Cyber Essentials, explained plainly
Straight answers to the questions organisations actually ask before certifying — written for people who have to sort this out alongside their real job, not for IT departments.
How to get Cyber Essentials, start to finish
The whole route in order: scope, inventory, fixing the gaps, the questionnaire, assessment and the certificate — with realistic timescales for a small organisation.
Read › 2026 rulesThe MFA auto-fail rule — one setting now fails everything
Since April 2026, missing MFA on any cloud service that offers it fails the whole assessment — plus the 14-day patching twin rule, what counts as a cloud service, and the platform fix list.
Read › 2026 rulesWindows 10 is a fail now — your real options
Support ended October 2025, so unsupported machines fail certification. The ten-minute fleet check, what Extended Security Updates buy, and the upgrade-or-replace maths.
Read › After a failFailed the assessment? What happens next
A fail is private and fixable, usually in weeks. What resubmission your body should include, the 2026 usual culprits, and the route back — without failing twice.
Read › ScopeServiced offices & co-working: whose firewall is it?
When you don't control the network, the boundary moves to the device. How to answer the firewall questions from a rented desk — and why co-working often certifies more easily.
Read › Choosing a providerHow to choose a certification body — the 7 checks
All 350+ bodies issue the identical certificate, so choose on service: published all-in pricing, turnaround in writing, resubmission policy, human help — and the red flags to walk from.
Read › For buyersCheck whether a company really holds Cyber Essentials
The official certificate search, free, in a minute — why certificates vanish after 12 months, how to read level, date and entity, and what to do when a supplier's cert has lapsed.
Read › CostHow much does Cyber Essentials cost?
The published fee bands, what remediation actually costs, Cyber Essentials Plus pricing, and the free cyber liability insurance most organisations do not realise they get.
Read › CostWhat Cyber Essentials Plus actually costs
Realistic figures for the hands-on audit, the four things that drive your price, the hidden cost of failing the test — and an honest framework for whether you need Plus at all.
Read › AssessmentWhy Cyber Essentials applications fail
Two answers now fail the whole assessment on their own. Plus the scoping, account and default-credential errors that catch small organisations out.
Read › Mid-assessmentStuck on the questionnaire?
How assessors read your answers, the questions people genuinely get stuck on, what to do when your setup doesn't fit the question — and why borrowed "model answers" backfire.
Read › StandardsIASME explained: Cyber Assurance vs Cyber Essentials
The body behind UK cyber certification, how its broader Cyber Assurance standard differs from Cyber Essentials, the two levels — and which your contract is really asking for.
Read › Free templateA cyber security policy you can copy today
Plain-English, aligned to the five Cyber Essentials controls on purpose. Copy it from the page, adapt the brackets, adopt it — and get the Word version free by email.
Read › Buying guideBuying cyber security services — without the fear-selling
What an MSP covers, where certification fits, what testing you genuinely need, the questions that expose weak providers — and the spending order that respects your budget.
Read › ScopeAre personal phones and home laptops in scope?
Scope follows the data, not who owns the device. What BYOD means for the assessment, the three legitimate ways to narrow scope, and what can never be excluded.
Read › ChoosingCyber Essentials or Cyber Essentials Plus?
What the Plus audit involves, the tighter sampling rules that closed the old workarounds, and how to plan backwards from a contract date.
Read › Before you submitThe details that bounce an application
Company name, registered office, entities and scope description — the administrative gate a submission has to clear before the security is even looked at.
Read › Before you applyScope: what’s in, what’s out
Every device and account that can reach your data is in — home laptops and personal phones included. Whole organisation versus a sub-set, and how to write the scope so it isn’t bounced.
Read › Before you applyThe Cyber Essentials checklist
All five controls on one screen, line by line, with the two auto-fail rules marked and the scope check that catches most failures before the questionnaire does.
Read › After you passThe Cyber Essentials logo: getting it and using it properly
Where the badge comes from, where you can use it, the twelve-month rule, what not to do with it, and how to make it prove itself to anyone checking.
Read › Included with a passThe free £25,000 insurance, and what it means for your premiums
Who qualifies for the included cyber liability cover, what it does and doesn't cover, and why underwriters now ask for the certificate.
Read › Which standardISO 27001 vs Cyber Essentials
Days versus months, hundreds versus tens of thousands, technical controls versus a management system — and the sensible order to do them in.
Read › Year twoRenewal: fresh rules, and no lock-in
Renewal is a fresh certification against a standard that has moved — the two traps that fail last year's passers, what it should cost, the six-week timeline, and why switching provider is trivially easy.
Read › SchoolsCyber Essentials for schools and trusts
The pupil device question, shared logins, MFA on the MIS and safeguarding systems, and how scope works across a multi-academy trust.
Read ›Not sure where you stand?
The readiness check runs through the requirements in a few minutes and tells you what would currently fail — before you commit to anything.
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Running a parish council or a charity? Our parent company publishes sector guides covering the same ground alongside the finance side — Cyber Essentials for parish councils, Cyber Essentials for charities, and more at Edwards Bros Insights.