cyber essentials for smes

A dental practice holding patient records and a two-partner solicitors’ firm handling client funds have more in common than either would guess. From an attacker’s point of view, both are worth breaking into, and neither has a security team watching for it. Cyber Essentials for SMEs exist for that exact gap. It’s a UK Government-backed scheme that gets small businesses to a proven baseline, and the businesses skipping it are rarely the ones with nothing worth stealing. They are usually the ones an attacker has already worked out are the easier route in.

Does a Small Business Need Cyber Essentials Certification?

Need is the wrong word to start with. Worth doing is closer. Forty six per cent of UK small businesses reported a cyber breach or attack in the last twelve months, according to the government’s own Cyber Security Breaches Survey 2025/2026, a figure that has crept back up after two years of gradual improvement. Attackers don’t target small businesses despite their size. They target them because of it. A dental practice with patient records and a solicitors’ firm with client account access carry real data behind comparatively thin defences, and that gap between value and protection is exactly what gets exploited.

Cyber Essentials for SMEs closes a specific part of that gap. Five controls sit at the centre of it, firewalls, secure configuration, access control, malware protection and security updates, the same five the National Cyber Security Centre says would prevent the vast majority of the opportunistic attacks small businesses actually face. Not a nation-state operation. The standard automated scan that finds an unpatched system or an open port and walks straight in.

Is Cyber Essentials a Legal Requirement?

Not for every business, no, and that catches some owners out into assuming it doesn’t apply to them at all. Certification is mandatory for a specific slice of government contracts, including work that touches personal data for departments like the MOD. Outside that world, no law forces a small business to hold it.

What’s changed is who asks for it anyway. Insurers increasingly price it into premiums. Larger clients build it into supplier onboarding as a box that has to be ticked before a contract gets signed, whether or not any law requires it. A legal requirement and a practical one end up looking almost identical from where a small business owner is standing.

Can You Self-Certify Cyber Essentials?

Not quite, and the word self-assessment causes more confusion here than it should. A business completes the questionnaire itself, answering detailed questions about its firewalls, its patching, its access controls. That part is self-assessed. What happens next isn’t. An independent certifying body checks the answers hold together before issuing anything, and inconsistent or implausible answers get challenged rather than waved through.

Cyber Essentials Plus removes even that ambiguity, since a qualified assessor tests the actual systems directly rather than relying on the questionnaire at all. Standard Cyber Essentials sits in the middle. Self-reported, but independently checked, which is a meaningfully different thing to filling in a form and printing a certificate.

Is Cyber Essentials Expensive for Small Businesses?

Not by the standards of what a breach actually costs. Standard Cyber Essentials certification typically runs between £300 and £500 for most small businesses, covering the assessment fee itself. That’s the number most owners fixate on, and it’s genuinely the smaller part of the equation.

Remediation is where the real cost sits, and it varies enormously depending on how far the current setup sits from the five controls already. A business that has kept firewalls and patching reasonably current might get through for close to the assessment fee alone. One running years-old software with no real access control policy is looking at proper remediation work first, and that isn’t really a Cyber Essentials cost. It was always going to turn up eventually. Certification just surfaces it earlier, and on a considerably smaller bill than a breach would.

Does Cyber Essentials Replace Cyber Security Services?

No, and treating it as the finish line is the single most common mistake that follows certification. Cyber Essentials proves five technical controls were in place on the day of assessment. It says nothing about the phishing email that gets through eleven months later, the member of staff who clicks the wrong link, or what happens to the practice in the hours after a breach actually lands.

The NCSC’s own guidance puts the five controls at preventing roughly 80% of commodity attacks, which leaves a meaningful gap that technical controls alone were never going to close. That’s what a dedicated cyber security service is for, staff training, ongoing monitoring, and an incident response plan that decides whether a breach is a bad afternoon or an actual crisis. Cyber security for SMEs starts with Cyber Essentials. It doesn’t end there.

What Counts as a Small Business Here?

There’s no headcount cut-off on the certificate itself. A two-partner solicitors’ practice and a fifty-person dental group both qualify for Cyber Essentials, and both get assessed against the same five controls, priced against the number of devices and users involved rather than a fixed small business bracket. The scheme was built with organisations this size specifically in mind, not scaled down from an enterprise standard as an afterthought.

That matters because plenty of small business owners assume Cyber Essentials is built for somebody bigger and put it off as a result. Cyber essentials for small businesses is not a smaller version of something else. It’s the version most small businesses actually need.

Whether the practice, firm or clinic in question has never looked at Cyber Essentials or is trying to work out if it is legally required, self-certified, or worth the cost, that’s the exact conversation Lift Off IT has with small businesses across several sectors each week. Our Cyber Essentials certification service covers the whole journey from first assessment to renewal, and our complete guide to Cyber Essentials certification in Liverpool breaks down the process in more detail. Get in touch to find out where the business currently stands against the five controls, or book a free review before the next attack finds out first.

Contact Us