Cyber Essentials Certification Services

Cyber Essentials is the UK Government-backed certification scheme, owned by the National Cyber Security Centre (NCSC) and delivered by IASME, that verifies your organisation has five fundamental technical controls in place against the most common internet-based attacks.

RedSecLabs is an IASME-licensed Certification Body for Cyber Essentials, with Plus assessments launching soon, backed by the same CREST-accredited security team that delivers our penetration testing, PCI DSS and ISO 27001 work.

Unlike box-ticking providers, we approach Cyber Essentials as security engineers: we help you scope honestly, fix real gaps, and pass the assessment under the current Danzell (v3.3) requirements first time.

CREST Member Company Cyber Essentials Certification Body PCI SSC Qualified Security Assessor (QSA) Company ISO 27001 Certified UKAS Accredited Certification

Get a Fixed-Fee Quote

Tell us about your organisation and we’ll come back with a fixed-fee quote and readiness view the same business day. No obligation.

We reply within one business day with next steps. Your details are used only to scope your enquiry, never shared or sold.

You’ll get our Danzell readiness checklist by reply. No mailing lists, ever.

Certification Body RedSecLabs is an IASME-licensed Certification Body for Cyber Essentials. Cyber Essentials Plus assessments launching soon. Start My Certification or request our free Danzell readiness checklist.
IASME Certification Body · UK-based CREST member · Danzell (v3.3) ready · Assessor-grade pre-review · Same-day scoping response · Renewal reminders included
Who this is for

This page is for you if you’re..

1
Bidding for UK contracts
Suppliers to central government, MOD or NHS supply chains where Cyber Essentials is a mandatory procurement requirement.
2
First-time certification
SMEs certifying for the first time who want to pass under the tougher 2026 (Danzell) rules without failed submissions.
3
Insurance & assurance
Organisations that want a recognised baseline, plus the included £25,000 cyber liability insurance for eligible UK businesses.

Cyber Essentials, Quick Facts

Last reviewed: 2026-07-21
Scheme owner
UK National Cyber Security Centre (NCSC); delivered by IASME through licensed Certification Bodies
Current requirements
Requirements for IT Infrastructure v3.3, assessed via the Danzell question set (from 27 April 2026)
The five controls
Firewalls, secure configuration, security update management, user access control, malware protection
Official assessment fee
Micro (0–9 staff) £320 + VAT · Small (10–49) £440 + VAT · Medium (50–249) £500 + VAT · Large (250+) £600 + VAT
Validity
12 months; annual recertification required to stay on the NCSC certified-organisations register
Included insurance
£25,000 cyber liability cover for UK organisations under £20m turnover certifying their whole organisation
5
Technical controls assessed
Danzell v3.3
Current question set (2026)
12 months
Certificate validity
From £320
Official IASME fee + VAT

What is Cyber Essentials?

Cyber Essentials is a verified self-assessment: your organisation answers the Danzell question set covering the five technical controls, a board member or equivalent signs the declaration, and a licensed assessor reviews and verifies the responses. It is deliberately scoped at the fundamentals, the controls that stop the commodity attacks responsible for the majority of breaches affecting UK SMEs.

The 2026 update raised the bar considerably. Multi-factor authentication is now mandatory on all cloud services where it is available, and failing to apply high or critical security updates within 14 days is now an automatic failure rather than a discretionary mark-down. Scope definitions were also tightened, so remote workers, BYOD devices used for work data, and cloud services can no longer be quietly excluded.

What Cyber Essentials certification gives you:
Eligibility for UK government, MOD and public-sector contracts that mandate it
A recognised, independently verified security baseline for customer due diligence
£25,000 cyber liability insurance included for eligible UK organisations
Demonstrable protection against the most common internet-borne attacks
A fast, affordable credential you can achieve in days rather than months
A sensible first rung before Cyber Essentials Plus and ISO 27001

For most UK SMEs, Cyber Essentials is the fastest and cheapest way to turn good security hygiene into a credential that procurement teams and insurers actually recognise.

Why organisations fail in 2026

Pass rates have tightened since the Danzell question set introduced automatic failure conditions. Most failures are avoidable, they come from misunderstanding scope or answering aspirationally rather than accurately. An assessor cannot pass an answer that describes what you intend to do; only what is true on the day you submit.

Because our team audits infrastructure for a living, we review your draft answers the way an assessor will read them, and tell you exactly what to fix before you submit, not after a failed attempt.

