Cyber Security · Liugo Insights

Does My Small Business Need Cyber Essentials? A Practical UK Guide for 2026

A calm, practical guide for UK small businesses: when Cyber Essentials matters, what it checks, what it costs and how to prepare without turning security into an enterprise project.

Liugo Insights12 min read
Small business directors reviewing cyber security controls on a laptop in a modern office

Short answer: most UK small businesses are not legally required to have Cyber Essentials.

But if your business handles customer data, relies on Microsoft 365 or other cloud services, works in a supply chain, bids for contracts, or simply wants a sensible cyber security baseline, it is increasingly worth serious consideration. For some contracts, it can be a requirement rather than a choice.

Cyber security has a habit of sounding terribly complicated when, for most small businesses, the important questions are actually rather simple.

Are your devices secure? Are they up to date? Are the right people able to access the right things? And if someone tries the digital equivalent of the front door, have you remembered to lock it?

That, in essence, is what Cyber Essentials is designed to address.

What is Cyber Essentials?

Cyber Essentials is a UK Government-backed cyber security certification scheme, overseen by the National Cyber Security Centre (NCSC).

It was created to help organisations protect themselves against some of the most common cyber attacks without expecting every small business to employ a security team or become an expert in cyber security.

Firewalls

Protecting the boundary between your systems and the internet, so access is controlled rather than simply exposed.

Secure configuration

Making sure devices and software are configured safely, with unnecessary services, accounts and privileges removed.

Security update management

Keeping operating systems, applications, routers, firewalls and other software supported and properly patched.

User access control

Ensuring people have individual accounts and only the access they genuinely need for their role.

Malware protection

Reducing the risk posed by viruses, malicious software and other threats before they can become an incident.

These are not particularly exotic security measures. That is rather the point. Cyber Essentials is about getting the fundamentals right consistently.

Does a small business really need Cyber Essentials?

For many businesses, need is perhaps the wrong first question.

A better question is: would we be comfortable explaining our current cyber security arrangements to an important customer, insurer or prospective business partner?

If the answer is uncertain, Cyber Essentials is a useful place to start.

According to the UK Government's Cyber Security Breaches Survey 2025/2026, 46% of small businesses reported identifying a cyber security breach or attack during the previous 12 months. Among micro businesses the figure was 42%.

That does not mean almost half of small businesses suffered a catastrophic breach. The survey includes a broad range of attacks and attempted attacks. But it makes one point rather clearly: being small does not make a company invisible to cyber criminals.

Automated attacks do not particularly care whether you employ five people or five thousand. If an exposed account, outdated laptop or poorly secured remote-access service can be found, it can be targeted.

So, do I actually have to have Cyber Essentials?

Usually, no.

There is no general rule saying that every private company in the UK must hold Cyber Essentials certification.

However, there are circumstances where certification can become commercially important or contractually required. Certain UK public-sector contracts require suppliers to demonstrate appropriate Cyber Essentials controls, particularly where the contract involves personal information, government information or certain technology services.

Outside government, an increasing number of larger organisations also use Cyber Essentials as part of their supplier security requirements. That means a business can suddenly encounter a request to provide a current Cyber Essentials certificate — and that tends to be an inconvenient moment to begin wondering what Cyber Essentials is.

When is Cyber Essentials particularly worthwhile?

For a small business, we would give it serious consideration if any of the following sound familiar.

  • You rely heavily on Microsoft 365, SharePoint, OneDrive, Teams or other cloud platforms.
  • Your staff work from home or use laptops outside the office.
  • You hold personal, financial, commercial or customer information.
  • You have several employees accessing shared systems.
  • You work with larger organisations that carry out supplier security checks.
  • You intend to bid for public-sector or larger commercial contracts.
  • You have customers asking about MFA, encryption, patching, cyber insurance or security policies.
  • You simply do not know, with any confidence, whether the basics are already being managed properly.

In that last case, the certification itself is almost secondary. The preparation exercise can be valuable because it forces someone to answer questions that are very easy to ignore during the normal rush of running a business.

What does Cyber Essentials actually check?

There is a common misconception that Cyber Essentials involves buying an expensive security product. It does not. The scheme is mainly concerned with how the technology you already use is configured and managed.

1. Firewalls

Your business should have suitable protection between internal devices and untrusted networks such as the internet. For a traditional office this may include a business firewall or router. For cloud-based environments, responsibility may be divided between your organisation and the cloud provider.

The important point is that access is controlled rather than simply exposed.

2. Secure configuration

New computers and software often arrive configured for convenience rather than maximum security. Unnecessary applications, services, accounts and administrative privileges create additional ways into a system.

Secure configuration is largely about removing what is not required and properly configuring what remains.

