What Cyber Essentials is, and why it matters
Cyber Essentials is a UK government-backed certification scheme administered by the IASME Consortium on behalf of the National Cyber Security Centre. It defines five technical controls that, when properly implemented, prevent around 80% of the most common cyber attacks targeting UK businesses.
The certification has become a baseline expectation across UK public-sector procurement, professional services contracts, and supply chains in regulated sectors. For most UK SMEs it is now easier to list the customers who don't ask for it than the ones who do.
There are two levels: Cyber Essentials, which is a self-assessment verified by an external assessor, and Cyber Essentials Plus, which adds independent technical testing of a sample of your devices. Plus is increasingly the expected standard for organisations serving central government, the NHS, MOD supply chains, and large enterprise clients.
The five technical controls explained
All Cyber Essentials evidence maps to five control areas. Understanding what each one means in practice saves weeks during the actual assessment.
- Firewalls - every device that connects to the internet must have a properly-configured firewall, with default admin passwords changed and unnecessary inbound services blocked
- Secure configuration - devices and software must be configured to reduce attack surface: unnecessary accounts disabled, default passwords changed, unused services removed
- User access control - users have only the access they need, admin accounts are separate from day-to-day accounts, MFA is enforced on cloud services and remote access
- Malware protection - either anti-malware software with current definitions, or application allow-listing, or both, deployed on every in-scope device
- Security update management - operating systems and software must be supported, automatic updates enabled, and high-risk patches applied within 14 days of release
Why first-time applications fail - and how to avoid it
The IASME assessors see the same handful of failure modes repeatedly. Knowing them up front turns a six-month false start into a four-week certification.
The most common failure is unsupported software still in use - Windows 7 on a finance machine, an unpatched server, or an end-of-life mobile device. Assessors will fail a submission with any unsupported asset in scope, regardless of how well-controlled the rest of the estate is.
The second most common failure is MFA gaps. Cloud services with privileged access - Microsoft 365 admin, Google Workspace admin, financial systems - must enforce MFA. Allowing exceptions for senior staff is an instant fail.
The third is overly broad scope. Many businesses submit their whole estate when a more carefully drawn scope - excluding, for example, a guest Wi-Fi network or a legacy lab environment - would have certified comfortably.
Scoping the assessment correctly
Scope is the most important decision you make. The official rule is that anything that can access organisational data or services must be in scope, but you may exclude clearly segregated networks and bring-your-own-device estates that are properly contained.
A typical first-time scope for a 30-50 person UK SME is: all Windows and Mac laptops, all company-issued mobile phones, Microsoft 365 or Google Workspace, the office firewall, and the corporate Wi-Fi. Guest Wi-Fi and personal devices are excluded with appropriate technical controls in place.
Realistic 4-to-6 week timeline
For most UK SMEs without major gaps, certification takes four to six weeks end to end. Larger or more complex estates take longer; estates with end-of-life software take as long as it takes to replace it.
- Week 1: scoping workshop, asset inventory, gap analysis against the five controls
- Weeks 2-3: remediation - MFA rollout completion, patching, configuration tightening, replacing unsupported assets
- Week 4: documentation, evidence pack, submission of the self-assessment
- Weeks 5-6: assessor questions, certification issued
- For Cyber Essentials Plus, add 2-3 weeks for the independent technical testing
What changes after you certify
Cyber Essentials is annual. The controls need to stay in place, evidence needs to remain current, and you re-certify every twelve months. Treat the first certification as the start of an ongoing security baseline, not a one-off project.
Most clients also use certification as a forcing function for related improvements: a security awareness training programme, a documented incident-response plan, and a move to a managed security service for ongoing monitoring. Telappliant offers all three.
Next steps with Telappliant
Telappliant is a Cyber Essentials certified body and supports UK businesses through both Cyber Essentials and Cyber Essentials Plus. The fastest entry point is our Cyber Essentials Readiness tool, which produces an honest gap analysis in under three minutes.
Frequently asked questions
Related reading
Talk to a UK specialist about cyber essentials: the complete uk certification guide
Short consultation, honest advice, no pressure.

