Getting Cyber Essentials certified in the UK takes most SMEs between two and eight weeks, depending on how ready your IT environment is when you start. The process is a self-assessment against five technical controls, submitted through an IASME certification body, followed by a review. Certification lasts 12 months and needs annual renewal. Costs start at £320 plus VAT for a micro business and cap at £600 plus VAT for larger organisations.

This guide walks you through the six-step process, the timings that catch businesses out, the 2026 v3.3 changes you now need to meet, and the common reasons SMEs fail the first submission.

What Cyber Essentials is and how the certification works

Cyber Essentials is a UK government-backed certification scheme run by the National Cyber Security Centre (NCSC) and delivered by IASME. It shows that your business has put in place five basic technical controls that block the most common cyber attacks.

The five controls are firewalls, secure configuration, user access control, malware protection, and security update management. You submit evidence via a self-assessment questionnaire. An IASME certification body scores your answers, gives feedback if anything falls short, and issues the certificate when you pass.

Cyber Essentials Plus adds an independent technical audit on top of the self-assessment. Same five controls, external verification. Most UK SMEs start with the basic Cyber Essentials and add Plus only when a specific contract or insurer requires it.

How long does Cyber Essentials take to get?

Two to eight weeks is the honest range. Where you land on that scale depends on how much cleanup your environment needs before you can honestly answer the questionnaire.

A business already running Microsoft 365 with MFA enforced, endpoint protection deployed, and a documented patching cadence can usually complete the self-assessment in a week and be certified within another week of submission. A business that needs to introduce MFA, deploy endpoint protection, and clean up admin accounts before submitting is typically looking at four to eight weeks of preparation, then one to two weeks for the review.

How long does Cyber Essentials last?

Twelve months, exactly. IASME issues the certificate on the day you pass, and it expires on the same date the following year. Cyber Essentials Plus follows the same 12-month cycle.

We do not apply discounts to renewals. You pay the full IASME assessment fee each year, and re-run the self-assessment against the current version of the requirements. If v3.3 was in force when you certified but v3.4 has landed by renewal, you assess against v3.4. Plan renewal 60 to 90 days before expiry to avoid a gap on the IASME public register, which procurement teams increasingly check.

Getting the scope right (the decision that saves rework)

Scope is the boundary you draw around what the certification covers. Get it right and the process is smoother. Get it wrong and the assessor will ask you to redo the entire submission.

Whole-organisation scope is the default. Every user, every device, every cloud service that touches business data is in scope. This is the strongest signal to procurement teams and cyber insurers, and it is usually the sensible choice for UK SMEs under 250 users.

A defined sub-scope is possible where a larger business wants to certify one part of the operation, or where a specific isolated environment (a lab, a client-facing platform) needs its own certification. The trade-off is that the scope boundary must be genuinely isolated, and the certificate only speaks to what is inside it. Enterprise customers usually read sub-scoped certificates carefully.

The six-step process for UK SMEs

Step 1: Define your scope

Decide what part of your business the certification covers. Whole organisation is the default and the strongest signal. A defined sub-scope is possible for larger businesses that want to certify one division first. Get this wrong and the assessor will send it back.

Step 2: Fix the five controls

Before you touch the questionnaire, work through the five technical controls against your live environment.

  • Firewalls on every internet-facing device
  • Secure default configurations, especially on new laptops
  • MFA on all cloud services and admin accounts
  • Endpoint protection deployed and current
  • Security updates applied within the required window (five working days for high-severity vulnerabilities under v3.3)

Step 3: Complete the self-assessment questionnaire

The questionnaire runs to around 70 questions. It is not a tick-box exercise. Assessors read your answers and score them against the current requirements document.

The v3.3 requirements are published by NCSC in April 2026 and cover authentication, patching windows, cloud services, and mobile device management. Answer honestly. Vague or contradictory answers get flagged.

Step 4: Submit through an IASME certification body

You submit the questionnaire and payment through an IASME-accredited certification body. Unite is one of these where you would like a partner to walk the assessment with you, but any certification body will do. Reviews are typically returned within one to two working days for micro and small businesses.

