Hatch resource banner image for How to apply for Cyber Essentials certification

How to apply for Cyber Essentials certification

Getting Cyber Essentials certified shows customers and partners you're serious about cyber security and is a key step to winning public sector contracts.

First, what is Cyber Essentials?

To get your business certified, you must implement five basic security controls and then complete a self-assessment questionnaire through an official certification body. The Cyber Essentials scheme is government-backed, designed to help you protect your organisation against a wide range of the most common cyber attacks. Completing it is essential if you plan to bid for UK government contracts and provides a clear signal to your customers that you take security seriously.

The Two Levels: Cyber Essentials vs. Cyber Essentials Plus

There are two levels of certification. For most small businesses, the standard Cyber Essentials is the perfect starting point. Cyber Essentials Plus includes a hands-on technical audit and is more suitable for businesses that need to demonstrate a higher level of security assurance.

FeatureCyber EssentialsCyber Essentials PlusAssessment TypeOnline Self-Assessment Questionnaire (SAQ)SAQ + Hands-on technical audit by an external assessorEffortLower - you verify your own controlsHigher - includes vulnerability scans and testsCostLower (from around £300 + VAT)Higher (costs vary significantly based on business size)Best ForStartups, SMEs, and any business new to security certificationBusinesses handling more sensitive data or needing to meet specific contractual requirements

The Five Core Security Controls Explained

The entire scheme is built around protecting your business in five key areas. You must have measures in place for all of them before you can pass the assessment.

  1. Firewalls: This is about creating a secure barrier between your internal network and the internet. This includes the firewall provided by your internet router and personal firewalls on your computers.
  2. Secure Configuration: When you get new computers, software, or network equipment, they often come with insecure default settings. This control ensures you change default passwords and remove or disable any unnecessary software and user accounts.
  3. User Access Control: Your staff should only have access to the software and data they need to do their jobs. This principle of 'least privilege' minimises the damage an attacker can do if they compromise a user's account.
  4. Malware Protection: This means protecting all your computers and devices from viruses and other malicious software. You can achieve this by using approved anti-malware software and ensuring it is always kept up to date.
  5. Security Update Management: Software and apps always have vulnerabilities discovered over time. This control ensures you apply the latest security updates (or 'patches') to all your software and devices within 14 days of release to fix any known security holes.

Your Step-by-Step Guide to Certification

The process is managed not by the government directly, but by a single partner, the IASME Consortium, and its network of accredited Certification Bodies.

  1. Prepare Your Organisation: Before you even apply, use the free Cyber Essentials Readiness Tool on the IASME website. This will ask you a series of questions to help you gauge if you have the necessary controls in place.
  2. Choose a Certification Body: You need to apply via an official Certification Body. You can find a list of them on the IASME website. They will provide you with access to the online self-assessment portal.
  3. Complete the Self-Assessment Questionnaire (SAQ): This is the core of the application. You will be asked a series of questions about the five controls. You must answer truthfully, confirming that the controls are implemented across all devices and software in scope.
  4. Submit and Await Your Certificate: Once you submit your SAQ, the Certification Body will review your answers. If everything is in order, you will be awarded your Cyber Essentials certificate, which is valid for 12 months. If you fail, you typically have a grace period to fix the issues and resubmit.
A Final Tip: Don't treat this as just a box-ticking exercise. The real value of Cyber Essentials is not the certificate itself, but the process of genuinely improving your security. By implementing these five controls properly, you will make your business a much harder target for cyber criminals.

Created by hatch. • Updated on April 27, 2026