Cyber Essentials in a week: the SMB fast-path
Cyber Essentials has a reputation problem. Small companies hear “certification” and picture a six-month programme, a consultant on a retainer, and a binder of policies nobody reads. So they put it off - right up until an enterprise customer, an insurer, or a UK public-sector tender makes it a hard requirement, and suddenly it’s blocking a deal.
Here is the reframe: Cyber Essentials is five technical controls and a self-assessment questionnaire. It is deliberately designed by the UK’s National Cyber Security Centre to be achievable by a small organisation without a security team. For most SMBs that already run a reasonably tidy IT estate, the honest timeline to ready is about a week - most of which is checking and tightening things you already have, not building anything new.
This post is the fast-path. It is not a substitute for the official NCSC requirements document - read that too - but it will tell you what the week actually looks like and where people lose time.
The five controls, in plain English
Everything in Cyber Essentials maps to five technical control themes. If you understand these, you understand the whole scheme:
- Firewalls. Every device that connects to the internet sits behind a correctly configured firewall - your office boundary firewall and the software firewall on laptops that leave it. Default passwords changed, no unnecessary inbound holes.
- Secure configuration. Devices and software are set up to reduce their attack surface: remove or disable what you don’t use, change default credentials, don’t run unnecessary services or accounts.
- Security update management. Everything - operating systems, applications, firmware - is supported by its vendor and patched promptly. High/critical security updates applied within 14 days is the benchmark. Unsupported software is removed or taken out of scope.
- User access control. People have accounts with only the access they need; administrator privileges are controlled, separate from day-to-day accounts, and removed when someone leaves; multi-factor authentication is in place, especially for cloud services and admin.
- Malware protection. Anti-malware on devices, or an equivalent approach (allow-listing, or the built-in protections on a well-configured mobile OS).
That is the entire technical bar. None of it is exotic. The work is proving each one is true across your whole in-scope estate - and scope is where the week is won or lost.
Day 0: get scope right (this is the part people rush)
Before touching a single control, define what’s in scope. Cyber Essentials covers your whole organisation by default, or a clearly segmented sub-part. In scope: all devices that connect to the internet and access organisational data or services - laptops, desktops, servers, mobile phones, tablets, and the cloud services you use (IaaS, PaaS, SaaS all count).
This is where small companies quietly fail, and it’s the same failure that hurts them in a breach: the asset you forgot you own. The laptop of the contractor who left. The old VPS still running a demo. The SaaS admin account nobody deprovisioned. The self-assessment asks you to attest to controls across everything - so an accurate inventory of your internet-facing estate is the real Day 0 task. If you can’t list it, you can’t certify it, and you certainly can’t defend it.
The week, day by day
This assumes a small company with a mostly-cloud, laptop-based estate. Adjust for your reality.
- Day 1 - Inventory and scope. List every device and cloud service. Decide what’s in scope. Identify anything unsupported or forgotten - that’s your remediation list.
- Day 2 - Access and MFA. Turn on MFA everywhere it isn’t (email, cloud consoles, admin panels). Separate admin accounts from daily-driver accounts. Remove leavers and unused accounts. This is usually the highest-impact day for real security, not just the certificate.
- Day 3 - Patching and configuration. Confirm automatic updates are on and devices are current. Enable device firewalls. Remove or replace unsupported software (an out-of-support OS will fail you outright). Change any lingering default credentials.
- Day 4 - Malware and boundary. Verify anti-malware / built-in protections on every device. Check your firewall config - no default admin passwords, no unnecessary inbound rules.
- Day 5 - Fill in the questionnaire. Work through the self-assessment. Because you did the legwork, most answers are now “yes, and here’s how.” Flag anything you couldn’t fully close.
- Buffer - Remediate the gaps. Realistically you’ll find one or two things on Day 5 that need a fix before you can honestly answer “yes.” That’s the buffer. Don’t fudge the answers; a self-assessment you lied on is worse than no certificate.
Then it’s submitted to a certification body for review. Important honesty note: the certificate is issued by an accredited certification body, not by a readiness partner - that independence is the entire point of a certificate. We (or anyone doing readiness) get you ready; the certification body certifies. Anyone claiming to “issue” you Cyber Essentials directly is selling something else.
Cyber Essentials vs. Cyber Essentials Plus
Standard Cyber Essentials is the self-assessment above, verified by a certification body. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit - an assessor independently tests a sample of your devices and your defences rather than taking your word for it. CE Plus is usually done shortly after CE, on the same controls, so getting CE right is the groundwork for CE Plus either way. If a customer or tender specifies “Plus,” plan for the extra assessment step; the readiness work is the same work.
Why CE is often the right first certificate
For a UK SMB, Cyber Essentials is frequently the cheapest, fastest certificate that unblocks a deal - and it’s a genuine security floor, not just a badge. Those five controls, honestly implemented, stop a large share of the opportunistic, automated attacks that make up the internet’s background noise. It’s also a clean on-ramp: the discipline you build for CE - accurate asset inventory, patched systems, controlled access - is the same discipline that ISO 27001, SOC 2, and NIS2 all ask for at greater depth. Start here, and the next certificate is less of a leap.
The part that decays after certification
One honest caveat, because it’s the thing the annual-certificate model gets wrong: Cyber Essentials is a point in time. You attest that the controls are in place today. Tomorrow you onboard a new starter, spin up a new cloud service, or a critical patch drops and the 14-day clock starts. The certificate on the wall doesn’t know about any of it.
That’s the gap continuous monitoring fills - not to pass the audit, but to keep the thing the audit measured actually true between certificates. Your asset inventory stays current because something is discovering new exposure as it appears; your patch posture stays honest because something is checking. The certificate proves you were ready in week one. Staying ready is a different, ongoing job.
Getting Cyber Essentials ready and want a straight answer on scope and gaps - or a way to keep the controls honest after you’re certified? A 30-minute scoping call is the fastest way to find out where you stand. See what’s exposed.
Get new posts by email
Security engineering, compliance without theatre, open-source threat intel. No tracking, no forwarding your address, unsubscribe in one click.