A client has asked if we have Cyber Essentials. What now?

Published 2026-08-02 by Woodruff Training

It usually arrives in a tender document, or an email from a client's procurement team, phrased as though you will obviously know what it means. Do you hold Cyber Essentials? For most small businesses the honest answer is no. The second honest answer is that it is more achievable than it sounds.

What they are actually asking for

Cyber Essentials is a government-backed scheme. The NCSC owns it and IASME runs it on their behalf. It asks you to have five basic technical controls in place, and then to answer a questionnaire about them truthfully. A certification body licensed by IASME marks those answers and issues the certificate. Nobody comes to your office.

There are two levels, and it is worth pinning down which one you need before you spend anything. The standard certification is that self-assessment. Cyber Essentials Plus covers exactly the same five controls, but somebody from the certification body tests them hands-on, which costs more and takes longer. Ask your client which they mean. Plenty of procurement teams write "Cyber Essentials" when the standard certification would satisfy them perfectly well, and a few are working from a template and have no firm requirement at all.

The five controls

None of it is exotic.

  • Firewalls. Something sensible between your devices and the internet, including for people working from home.
  • Secure configuration. Default passwords changed, software and accounts nobody uses removed, devices that lock themselves.
  • Security update management. Updates applied promptly, and nothing still running that the vendor has stopped supporting.
  • User access control. Everyone on their own account, administrator rights used only for administrator work, and multi-factor authentication on your cloud services.
  • Malware protection. Anti-malware kept current, or only allowing applications from an approved list.

Most businesses are already further along than they expect. Multi-factor authentication and retiring old software are the two that usually need real work.

Where applications come unstuck

Scope, more than anything else. Before you answer a single question, decide what is being certified: the whole organisation, or a clearly defined part of it. That decision has to account for laptops, phones, staff working from home and every cloud service people log into. It is tempting to quietly leave out the awkward machine in the corner, and that is exactly the thing that unravels later.

The other one is answering hopefully. The questionnaire is a declaration you are signing, and "we are getting round to it" is not a yes. If a control is not in place, put it in place and then answer.

What to do this week

Work out roughly where you stand before you commit any money, then get a quote from a certification body and remember their fee sits on top of any help you pay for. It is also worth asking what else comes with certification, because for smaller UK organisations it can include a limited cyber insurance option. Check the current terms rather than assuming, since they change.

Being asked is good news, in a roundabout way. It means somebody wants to work with you and has a box that needs ticking. Most small businesses get there in a few weeks rather than a few months.

If you want to know where you stand before speaking to anyone, our free readiness checklist covers scope and all five controls in thirty plain-English questions. If it turns up more than you fancy tackling on your own, that is the work we do.