Cyber Essentials UK 2026: Is It Worth It for Small Business?

Cyber Essentials UK 2026: Is It Worth It for Small Business?

Cyber Essentials is the UK government’s own cybersecurity certification — and for most small businesses, it’s the single most practical thing you can do to protect yourself. The 2025/2026 Cyber Security Breaches Survey (published April 2026) found that 43% of UK businesses experienced a cyber breach or attack in the past 12 months, and businesses that did suffer a financial hit averaged £3,550 per incident. Against that, a Cyber Essentials certificate starts at around £300 + VAT. The maths isn’t complicated. This guide covers what changed in April 2026, what it actually costs, and when it’s genuinely worth doing — and when it isn’t.

  • Cyber Essentials (self-assessment): from £300 + VAT, scaling by company size (1–9 staff: ~£300; 10–49 staff: ~£440)
  • Cyber Essentials Plus (independently audited): from £1,499 + VAT, typically £1,500–£3,000 for SMEs
  • April 2026: new “Danzell” question set (v3.3) replaced the previous Willow version — stricter MFA rules and new auto-fail criteria
  • Required for UK government contracts handling personal or sensitive data; mandatory for MOD supply chain work
  • Managed by IASME Consortium on behalf of the NCSC; other accredited bodies include QG Management Systems

What is Cyber Essentials — and who runs it?

Cyber Essentials is a UK government-backed certification scheme, launched in 2014 and maintained by the National Cyber Security Centre (NCSC). The NCSC licenses IASME Consortium as the sole accreditation body; IASME then authorises certification partners across the UK to carry out assessments. You do not go to the NCSC directly — you work with an IASME-licensed body.

The scheme is built around five technical controls:

  1. Boundary firewalls and internet gateways — making sure your network has a properly configured perimeter
  2. Secure configuration — removing unnecessary software and default passwords from every device in scope
  3. User access control — limiting who can access what, and removing accounts when people leave
  4. Malware protection — anti-malware tools running and up to date on all devices
  5. Security update management — keeping operating systems and software patched promptly

The NCSC states that these five controls, properly implemented, prevent around 80% of common cyberattacks — including phishing, malware, and ransomware. That’s a significant claim, and it’s broadly supported by incident data. They don’t cover everything (more on that below), but they address the routes most attackers actually use against small businesses.

What changed in Cyber Essentials in 2026?

From 27 April 2026, all new Cyber Essentials assessments must use the updated Danzell question set (v3.3), which replaces the previous Willow version. This is the most significant update the scheme has seen in several years.

Here’s what’s actually different:

Auto-fail questions for the first time. Danzell introduces automatic failure criteria — previously, minor gaps could be discussed with an assessor. Under Danzell, certain MFA and patching failures result in an immediate fail, full stop.

Stricter MFA requirements. Multi-factor authentication is now expected across a wider range of accounts and services. Passkeys and biometric authentication are now formally accepted as satisfying the MFA control — a useful update for businesses already using them.

Cloud services cannot be excluded. This is the change catching most businesses off guard. Under Danzell, any service that stores or processes your business data — email platforms like Microsoft 365 or Google Workspace, identity providers, social media platforms, and AI tools like Copilot or ChatGPT Enterprise — must meet the required controls. You cannot simply declare them “out of scope.”

High-severity vulnerabilities must be patched within 5 days (previously 14 days for some categories).

Existing certificates are not affected. If your certificate was issued before 27 April 2026, it remains valid for its full 12-month period. The new rules hit you at renewal time.

What many businesses don’t realise: if you created your assessment account on the IASME portal before 27 April, you can still complete it under the old Willow standard — and you have six months from account creation to submit. That transitional window runs until 26 October 2026 for accounts opened in time.

How much does Cyber Essentials certification cost in 2026?