3. Security updates

Supported software must be kept updated. Under the current Cyber Essentials requirements, relevant high-risk or critical vulnerability fixes generally need to be applied within 14 days of release.

Unsupported software presents an obvious difficulty because, once a vendor stops fixing vulnerabilities, there may be nothing sensible left to install when the next security problem appears. This is one reason ageing PCs and forgotten applications so often surface during Cyber Essentials preparation.

4. User access control

Not everybody needs to be an administrator. Indeed, most people should not be. Employees should have individual accounts, appropriate permissions and access only to the systems required for their role.

Administrator access should be treated rather differently from an everyday user account. This is also where properly configured authentication and multi-factor authentication become particularly important.

5. Malware protection

Devices must have appropriate protection against malicious software. Depending on the environment, this can involve anti-malware technology, application controls and other supported approaches.

Again, the principle is not particularly glamorous. It is simply much better to stop malicious software before it becomes an incident.

What about Microsoft 365? Isn't Microsoft securing everything already?

Microsoft secures Microsoft's infrastructure.

Your business is still responsible for a considerable part of how your Microsoft 365 environment is used. That distinction matters.

Microsoft can operate a highly secure cloud platform while your organisation simultaneously has:

  • weak user accounts
  • unnecessary administrator permissions
  • poorly configured MFA
  • old laptops
  • unmanaged devices
  • former employees who still have access
  • outdated third-party applications
  • unsafe sharing practices

Cyber Essentials therefore includes cloud services within its scope and uses a shared-responsibility approach depending on the type of cloud service involved. Moving something to the cloud does not transfer every security responsibility to the cloud provider.

If Microsoft 365 is central to your business, our Microsoft 365 service focuses on exactly these practical areas: identity, MFA, devices, permissions, sharing and secure day-to-day management.

Cyber Essentials vs Cyber Essentials Plus – what is the difference?

This causes rather more confusion than it ought to.

Both certifications are based on the same five technical controls. The difference is how those controls are verified.

Cyber Essentials

Independently assessed self-assessment

Your organisation answers detailed questions about its systems and security controls. A suitably senior person signs off the answers, and an independent assessor reviews the submission.

Cyber Essentials Plus

Technical testing and audit

After achieving Cyber Essentials, a technical audit tests whether the required controls are genuinely working across a representative sample of devices and relevant internet-facing systems.

In simple terms: Cyber Essentials asks you to demonstrate that the controls are in place. Cyber Essentials Plus technically tests them.

For businesses dealing with more demanding customers, contracts or supply chains, the additional assurance of Plus can be valuable.

How much does Cyber Essentials cost in 2026?

The official Cyber Essentials assessment fee is based on the number of employees in the organisation.

Organisation sizeEmployeesCyber Essentials assessment
Micro0–9£320 + VAT
Small10–49£440 + VAT
Medium50–249£500 + VAT
Large250+£600 + VAT

Cyber Essentials Plus is priced separately because the cost depends on the size and complexity of the environment being audited.

There is, however, an important distinction between the certification fee and the cost of becoming ready for certification.

If everything is already properly managed, preparation may be relatively straightforward. If the review uncovers unsupported computers, old software, unmanaged personal devices, excessive administrator permissions or poorly configured Microsoft 365 accounts, those issues will need dealing with.

In our view, that should not be seen as money being spent merely to pass an assessment. Those are precisely the weaknesses you would want to discover anyway.

How difficult is Cyber Essentials for a small business?

For a well-managed small business, it should not be frightening. But it does require somebody to understand the environment properly.

You need to know what devices are in use, which operating systems and applications they run, how users authenticate, which cloud services are used, what internet-facing equipment exists and whether software remains supported and updated.

This is where businesses sometimes discover that their IT environment is not quite as simple as everybody thought. There may be an old laptop in a cupboard. A director may use a personal computer at home. A former employee's account might still exist. Perhaps a router was installed five years ago and nobody remembers the login. Or several employees may quietly have administrator privileges because it once made installing a printer easier.

None of these is terribly unusual. Cyber Essentials simply has a habit of bringing them into the daylight.

How long does Cyber Essentials certification last?

A Cyber Essentials certificate is valid for 12 months from the date of issue.

Certification should therefore be thought of as an annual health check rather than a one-off badge. Technology changes. People join and leave. Computers are replaced. New software appears. Security standards evolve.

A company that was secure two years ago is not automatically secure today.

Does Cyber Essentials mean my business cannot be hacked?

No. And any company suggesting otherwise should be treated with a little caution.

Cyber Essentials establishes a strong baseline against common cyber threats. It does not certify that a business is immune from every possible cyber attack. That is not a weakness in the scheme.

