Cyber Essentials explained
Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC), that shows an organisation has five technical controls in place against the most common internet-based attacks. Cyber Essentials Plus checks the same controls through independent technical testing. Neither is insurance, but both cover much of the ground that cyber insurers typically ask about.
Part of: Cyber insurance at Apex
In short
Cyber Essentials is a government-backed certification, overseen by the NCSC and delivered by IASME, covering five controls: firewalls, secure configuration, security update management, user access control and malware protection. Standard certification is an independently marked self-assessment; Plus adds a technical audit. Certificates last 12 months. Certification is not insurance and does not guarantee an insurer’s terms or discount; eligible organisations can opt in to £25,000 of included cover.
The NCSC describes Cyber Essentials as “the minimum standard of cyber security recommended by the Government for organisations of all sizes”. Launched in 2014, the scheme is built around five technical controls designed to prevent the most common internet-based attacks — which, the NCSC says, are mostly basic in nature, like a thief trying the front door to see if it is unlocked.
Certification should cover the whole of the IT infrastructure used to run the business or, if necessary, a well-defined and separately managed sub-set agreed with the certification body. Because scope can be narrowed, anyone relying on a supplier’s certificate should check what it covers. Current certificates can be searched on IASME’s website.
The requirements sit under five control themes. Version 3.3 has applied since 27 April 2026; applications started before that date can follow version 3.2.
| Control | What it requires, in summary |
|---|---|
| Firewalls | Every in-scope device protected by a correctly configured firewall, so only secure and necessary services can be reached from the internet. |
| Secure configuration | Unnecessary accounts and software removed, default or guessable passwords changed, auto-run disabled and device locking in place. |
| Security update management | Software licensed and supported, unsupported software removed, and critical or high-risk updates installed within 14 days of release. |
| User access control | Accounts only for authorised people, access limited to what each role needs, separate administrator accounts, and multi-factor authentication (MFA) where available — always for cloud services. |
| Malware protection | Active, up-to-date anti-malware software or application allow listing on every in-scope device. |
The April 2026 changes matter in practice: cloud services cannot be excluded from scope, and under IASME’s question set, not using MFA on cloud services where it is available, or not installing critical or high-risk updates within 14 days, now means an automatic fail. Backing up data is still not a technical requirement of Cyber Essentials, although the NCSC highly recommends it.
Both levels assess the same five controls. The difference is how compliance is checked.
| Aspect | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Method | Verified self-assessment: an online question set, signed off by a board member or equivalent and marked by an assessor from a certification body | Technical audit by a certification body, on site or remotely, to verify the controls work in practice |
| What is tested | Your answers, plus any evidence the certification body asks for | An external vulnerability scan of your public IP addresses, plus tests on a representative sample of devices and cloud services covering patching, malware protection, MFA and separate admin accounts |
| Prerequisite | — | Cyber Essentials certification; IASME says the audit can be completed within three months of it |
| Validity | Expires after 12 months | Expires after 12 months |
The NCSC describes two routes: self-led, where you register through IASME and complete the assessment yourself, or supported, where you hire a certification body licensed by IASME to help. In outline:
A certificate is a snapshot. Government guidance notes that Cyber Essentials “provides assurance of compliance only at the time of testing”, and an organisation that stops patching may become non-compliant well within the year.
The government recommends Cyber Essentials for organisations of all sizes, and official guidance requires it, or equivalent controls, for certain government contracts. Procurement Policy Note 014, updated in February 2025 and replacing PPNs 09/14 and 09/23, applies to central government departments, their executive agencies, non-departmental public bodies and NHS bodies. They must ensure suppliers meet certain technical requirements on contracts where:
The PPN names Cyber Essentials or Cyber Essentials Plus certification as “the quickest and most effective means” of mitigating those risks, with Plus for higher-risk contracts. Where certification is required it must be renewed annually for the life of the contract, and evidence is needed before contract award. Suppliers without it must demonstrate equivalent controls instead. Buyers are told not to apply it to every contract as a matter of course.
More widely, the NCSC notes that “a growing number of organisations require suppliers to be certified to bid for work”, so it can also be a commercial requirement set by a client or tender.