Step 5: Handle assessor feedback

Most SMEs get some feedback on the first submission. Common asks: clarify a specific answer, provide evidence for a control, or fix something before re-scoring. You have 30 days from submission to resolve the feedback. Miss the window and you re-submit and re-pay.

Step 6: Plan for renewal

As soon as you pass, add a calendar reminder for 60 days before expiry. Renewal is not a formality if the requirements have moved on. Businesses that treat renewal as an annual health check rather than a rubber stamp keep the certification current without last-minute scrambles.

Cyber Essentials vs Cyber Essentials Plus

Basic Cyber Essentials is a self-assessment. You answer the questionnaire, the certification body scores it, and if it passes you are certified. There is no independent verification of your answers.

Cyber Essentials Plus adds an on-site or remote technical audit. An assessor connects to a sample of your devices and cloud services, runs vulnerability scans, tests MFA enforcement, and verifies that what you claimed on the questionnaire matches reality. The same five controls are checked, but the assessor sees the evidence directly.

For most UK SMEs, basic Cyber Essentials is the right starting point. Move to Plus when a specific contract requires it, when your cyber insurer offers a meaningful premium discount for it, or when you have already been certified basic for two or three cycles and want the stronger assurance signal for enterprise customers.

The cost of Cyber Essentials in 2026

Basic Cyber Essentials pricing is banded by organisation size:

  • Micro (0 to 9 employees): £320 plus VAT
  • Small (10 to 49 employees): £440 plus VAT
  • Medium (50 to 249 employees): £520 plus VAT
  • Large (250+ employees): £600 plus VAT

Cyber Essentials Plus adds an independent audit and typically runs £1,500 to £3,000 plus VAT depending on the size and complexity of your environment. Both fees are paid in full at renewal each year.

Budget for two additional line items that catch businesses out: any technology upgrades needed to meet the controls (endpoint protection licences, MFA setup time, mobile device management) and the internal or partner time to run the self-assessment properly, which is usually one to three working days of focused effort.

What changed in v3.3 in April 2026

The NCSC released Cyber Essentials Requirements v3.3 in April 2026. The tightest change for SMEs is the five-working-day fix window for high-severity vulnerabilities. Passwordless authentication (passkeys and biometric) is now accepted alongside MFA, which brings NCSC alignment with mainstream cloud identity practice. AI and LLM tools are formally in scope as cloud services, and the mobile device management requirements are clarified.

Our v3.3 changes piece walks through the technical detail. This guide focuses on the process side of certification, which has not changed.

Common reasons UK SMEs fail Cyber Essentials on the first attempt

  • MFA gaps on admin accounts. All admin accounts must have MFA. The most common failure is a forgotten service account or a break-glass account left with password-only.
  • Patching outside the required window. High-severity vulnerabilities must be fixed within five working days. Businesses without a documented patching cadence usually cannot show this evidence when asked.
  • Unsupported operating systems in scope. A Windows Server or Windows 10 machine past end-of-support inside the scope will fail. Either remove it from scope, retire it, or complete migration before submitting.
  • Weak cloud service configuration. Cloud tenants with unrestricted external sharing, no conditional access, and no MFA on cloud admin accounts fail the cloud services section.
  • Vague or defensive answers. Assessors are experienced. “We handle this” without specifics gets flagged. Give concrete evidence, including tool names and configuration details.

A prep checklist for UK SMEs

Run through this list before you open the questionnaire. If you cannot honestly tick every item, resolve it first.

  • MFA enforced on every user and admin account, including cloud services
  • Endpoint protection deployed and updating on every device in scope
  • A patching schedule that hits the five-working-day window for high-severity issues
  • No unsupported operating systems in the scope boundary
  • Cloud tenant with conditional access, restricted external sharing, and MFA on all admins
  • A documented list of devices, users and cloud services in scope
  • An accurate asset register you can cross-check against the questionnaire answers

Get a Cyber Essentials readiness review

If you would like a second pair of eyes on your setup before you submit, get in touch and we will walk through your scope, the five controls against your live environment, and where the likely feedback will come from. Most UK SMEs pass first time when they complete a proper readiness check.