Cyber Essentials is worth doing. It is not the point where a business gets to stop thinking about security.
Published: 12 June 2026 · Updated: 2 July 2026
Cyber Essentials gives SMEs a useful baseline. It pushes important questions about MFA, patching, firewalls, malware protection and secure configuration. For many businesses, that alone is progress.
But a certificate is not a security strategy. It is a point-in-time statement about a defined set of controls.
Cyber Essentials gives business owners a practical starting point. It asks whether devices are supported, whether users have MFA, whether malware protection is in place, whether firewalls are configured and whether people have more access than they need.
Those are good questions. A lot of real incidents still begin with basics that were missed, delayed or assumed.
The scheme is built around five control areas: firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. If those five are genuinely in place across every in-scope device, a large share of commodity attacks — the automated, indiscriminate kind that make up most of the threat — simply stop working against you. That is real value, and it is why insurers, supply chains and government contracts increasingly ask for the certificate.
It also comes in two levels. Standard Cyber Essentials is a verified self-assessment; Cyber Essentials Plus covers the same controls but adds an independent technical audit, where an assessor actually tests a sample of your devices. If a customer or insurer is leaning on you for assurance, Plus is what carries the weight — because someone other than you has checked.
Cyber Essentials does not prove that your Microsoft 365 tenant is well governed, your backups are recoverable, your alerts are reviewed, your incident plan works, your suppliers are controlled or your staff know what to do when something looks wrong.
It also does not remove the need for judgement. A business can technically answer a question and still have a weak operational setup.
Cyber Essentials is a point-in-time statement, and the point in time passes quickly. New starters join, devices get replaced, someone spins up a trial of a new cloud app, an admin makes a “temporary” change that becomes permanent. Six months after certification, the honest question is not “are we certified?” but “would we still pass this afternoon?”
Businesses that treat the certificate as an annual event tend to rediscover the same gaps every year — usually in a rush, usually at renewal. Businesses that treat the controls as their normal operating standard barely notice renewal at all, because nothing has been allowed to drift.
It helps to be concrete about the boundary. A certified business can still lose money to payment-redirection fraud, because Cyber Essentials checks technical controls, not whether your finance team verifies changed bank details by phone. It can still be taken offline by ransomware it cannot recover from, because the scheme does not require backups at all — let alone isolated, tested ones. It can still have a compromised mailbox quietly forwarding invoices for weeks, because nobody was required to monitor sign-in activity or review alerts.
None of that is a criticism of the scheme — it was never designed to cover those things. It is a criticism of treating the certificate as if it were a security strategy.
For most SMEs, the next layer is practical resilience: Conditional Access, app consent controls, endpoint monitoring, backup isolation, restore testing, admin account governance, email authentication, incident readiness and clear ownership of systems.
Regulated or higher-risk organisations may also need evidence, policy, control mapping and support for frameworks such as ISO 27001, PCI DSS or sector-specific requirements.
The healthiest approach is to treat Cyber Essentials as part of normal IT management. Keep devices current, review access, maintain secure defaults and gather evidence as you go. That way certification becomes a checkpoint, not a once-a-year panic.
The certificate matters. The operating standard behind it matters more.
NorthMSP builds Cyber Essentials readiness into secure onboarding, then keeps improving the underlying controls. Read about secure onboarding or our Secure and Assured cybersecurity tiers.
We’ll review the controls behind the certificate — monitoring, backups, access, incident readiness — and tell you plainly where the gaps are.