Certified organisations that qualify can take a cyber liability policy arranged by IASME. According to IASME, an organisation qualifies if:
The policy has a £25,000 total limit of indemnity and a 24-hour helpline for crisis management and incident response. Within that limit it can respond to liability claims, incident costs such as legal, IT and data recovery expenses, extortion threats and some interruption losses. It lasts 12 months from certification and cannot be renewed separately from the certificate. It does not cover money stolen electronically or through cyber fraud, an excess applies, and updates for critical business software must be kept installed for the insurance to remain valid.
IASME says the £25,000 limit “might be sufficient for a small breach or incident but inadequate for a serious problem or more than one incident”, and the NCSC says this cover “won’t be suitable for all organisations”. You cannot claim on two policies, so an organisation already satisfied with its own cyber cover can decline it.
Certification and insurance do different jobs. Cyber Essentials lowers the chance that a common attack succeeds, but it does not remove risk and is not designed for advanced, targeted attacks. Cyber insurance deals with the aftermath: subject to the wording, a standalone policy typically covers incident response, restoring systems and data, business interruption losses and liability for claims from affected third parties. As the NCSC puts it, insurance “will not prevent a cyber breach/attack”.
The two overlap in practice. Cyber insurance proposal forms typically ask about the same ground Cyber Essentials covers — MFA, patching timescales, user and administrator access — and usually about backups, which Cyber Essentials does not assess. The NCSC’s cyber insurance guidance warns that if you claim security measures are in place when they are not, “the insurer may not be obliged to pay any claims”. Answer from how your systems actually run, not from what a certificate implies.
Good controls help, but they do not decide terms. The NCSC says some insurers offer discounts for recognised defences such as Cyber Essentials, and advises telling your broker about them. Its 2023 Annual Review cited data suggesting 80% fewer cyber insurance claims where Cyber Essentials was in place; a later government evaluation explains the comparison was with organisations holding the same policy without certification, using 2022 claims data. Each insurer still makes its own assessment, and certification does not guarantee cover, a discount or a particular limit.
Also check whether a policy covers business email compromise fraud (the NCSC notes some do not), whether the limit fits your exposure, and whether existing commercial insurance policies include or exclude cyber losses. A data breach can also bring claims from clients, so professional firms should know how their cyber and professional indemnity insurance wordings each respond; see also ransomware and professional firms. Apex arranges cyber insurance and can help present your controls, including any certification, clearly to insurers.
No. Cyber Essentials is a certification showing that five technical security controls were in place when you were assessed. Cyber insurance is a policy that pays for specified costs and liabilities after an incident, subject to its wording. Eligible certified organisations can opt in to an included cyber liability policy with a £25,000 total limit, but IASME says that limit may be inadequate for a serious incident.
Cyber Essentials and Cyber Essentials Plus certificates both expire after 12 months, so organisations must recertify every year to stay certified. Government procurement guidance adds that a certificate gives assurance only at the time of testing, and an organisation that stops patching or managing its configuration can become non-compliant well before the year is up.
Both cover the same five controls. Cyber Essentials is a verified self-assessment: you answer an online question set, a board member signs it off, and an assessor from a certification body marks it. Cyber Essentials Plus adds a technical audit, including vulnerability scans and tests on a representative sample of devices. You need Cyber Essentials first, and IASME says the Plus audit can be completed within three months of it.
For eligible organisations, yes. IASME says an organisation qualifies if the whole organisation is certified, it is domiciled in the UK or Crown Dependencies, its annual turnover is under £20m and it opts in. The cover has a £25,000 total limit of indemnity, includes a 24-hour incident helpline, lasts 12 months from certification and does not cover money stolen electronically or through cyber fraud.
It may help, but it is not automatic. The NCSC says some insurers offer discounts where recognised defences such as Cyber Essentials or Cyber Essentials Plus are in place, and advises making sure your broker knows about them. Each insurer still makes its own assessment of the whole risk, so certification does not guarantee that terms, a discount or a particular limit will be offered.
For some. Under PPN 014, central government departments, their executive agencies, non-departmental public bodies and NHS bodies must ensure suppliers meet certain technical requirements on contracts involving, for example, citizens’ or officials’ personal information or ICT systems handling OFFICIAL data. The PPN names Cyber Essentials or Plus certification as the quickest way to meet them; suppliers without it must show equivalent controls, and certification must be renewed annually for the life of the contract.
Tell us how your systems are set up, including any certification, and we’ll find cyber insurance that fits your business. Or call 0117 325 0027.
Get a quote Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not legal or tax advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.