
Do you need Cyber Essentials, managed cyber security, or both? For most UK businesses above roughly 20 users in 2026, the honest answer is both. Cyber Essentials confirms that your controls met the required standard when you were assessed. Managed cyber security keeps watch on those same controls every day and picks up what slips in the months between. There is a genuine exception: a business under 10 users with no cyber insurance, no regulated obligations and competent internal IT can reasonably hold certification on its own. Above 20 users that position has become rare, and the reason is what happens in the gap.
Cyber Essentials and managed cyber security do two separate jobs
Cyber Essentials is a UK government-backed certification scheme. The National Cyber Security Centre describes it as the minimum cyber security standard that the government recommends for organisations of all sizes. IASME oversees the scheme, while a network of accredited certification bodies delivers the assessments. It covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Assessment is a questionnaire scored by an accredited body. Cyber Essentials Plus adds an independent technical audit on top.
The certificate confirms one thing with precision: your controls met the standard when the certification body scored your questionnaire. It says nothing about whether a breach is in progress today, whether multi-factor authentication still works across every account this week, or whether someone quietly added an administrator in month four.
Managed cyber security answers the second set of questions. It is a continuous service, priced monthly per user, that watches the same controls certification measures once. Our Cyber Essentials certification service sits alongside it for exactly that reason.
The twelve-month gap where controls slip
Assessors check whether your organisation enforces MFA, keeps patches current, deploys endpoint protection and controls administrator accounts. Every one of those answers is true on assessment day. Each of them drifts.
MFA gets switched off. Enforced in month one. In month four someone disables it on a shared mailbox because it was slowing them down. The certificate still records that MFA was enforced.
Patching slips quietly. The scheme requires high-risk and critical updates inside 14 days. Managed patching measures the weekly compliance rate you achieved, and produces the evidence log an insurer asks to see.
Endpoint agents stop reporting. Certification confirms antivirus is deployed. Monitoring flags the laptop where the agent uninstalled itself six weeks ago.
Administrator accounts multiply. Certification audits admin access on the day. Monitoring alerts you when a new one appears without approval.
Certification measures your setup once a year. Managed cyber security measures it every hour. Both numbers matter to an insurer, and they measure different things.
What Cyber Essentials and managed cyber security cost a 30-user business
Figures below exclude VAT and assume 30 users.
| Cyber Essentials | Cyber Essentials Plus | Managed EDR | Full managed security | |
| What it is | Annual certification | Certification plus independent technical audit | Continuous monitoring, 24/7 | Full stack plus incident response |
| Annual cost | £440 | £1,940 to £3,440 | £2,520 to £5,040 | £5,400 to £14,400 |
| Satisfies an insurer | Partly | Yes, for procurement clauses | Yes, for premium calculation | Yes, across the board |
| Catches an attack in progress | No | No | Yes | Yes |
Certification is the lowest-cost item on this list by a wide margin.
Plus costs several times basic certification because it includes an independent technical audit.
Priced per endpoint per month, and the cheapest layer to add first.
Priced per user per month, scaling with headcount.
For a 30-user business, a sensible middle position combines certification, managed detection and awareness training, and lands around £5,000 to £8,000 a year. That figure usually sits inside the managed IT budget the business already runs, which is why the two tend to arrive bundled.
For most businesses this size it sits inside the managed IT budget they already run.
Which of those columns fits you depends on three things: your user count, whether you operate in a regulated sector, and what your insurer asked for at your last renewal. Twenty minutes on the phone settles it faster than a quote does.
What changed in Cyber Essentials in April 2026
Two of these changes will fail an assessment outright, so they are worth knowing before you book one. IASME, who deliver the scheme, published the detail in full.
MFA is now mandatory wherever a cloud service offers it. Leaving available MFA switched off is an automatic assessment failure. For most SMEs, this is where the change has the biggest impact because it closes the gap between systems. For example, businesses may have enabled MFA for email while leaving finance systems or CRM platforms without the same protection.
The 14-day patch window is now an automatic failure. High-risk and critical updates must be applied within 14 days of release. Missing that window fails the assessment.
Passwordless methods now have formal recognition. For example, organisations can use passkeys, biometrics and hardware keys as stronger alternatives to traditional passwords. They sit alongside the MFA requirement above and do not replace it.
Scope rules tightened. Any internet-capable device falls within scope. In addition, the scheme defines cloud services as any on-demand, internet-accessible service running on shared infrastructure, which clearly brings mainstream productivity suites into scope. Finally, you must document any exclusions and identify the legal entities the certification covers.
