Smart Path IT logo
Smart Path IT
Blog/Cyber Essentials 2026: The UK SME Guide to Certification, Costs, and What's Changed
🛡️ Security

Cyber Essentials 2026: The UK SME Guide to Certification, Costs, and What's Changed

2026-06-1611 min read
By SmartPath Security Team

What is Cyber Essentials?

Cyber Essentials is a UK government-backed cybersecurity certification scheme run by the National Cyber Security Centre (NCSC). It sets a baseline of five technical controls designed to protect organisations against the most common cyber attacks.

There are two tiers:

  • Cyber Essentials: Self-assessed questionnaire verified by a certification body
  • Cyber Essentials Plus: Same controls plus independent technical testing by a qualified assessor

Both are valid for 12 months and must be renewed annually.

Why it matters in 2026

Government contracts

Since 2014, Cyber Essentials has been mandatory for all UK government contracts involving sensitive or personal data. The scope has gradually expanded — by 2026, most central government procurement frameworks, NHS supplier requirements, and many local authority contracts require at least Cyber Essentials.

If your business supplies public sector organisations, or wants to, certification is effectively non-optional.

Cyber insurance

An increasing number of UK cyber insurance providers now require Cyber Essentials (or equivalent controls) as a condition of cover, or offer premium reductions for certified organisations. NCSC data suggests certified organisations file 80% fewer claims.

Customer and tender requirements

Beyond government, many large private sector organisations now include Cyber Essentials in their supplier due diligence processes. Completing your certification reduces friction in enterprise sales cycles.

It's just good practice

The five controls address the most common attack vectors. An organisation that genuinely implements them properly reduces its risk exposure significantly — not to zero, but the basic Cyber Essentials controls would have prevented the majority of the cyber incidents SmartPath IT has responded to in recent years.

The five Cyber Essentials controls

1. Firewalls (boundary and device)

  • Network firewall protecting your internet-facing boundary
  • Software firewalls on all devices, including laptops used remotely
  • Rules permitting only necessary inbound connections
  • Default passwords changed

2. Secure configuration

  • Remove or disable unnecessary software, accounts, and services
  • Change default admin credentials
  • Enable automatic screen lock after inactivity
  • No auto-run of external media (USB, DVD)

3. User access control

  • User accounts for day-to-day work — separate administrator accounts for admin tasks
  • Two-factor authentication on all internet-facing services (email, remote access, cloud services)
  • Limit admin rights to those who genuinely need them
  • Review accounts regularly and disable leavers promptly

4. Malware protection

  • Anti-malware software installed and active on all devices
  • OR application allowlisting (an alternative approach for managed devices)
  • Signature/definition updates applied automatically

5. Patch management

  • Security patches applied within 14 days of release for internet-facing systems
  • Patches applied within 14 days for all software on all devices
  • Unsupported software removed (this is why Windows 10 machines are a problem — see our separate guide)
  • Automatic updates enabled where possible

What the 2026 scheme looks like

The NCSC updated the Cyber Essentials scheme in January 2022 and further refined it in 2023 and 2025. Key 2025/2026 points:

  • Cloud services explicitly in scope: Office 365, AWS, Google Workspace — all covered. If it processes your data, it's in scope
  • Firmware counted as software: Router and firewall firmware must be patched within 14 days (previously ambiguous)
  • Remote workers fully in scope: Home office devices are in scope if they access company systems
  • Multi-factor authentication on all cloud services: This is now a hard requirement, not a recommendation
  • Unsupported software is an automatic fail: Any device running software that no longer receives security updates fails the assessment

Costs in 2026

Cyber Essentials (self-assessed)

  • Certification body fee: £300–£450 + VAT (varies by provider)
  • SmartPath IT preparation support: From £500 for a readiness assessment and gap remediation
  • Total for a typical 20-person business: £800–£1,500

Cyber Essentials Plus (technical test)

  • Certification fee: £1,500–£3,000 + VAT (includes technical testing)
  • Remediation if issues found: Variable
  • SmartPath IT full-service package: From £2,500 for preparation, testing coordination, and certification

Free support for SMEs

The NCSC's Cyber Essentials for SMEs programme offers free guidance resources. Additionally, certain sector bodies and growth hubs offer subsidised certification — particularly for:

  • Charities and third-sector organisations
  • Defence supply chain companies (Defence Cyber Protection Partnership)
  • NHS suppliers

Ask SmartPath IT whether your sector qualifies for subsidised or co-funded certification.

What to expect from the process

Cyber Essentials (self-assessed)

  1. Readiness assessment (~1 week): Review your current controls against the five areas. Identify gaps.
  2. Remediation (1–4 weeks depending on gaps): Patch, configure, implement MFA, tighten firewall rules.
  3. Submit questionnaire via an approved certification body portal.
  4. Verification call (1 hour): Certification body reviews your answers and asks clarifying questions.
  5. Certificate issued if you pass.

Most well-prepared organisations complete the process in 3–6 weeks.

Cyber Essentials Plus

Same preparation, plus:

  • Vulnerability scan of your internet-facing systems
  • Internal network scan looking for misconfigurations and unpatched systems
  • Device spot-check: Assessor reviews a sample of devices

If issues are found during testing, you have a short window to remediate and retest (varies by provider — typically 2–4 weeks).

Common failure points

The issues that cause most Cyber Essentials failures:

  • Running unsupported software (Windows 10, old Java, outdated browser versions)
  • Missing MFA on cloud services — particularly email (the most common gap)
  • Overly permissive inbound firewall rules
  • Local administrator accounts on standard user devices
  • Patches not applied within the 14-day window
  • Cloud services not included in the scope submission

How SmartPath IT helps

We offer a Cyber Essentials readiness service that covers:

  • Full gap analysis against all five control areas
  • Remediation of identified issues (patching, MFA rollout, firewall hardening)
  • Preparation of your questionnaire submission
  • Coordination with your chosen certification body
  • Ongoing Cyber Essentials renewal management

For organisations pursuing Cyber Essentials Plus, we also coordinate the technical testing and handle remediation of any issues found.

Get in touch to discuss Cyber Essentials preparation for your organisation.

Keywords:

#cyber essentials 2026#cyber essentials certification UK#NCSC cyber essentials#cyber essentials plus#UK government contracts cybersecurity
🛡️

About the Author

SmartPath Security Team is part of SmartPath's expert team focused on security and technology best practices. This article represents our latest insights and research.

Ready to Implement These Security Best Practices?

Our experts can help you develop a tailored strategy for your business. Get a free assessment today.