For most businesses, Cyber Essentials arrives as a demand, not a choice. A client sends a supplier questionnaire with a certification box you cannot tick. A tender lists it under mandatory requirements. Your insurer’s renewal paperwork suddenly asks for it. And now you need a certificate you half-understand, by a deadline you did not set.

Here is the good news: Cyber Essentials is the most achievable security certification a small business can get. It was designed by the UK government specifically so that ordinary companies, not just corporates with security teams, could reach a sound baseline and prove it. With systems prepared properly, most SMEs certify in two to three weeks. We handle that preparation for businesses across Scotland, and this page explains exactly what is involved.

What Cyber Essentials is

Cyber Essentials is the UK government-backed certification scheme, run by the National Cyber Security Centre through IASME, that certifies your business has five fundamental technical controls in place:

  1. Firewalls protecting your internet connection
  2. Secure configuration of devices and software
  3. User access control, including admin account discipline
  4. Malware protection on every device
  5. Security update management, meaning patches applied promptly

Certification means completing a detailed self-assessment questionnaire about how your business meets each control, signed off at board level, and reviewed by a licensed assessor. Pass, and you receive a certificate valid for twelve months and a listing on the national register of certified organisations. We have broken down each control and its evidence requirements in our Cyber Essentials checklist.

The certificate is not security theatre. The UK government’s assessment is that the five controls would have prevented the large majority of common internet-borne attacks. Preparing for certification genuinely hardens your business; the certificate is proof of it.

Why businesses get certified

We see four triggers again and again:

Contracts and tenders. Cyber Essentials is mandatory for many public-sector contracts, including most that involve handling personal data, and it is required across large parts of the MOD supply chain. Increasingly, large private-sector firms demand it from suppliers too. No certificate, no bid.

Insurance. Insurers now routinely ask about certification at renewal, and some price against it. Certification through IASME also includes cyber liability insurance for eligible smaller organisations as part of the scheme.

Client credibility. For accountants, solicitors, financial advisers and anyone else holding sensitive client data, the certificate answers the security question before it is asked. It is one of the few security claims a non-technical client can verify: the register is public.

Actually being secure. Some businesses come to us after a near-miss: a phishing email that nearly worked, a competitor’s ransomware story. Certification gives the clean-up a defined target and a deadline.

Cyber Essentials vs Cyber Essentials Plus

There are two levels. Cyber Essentials is a verified self-assessment: you answer the questionnaire, an assessor reviews it. Cyber Essentials Plus covers the same five controls, but an assessor also tests your systems directly, including vulnerability scans of a sample of your devices and tests of your email and browser defences. Plus carries more weight in tenders, and some contracts specify it.

Basic Cyber Essentials is a prerequisite for Plus, and the Plus audit must be completed within three months of your basic certification. If a contract demands Plus, we plan both stages as one project. Our comparison of the two levels covers which one you actually need.

What our certification support covers

You can attempt Cyber Essentials alone: pay the assessment fee, answer the questionnaire, hope. Businesses that do this without preparation tend to discover mid-questionnaire that honest answers would fail them: unsupported Windows versions still in use, staff running as administrators, MFA missing, no formal joiners-and-leavers process. The questionnaire requires a board member to sign that the answers are true, so optimistic guessing is not a strategy.

Our service closes that gap:

For Plus, we also prepare your estate for the technical audit and coordinate the assessor’s testing so it disrupts as little as possible.

How it works

  1. Scoping call. We establish what is in scope: devices, cloud services, home workers, and your deadline. Same week you contact us.
  2. Gap analysis. Typically completed within a week, remotely for most of it.
  3. Remediation. A few days to three weeks depending on findings; most fixes happen remotely with minimal staff disruption.
  4. Submission. The questionnaire goes in; assessor review usually returns within days.
  5. Certificate. You are on the public register, and the renewals clock starts. For Plus, the audit is scheduled after the basic pass.

A prepared business certifies in two to three weeks from a standing start. If your systems need serious remediation, or you need Plus, plan for six to twelve weeks. If a tender deadline is bearing down on you, say so on the first call: the timeline compresses further when it has to.

What it costs

Two costs make up the total. The assessment fee is set by IASME and depends on your size: from around £300 +VAT for micro businesses (under 10 staff) up to £500 to £600 +VAT for large organisations. The fee includes the assessment portal, one assessor review and one free resubmission. Cyber Essentials Plus audits are priced by device count, typically from around £1,500 to £2,500 +VAT for smaller estates.

The second cost is preparation and remediation, which depends entirely on your starting point. A business already running modern, managed systems may need very little. A typical 25-person business budgeting realistically for first-time certification, including remediation work, should expect a total first-year spend in the £1,500 to £3,500 range. After the gap analysis you get a fixed quote, so the decision is made with real numbers rather than estimates. Our Cyber Essentials cost guide breaks down the fee bands and the common remediation costs in detail.

For businesses on our managed support plans, most of the five controls are simply how we run your systems anyway, which makes certification largely a documentation exercise. See our cyber security service for what that ongoing protection includes.

Where we work

We prepare businesses for Cyber Essentials across Scotland from our base at Dundee Technology Park: Dundee, Perth, Fife, Angus and St Andrews on our doorstep, and Edinburgh, Glasgow, Aberdeen and Inverness covered remote-first with on-site visits where the work needs hands. Gap analysis and most remediation happen remotely, so distance changes nothing about the outcome.

Frequently asked questions

How long does Cyber Essentials certification take?

A well-prepared business can be certified in two to three weeks. Typical first-time projects run four to twelve weeks including remediation. Cyber Essentials Plus adds a technical audit and usually lands at twelve to sixteen weeks end to end.

What does Cyber Essentials cost in 2026?

The IASME assessment fee runs from around £300 +VAT for micro businesses to £500 to £600 +VAT for large ones. Plus audits start around £1,500 +VAT. Preparation and remediation are the variable: a realistic first-year total for a typical SME is £1,500 to £3,500.

Will we fail if some of our systems are old?

Unsupported operating systems and software in scope are among the most common causes of failure. The fix is to upgrade, replace or formally segregate them out of scope, and the gap analysis identifies which route is cheapest for each case.

Does it cover staff working from home?

Yes. Home workers’ devices that access business data are in scope, including personal devices used for work under a bring-your-own-device arrangement. The questionnaire asks about them specifically, and our preparation covers them.

Do we need Cyber Essentials or Cyber Essentials Plus?

Check what the contract, client or insurer actually demands. Basic satisfies most requirements today; MOD and an increasing number of public tenders specify Plus. If you need Plus, remember basic certification is the prerequisite and the audit must follow within three months.

What happens if our submission fails?

The scheme includes one free resubmission within 48 hours of feedback. Because we prepare the answers with evidence before anything is submitted, failure at assessor review is rare; borderline items get fixed before submission, not argued after.

Does certification include insurance?

Eligible UK organisations certifying at basic level through IASME are included in cyber liability insurance as part of the scheme, subject to the scheme’s terms. Separately, holding certification often improves your position at your own insurer’s renewal.

Is Cyber Essentials worth it if nobody is asking us for it yet?

The controls are worth having regardless: they block the common attacks that actually hit SMEs. Getting certified while nobody is demanding it means the first tender or insurer that asks is a box you tick, not a six-week emergency.

Get ahead of the deadline

If a questionnaire, tender or insurer has put Cyber Essentials on your desk, the next step is a gap analysis, and if you are simply weighing it up, our free IT health check will tell you how far off the standard you currently are. Either way you get findings in plain English and a fixed price for anything that needs fixing. Get in touch and tell us your deadline; we will work backwards from it.