Cyber Essentials Plus remediation now covers the whole estate. Fixing only the devices that were sampled is no longer sufficient.
Our full breakdown of the v3.3 changes covers how to pass first time, and how to get Cyber Essentials certified walks through the process.
Five layers in a UK SME security stack
A typical managed security service for a business of this size has five parts, usually delivered as one monthly per-user cost.
- A staffed security operations centre. Analysts watching endpoint and login activity overnight, at weekends and on bank holidays, which is when attacks are timed.
- Managed endpoint detection and response, or EDR. Instead of matching known virus signatures, it watches for suspicious behaviour, which is how ransomware gets stopped partway through.
- Identity monitoring. Watching Microsoft 365 sign-ins for the patterns that mean a stolen password: logins from two countries an hour apart, repeated MFA prompts designed to wear someone down, new mailbox forwarding rules.
- Security awareness training with realistic phishing simulations and completion tracking, run monthly.
- An incident response retainer. A defined process, named responders, a response time in writing and a playbook, all agreed before you need them.
Our review of Huntress covers one such platform in detail.
Sizing it to your business: under 10, 10 to 20, and above 20 users
Under 10 users: certification can stand alone
This works where all of the following hold. Fewer than 10 users. No regulated obligations, so no FCA, NHS, education or defence contracts. No cyber insurance in place. Competent internal IT present daily. And no enterprise clients asking for more than a certificate.
10 to 20 users: the judgement call
This is where the honest answer depends on the specifics. A 12-person accountancy practice holding client financial data sits differently from a 12-person design studio. Insurance, sector and client requirements decide it.
If you are in that range and unsure which side of the line you fall on, that conversation is worth having before your renewal date. Talk to us about a Cyber Essentials assessment and we will tell you plainly if certification on its own covers you.
Above 20 users: both, in almost every case
Certification proves your controls exist to the people who ask, meaning procurement teams, insurers and enterprise clients. Managed cover keeps those controls in place and catches what moves between assessments. Growth accelerates this: doubling headcount in a year doubles your devices, your accounts and your exposure, and continuous cover scales with that while an annual certificate does not.
How UK cyber insurers treat each at renewal
The market moved hard between 2020 and 2026. In 2020, insurers accepted Cyber Essentials as a broad signal of good practice. Ransomware losses pushed underwriters into asking for evidence of specific controls, and by 2026 the standard renewal question set covers documented EDR coverage, awareness training completion rates, backup restore evidence and certification.
Insurers increasingly ask for evidence of both at renewal.
Missing any one of those usually produces a higher premium or an exclusion. Our guide to cyber insurance renewal in 2026 lists the evidence pack worth assembling before the renewal call.
Six questions to ask a managed security provider before you sign
Contracts vary widely for similar money. These six separate a real service from a marketing wrapper.
- What is in the standard tier, and what triggers an upgrade? Detection, identity monitoring, training, incident response and monitoring hours, itemised.
- What are the SOC hours? Genuine 24/7 with human analysts, or business hours with automated overnight alerting. Both get sold as the same thing.
- What are the response times for each priority level? Make sure the provider sets them out contractually and in writing, with service credits applying if they miss the agreed targets.
- What evidence pack do you produce for assessments and insurance renewals? Ask to see a sample.
- What happens if we leave? Who owns the ticket history, the log data and the configuration, and how does it transfer.
- Which third parties handle our data, and where does it sit? Relevant if you carry UK data residency obligations.
A provider who answers all six in writing before signature is a different proposition from one who defers the detail to onboarding.
Where to start
Certification and continuous monitoring answer different questions, and for most UK businesses above 20 users in 2026 the sensible position holds both. The number that matters is not the price of either one, but what your insurer, your enterprise clients and your own risk appetite require of a business your size.
The useful first step is finding out what your current setup covers. We will walk through what you have, show you where the gaps sit against what insurers and procurement teams now ask for, and give you a straight answer on the right level for your headcount. If that turns out to be certification on its own, we will say so.
Book a Cyber Essentials assessment or review your managed IT and security cover.
Related reading
A breakdown of what managed IT typically costs a UK SME, see our guide to per-user IT support costs.
For the consolidation argument that often sits behind this decision, see one-provider IT for Newcastle SMEs.
A wider case for outsourced IT support, see why UK SMEs use an MSP.
