certification body rather than going directly to IASME. As of 2026, you can choose from over 60 IASME-approved certification bodies in the UK. The process starts with completing the self-assessment questionnaire (SAQ) which covers your security settings, asset inventory, and how your five controls are configured. You then submit your SAQ to the certification body, who will review it, verify your answers against evidence, and may conduct a vulnerability scan of your public-facing IP addresses. Once passed, you receive a certificate valid for 12 months. The timeline is typically two to four weeks, depending on how quickly you can gather asset data and answer the questions. Certification body fees range from £300 to £800 for the basic Cyber Essentials, depending on your organisation's size and complexity. Cyber Essentials Plus, which adds hands-on technical audits and simulated phishing, typically costs between £1,800 and £3,500.
Common Pitfalls and How to Pass the First Time
Many first-time applicants fail Cyber Essentials due to avoidable mistakes. The most common pitfall is an incomplete asset inventory: if you forget a cloud application, a satellite office router, or a personal device used for work, your assessment will be rejected. Another frequent issue is using the same default administrator password for all devices or failing to enable multi-factor authentication on internet-facing systems. Patching is also a recurring problem; you need to document your patching process and show evidence that critical updates are installed within 14 days. Beware of legacy systems that can no longer be patched, as they must be isolated from the network. To pass first time, map every device and user account before you start, secure configuration on all new devices, and ensure that your antivirus definitions are up to date. Work closely with your certification body if you have questions, and consider using IASME's own readiness guides.
FAQ
The five mandatory controls are: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management. You must show that each control is fully implemented across all in-scope devices and services. The controls are defined by the NCSC and assessed via the Cyber Essentials self-assessment questionnaire.