IASME sets the base fees for Cyber Essentials on a tiered structure by headcount. The 2026 prices are:

Organisation sizeCyber Essentials (basic)Cyber Essentials Plus
Micro (1–9 employees)~£300 + VAT£1,499–£1,900 + VAT
Small (10–49 employees)~£440 + VAT£1,900–£2,500 + VAT
Medium (50–249 employees)~£550 + VAT£2,500–£3,500 + VAT

But here’s the problem: the IASME fee is rarely the whole picture. A realistic budget for a 10-person business getting certified for the first time looks more like this:

  • IASME assessment fee: ~£440 + VAT
  • Internal time to complete the self-assessment questionnaire (typically half a day to a full day): £0 in cash, but real cost to your business
  • Remediation work if you fail areas — new router, MFA setup on email, removing unused accounts: anywhere from £0 to £500+
  • Optional consultancy to help you prepare: add £150–£400 from most providers

So a realistic first-year spend for a 10-person London marketing agency is probably £700–£1,200 all in for basic Cyber Essentials — and that includes fixing the things you probably should have fixed anyway.

For Cyber Essentials Plus, add the auditor’s fee (£1,499–£2,500 for small businesses) on top of the basic assessment. You also have to pass basic first, and you typically have three months to book the Plus audit before the window closes. Miss it, and you start again.

One benefit most people overlook: UK-based businesses with turnover under £20 million that certify their whole organisation receive £25,000 of cyber-liability insurance included in the certificate fee, provided through Hiscox via IASME. For a micro business with no standalone cyber cover, that’s worth more than the certificate itself.

Is Cyber Essentials actually worth it for small business?

Here’s an honest answer: for most UK small businesses, yes — but not for all the reasons vendors will tell you.

The 2025/2026 Cyber Security Breaches Survey from the UK government found that 43% of businesses experienced a breach or attack in the past 12 months. Among small businesses (10–49 employees), the figure is 46%. Among medium businesses, 65%. And for businesses that did suffer a financial loss, the average cost of the most disruptive breach was £3,550. That’s the average — some paid considerably more.

The NCSC’s own position is that Cyber Essentials prevents around 80% of common attacks. If you accept that at face value, paying £440 + VAT for the certificate (and a few hundred more to fix the gaps it reveals) is one of the better risk management decisions available to a small business.

But there’s a more practical reason to consider it. The number of organisations — both public and private sector — that now require Cyber Essentials from their suppliers has grown substantially. Government contracts handling personal data have required it since 2014. MOD supply chain work requires it. NHS supplier frameworks increasingly include it. And in 2024–2026, private-sector procurement teams have started adding it to supplier questionnaires too.

When it IS worth it:

  • You want to bid for government or public sector contracts
  • You handle customer personal data and want to demonstrate compliance with UK GDPR / DPA 2018
  • Your cyber insurance broker has asked about certification (or is requiring it)
  • You want the included £25k liability cover without paying separately for it
  • A key client has asked for it as part of their supplier due diligence

When it might not be urgent:

  • You’re a sole trader with no employees, no customer data, and no contracts requiring it
  • Your entire operation is offline or involves no networked devices

Even in that last scenario, the scheme is so low-cost at the micro level (~£300) that the question becomes less about ROI and more about whether you have an afternoon to spare.

How does Cyber Essentials affect UK cyber insurance?

This is where certification has quietly become more important in the past two years.

UK cyber insurers have tightened their underwriting requirements significantly since 2022. Many will now simply decline to quote for businesses without Cyber Essentials certification — or will quote at a substantially higher premium. In my experience, the discount for certified businesses ranges from 5% to 15% on cyber insurance premiums, though some brokers report savings of up to 30% for businesses that move from uncertified to certified.

The owner of a 15-person Bristol-based recruitment agency I spoke to recently said her broker told her certification would save her approximately £800 a year on her renewal premium. That’s more than twice the cost of the basic certificate.

