Cyber Essentials Explained: A UK Business Guide to Getting Certified
You have probably seen Cyber Essentials listed as a requirement on a tender document, or had a larger client ask whether you hold it before they sign. That question is becoming routine. More UK buyers now treat the certificate as a basic condition of doing business, and suppliers without it get quietly filtered out.
Here is what Cyber Essentials actually is, what it protects against, and how to get certified without the process eating your week.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification that confirms your business has the core controls in place to defend against the most common cyber attacks. You complete a structured self-assessment questionnaire, then an accredited certification body reviews it independently.
The scheme targets the everyday threats that hit small and medium firms hardest: phishing, malware, and attacks that exploit unpatched software or weak configuration. Get these basics right and you stop the large majority of opportunistic attacks before they start.
The five controls it covers
Cyber Essentials checks five technical controls:
Firewalls and secure internet gateways that keep untrusted traffic out.
Secure configuration so devices and software ship without risky default settings.
Access control that limits who can reach what, and removes rights people no longer need.
Malware protection running across your devices.
Security update management so patches land before attackers exploit the gap.
None of these are exotic. Most breaches at SME level trace back to one of them being missed.
Cyber Essentials vs Cyber Essentials Plus
There are two levels, and the difference matters for contracts.
Cyber Essentials is a 70-question self-assessment, verified independently, that confirms your setup lines up with the framework.
Cyber Essentials Plus covers everything in the basic level, then adds a hands-on technical audit. An assessor tests your systems with vulnerability tools to prove the controls hold up in practice, checking patch levels, malware protection, device configuration, user access, and internet-facing security.
You cannot jump straight to Plus. You pass the basic questionnaire first, because the Plus audit verifies the answers you gave. Once you hold the basic certificate, you have 90 days to complete Plus.
Why it is worth doing
Three reasons come up again and again with our clients:
You win more work. Many government frameworks and enterprise buyers will not engage a supplier without Cyber Essentials. Holding it keeps you on the shortlist.
You cut real risk. The five controls block the bulk of common attacks, which protects your data, your clients, and your reputation.
You strengthen the rest of your security. Cyber Essentials sets a recognised baseline. Plenty of our clients earn it, add Cyber Essentials Plus, then progress to ISO 27001 as their compliance needs grow.
What it costs and how long it lasts
Support at Intouch Tech starts from £420 + VAT. The certification fee itself follows a tiered scale set by company size, using the standard micro, small, medium, and large definitions. On top of that, we charge to run the whole project for you, priced on the size and complexity of your network. You get the full figure up front, with no surprises later.
Each certificate lasts 12 months. You renew annually to stay certified and keep meeting buyer requirements.
Timing is quicker than most owners expect. Many businesses certify within 7 to 10 working days, and the full process usually wraps up in 2 to 4 weeks.
How Intouch Tech gets you certified
Our in-house cyber team runs the whole thing, so you are not left decoding technical requirements on your own. It works in four steps:
Discovery call. We assess your needs and recommend the right level.
Cyber readiness and gap support. We prepare everything the assessment needs and fix what would otherwise fail.
Submission and independent assessment. Your certification is reviewed and issued through an accredited provider.
Certification achieved. You receive your official Cyber Essentials certificate.
We are a UK-based team, working with businesses since 2012, rated 4.9 on Trustpilot across more than a thousand UK organisations, with certification handled by an independent accredited body and penetration testing delivered through a CREST-accredited partner.
Frequently asked questions
Do I need Cyber Essentials to win contracts? Often, yes. Many government and enterprise buyers will not work with suppliers who lack it.
How much does certification cost? Support starts from £420 + VAT. The exact figure depends on your company size and network complexity, and we confirm it before you commit.
How long does it take? Most businesses certify within 7 to 10 working days, with the full process typically complete in 2 to 4 weeks.
How long does the certificate last? Twelve months, then you renew to stay certified.
What if we are not ready? Our cyber team fixes the gaps with you before you submit, so you are set up to pass first time.
Can we certify if we are based outside the UK? Yes. Organisations outside the UK can certify too, and we handle the process the same way.
Ready to get certified?
Cyber Essentials does not need to be complicated. With Intouch Tech you get expert guidance, a smooth process, and a certificate you can put in front of any buyer with confidence.
Call 0333 370 7000 or request a free quote to get started.
Intouch Tech provides Cyber Essentials certification support for UK businesses. Get expert guidance, remediation and security improvements t