A proper front-door lock does not make a building impossible to burgle either. It simply removes a very obvious route inside. Good cyber security works in much the same way: remove the easy opportunities first, then build additional protection according to the risks faced by the business.

Is there any other benefit to becoming certified?

Apart from improving security, certification can help demonstrate to customers and suppliers that your organisation takes cyber security seriously. It can also make supplier questionnaires and tender responses rather easier because you have recognised evidence that a baseline standard has been independently assessed.

There is another useful benefit for eligible businesses. According to the NCSC, UK organisations with turnover below £20 million that achieve certification covering their whole organisation are automatically entitled to cyber liability insurance arranged through IASME, subject to the scheme's applicable terms and eligibility conditions.

For many small businesses, that makes the overall proposition considerably more interesting than merely acquiring another certificate for the wall.

Is Cyber Essentials worth it for a five or ten-person company?

Quite possibly.

In fact, very small companies can have more reason to establish a sensible baseline because they usually do not have an internal security team watching over everything.

The Government's latest survey found that the proportion of micro businesses using an external cyber security provider increased from 39% to 44%, while small businesses were also considerably more likely than micro businesses to seek outside IT or cyber security advice.

That reflects reality rather well. A ten-person construction company, accountancy practice or engineering firm does not need its own cyber security department. It does need somebody making sure that the essentials are being done properly. There is quite a difference.

A sensible way to approach Cyber Essentials

Do not begin by buying the certificate. Begin by understanding the environment.

  • What devices does the business actually use?
  • Are all operating systems and applications supported?
  • Are security updates being managed?
  • Does everybody have MFA where required?
  • Who has administrator access, and why?
  • Are former employees and unused accounts removed?
  • Are home-working and personally owned devices understood?
  • Are firewalls, routers and internet-facing services properly configured?
  • Can somebody explain, clearly, how the company's Microsoft 365 environment is protected?

Once those questions have proper answers, the certification exercise becomes much more straightforward. More importantly, you will understand the security of the business rather than merely possessing a certificate.

Frequently asked questions

Do I need Cyber Essentials if I only use Microsoft 365?

You may still benefit from it. Microsoft protects the underlying Microsoft 365 platform, but your organisation remains responsible for areas such as user access, account security, configuration, devices and parts of the shared security model.

Is Cyber Essentials mandatory for UK small businesses?

Not generally. However, it is required for certain government contracts and can also be required by customers or supply-chain partners.

How much does Cyber Essentials cost for a small business?

For a UK business with 10–49 employees, the official Cyber Essentials assessment currently costs £440 + VAT. For a micro business with 0–9 employees, it is £320 + VAT. Preparation or remediation work is separate.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both use the same five technical controls. Cyber Essentials is an independently verified assessment, while Cyber Essentials Plus adds a technical audit that tests the controls in practice.

How long does Cyber Essentials last?

Certification is valid for 12 months and should be renewed annually.

Can I do Cyber Essentials myself?

Yes. The scheme is deliberately accessible and the assessment questions are available for businesses to review in advance. The more difficult part is often ensuring the answers accurately reflect the company’s devices, users, networks and cloud services.

Will I need to replace old computers?

Possibly. If a device or operating system is no longer supported and cannot meet the Cyber Essentials requirements, it may need to be upgraded, replaced or appropriately removed from the certification scope.

Does Cyber Essentials protect us from every cyber attack?

No. It provides a practical baseline designed to reduce exposure to common attacks. It should be viewed as a foundation for good cyber security, not a guarantee against every possible threat.

The Liugo view

Cyber Essentials makes most sense when it is treated as an outcome of good IT management, rather than an annual paperwork exercise.

If your devices are supported, updates are managed, Microsoft 365 is properly configured, users have sensible permissions, MFA is in place and somebody knows exactly what technology the business is using, much of the hard work is already being done.

If those things are unclear, that is useful information too. You have found the gap before somebody else did.

At Liugo, we help small UK businesses review their existing IT environment, identify gaps against Cyber Essentials requirements and put the technical foundations in place before independent certification.

We position this as Cyber Essentials Readiness: practical review and remediation, not a claim that Liugo itself issues the certificate.

No unnecessary enterprise complexity. No security theatre. Just practical improvements appropriate to the size of the business. If you are unsure whether your company is already close to Cyber Essentials — or whether certification would actually benefit you — start with a conversation rather than a purchase.

You can also see how this fits into our wider cyber security and backup approach for small businesses.

Official sources and further reading

Not sure how close your business is to Cyber Essentials?

Liugo can review your devices, Microsoft 365, user access, patching and network security, explain the gaps in plain English and help you prepare for independent certification.