What insurers are checking: active certification (they can verify this through the IASME public register), scope coverage (a certificate covering only part of your organisation is worth less to them), and increasingly, Cyber Essentials Plus for businesses above a certain size or in higher-risk sectors.

And remember: the certification itself comes with £25,000 of cyber-liability cover included (for eligible UK businesses). For micro businesses that have never bought cyber insurance, this alone often justifies the cost of certification.

Step-by-step: how to get Cyber Essentials certified

The process is more straightforward than most people expect. Here’s how it works for the basic certification:

Step 1 — Choose your level. Basic Cyber Essentials (self-assessed) or Cyber Essentials Plus (independently audited). For most small businesses starting out, basic is the right first move. You can always add Plus later.

Step 2 — Pick an IASME-accredited certification body. IASME maintains a directory at iasme.co.uk. Well-known options include IASME itself, QG Management Systems, IT Governance, and a range of regional IT support firms. Prices are fixed by IASME for the basic fee, but Plus pricing and any consultancy support will vary.

Step 3 — Create an account on the IASME portal and complete the self-assessment questionnaire. The SAQ covers 64 questions across the five controls. You answer based on your actual IT environment — devices, software, cloud services, user accounts. From 27 April 2026, new assessments use the Danzell question set. Give yourself a full day to work through it carefully.

Step 4 — Remediation if needed. If your assessor flags gaps, you typically get one free resubmission within 48 hours. Common issues: MFA not enabled on admin accounts, devices running outdated software, or cloud services that weren’t scoped properly. Fix what’s needed and resubmit.

Step 5 — Certificate issued. Valid for 12 months from issue date. You’ll receive the badge to display, and the certificate is listed on the IASME public register. Set a renewal reminder now — letting it lapse has real consequences (see below).

Timeline: basic Cyber Essentials typically takes two to six weeks from start to certificate, depending on how prepared your IT environment is. Some certification bodies advertise same-day certification for compliant organisations.

Common mistakes — what to avoid

Assuming it covers everything. Cyber Essentials covers the five technical controls. It does not address physical security (someone walking out with a laptop), social engineering (a staff member being manipulated over the phone), or insider threats. It’s a floor, not a ceiling. The NCSC is clear about this.

Letting the certificate lapse. The certificate is valid for exactly 12 months. Miss the renewal and you lose the right to bid on government contracts requiring active certification, you lose the bundled £25k insurance, and you go back to the start of the process. Annual renewal is mandatory. Put it in your calendar the day you receive the certificate.

Underestimating scope. Under Danzell, “all devices that can access organisational data” includes personal smartphones used for work email, cloud services, and AI tools your team uses for business purposes. Businesses that certify only their office PCs are setting themselves up for a failed audit — or, worse, a false sense of security.

Doing it just for the badge. The value of certification comes from actually implementing the controls, not from having the certificate on your website. I’ve seen businesses rush through the self-assessment questionnaire by answering questions optimistically, pass, and then fail to maintain those controls. When an insurer or client comes to verify, that becomes a serious problem. Fix the issues the questionnaire reveals; the badge follows naturally.

Is Cyber Essentials right for your business?

For most UK small businesses, Cyber Essentials UK certification is worth doing — not because it’s mandatory (though it increasingly is for government-facing work), but because the cost is low relative to what it protects. A basic certificate from £300 to £440 + VAT, a day of internal time, and remediation work that you probably needed to do anyway. Against average breach costs of £3,550 and rising, and against an attack rate of 43% of all UK businesses, the numbers point in one direction.

The 2026 Danzell update tightened the scheme meaningfully. MFA is no longer optional in any real sense, and cloud services — including the AI tools your team is likely using — are now firmly in scope. That makes certification slightly harder to achieve than it was two years ago, but also more valuable.

Start at the NCSC’s official page (ncsc.gov.uk) or at iasme.co.uk to find an accredited certification body. If you’re renewing before October 2026 and created your account before 27 April, check whether you’re still on the Willow transition window. Either way, don’t leave it another year.