The most common reasons submissions fail:
MFA not enabled on every in-scope cloud service, now an automatic failure
Unsupported operating systems or software still in scope (e.g. old Windows versions)
High/critical updates not applied within 14 days across all in-scope devices
Remote worker and BYOD devices wrongly excluded from scope
Business social media accounts missing from the cloud service list, now explicitly in scope
Admin accounts used for day-to-day work, breaching account separation rules

Every failed submission costs time, and under the 2026 marking rules, some gaps mean an outright fail rather than a chance to clarify. Preparation is where certification is won.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Start My Certification

The five controls of Cyber Essentials

Every Cyber Essentials requirement hangs off these five technical controls. They are unchanged in the 2026 update, what changed is how strictly two of them are marked.

1
Firewalls
Every in-scope device sits behind a correctly configured boundary firewall, or, for remote workers, a properly configured software firewall on the device itself. Default administrative passwords changed, management interfaces protected.
2
Secure configuration
Default passwords changed everywhere, unused accounts and software removed, autorun disabled, and device locking (PIN/password/biometric) enforced on anything that touches organisational data.
3
Security update management
Only supported software in scope, updates enabled, and high or critical fixes applied within 14 days of release. Under Danzell (v3.3) this is now an automatic-failure condition, not a discretionary one.
4
User access control
Individual accounts per user, access granted on business need, separate accounts for administrative tasks, and multi-factor authentication on cloud services, the second Danzell automatic failure if missing where available.
5
Malware protection
Approved anti-malware active and current on all in-scope devices, or an approved alternative mechanism such as application allow-listing. Verified per device type, not assumed.

Start My Certification

Request a quote today. We’ll review your readiness against the Danzell (v3.3) requirements and book your assessment slot.

How certification works

A guided path from first call to certificate, with a senior assessor on hand at every step, not a portal login and silence.

1
Scope and register
Tell us your organisation size and setup. We confirm scope, give you a fixed fee, and set up your assessment against the current Danzell question set.
2
Guided self-assessment
You complete the questionnaire with our assessors on hand. We interpret every requirement, flag gaps early (MFA, patching, device scope) and get you submission-ready.
3
Verified and certified
Your assessor reviews, you fix anything outstanding, and your certificate is issued, with £25,000 cyber insurance for eligible UK organisations included.
Download the Danzell 2026 question set →

Choose your route

Three ways to certify, priced fixed before you commit. Official IASME fees apply at every route; the difference is how much of the work we take off your plate.

Certify now
You answer the question set, our assessor reviews and certifies. The fast, lean route when your controls are already in shape.
  • Official IASME fee only (£320–£600 +VAT by size)
  • Assessor review with a free re-submission window
  • £25,000 cyber liability insurance for eligible UK organisations*
  • Certificate and badge, valid 12 months
Start My Certification
MOST CHOSEN
Certify + get Plus-ready
We prepare your answers with you, close the gaps, certify the basic level, and run Plus readiness on your device sample, so the Plus audit is a formality when you take it.
  • Everything in Certify now
  • Gap review before you submit: most clients pass first time
  • Plus readiness on a real device sample
  • First in the queue when our Plus assessment slots open
Start My Certification
Certified, every year
Certification plus renewal handled annually: we track question-set changes (Danzell from April 2026), re-check what moved, and recertify you without the yearly scramble.
  • Everything in Certify now
  • Question-set change tracking between cycles
  • Renewal reminder and re-assessment managed for you
  • Insurance benefit renewed with each certificate*
Set up annual cover

*Scheme benefit arranged by IASME, not by RedSecLabs: UK or Crown Dependencies organisations under £20m turnover, certifying the whole organisation, opt-in during assessment.

Four questions to ask any certification body
1) Will a named assessor review my answers, or a portal? 2) If something fails, is remediation guidance included or a paid “recovery” service? 3) Is the quoted price the whole price? 4) Who answers the phone mid-assessment? Our answers: a named IASME assessor, included, yes, and the assessor working your file.

Transparent pricing by organisation size

The figures below are the official IASME certification fees. Our guidance is quoted separately and fixed up front, so the number you approve is the number you pay.

Organisation sizeCertification feeTypical timeline
1 – 9 employees£320 + VATDays once ready
10 – 49 employees£440 + VATDays once ready
50 – 249 employees£500 + VAT1 – 2 weeks with guidance
250+ employees£600 + VATScoped to your estate

Cyber Essentials Plus is priced separately once basic certification is in place. Readiness consultancy is available now; independent Plus assessments are launching soon, and retainer clients get first place in the queue.

What happens after you get in touch
1
Same-day scoping call
Fifteen minutes to confirm organisation size, scope and the right route. Fixed quote follows the same business day.
2
Prepare and submit
Working document first, portal second. Your assessor flags weak answers before submission, not after a fail.
3
Certified
Pass verdict, certificate, badge, insurance opt-in confirmed. Plus-readiness clients book the audit window immediately.

Frequently Asked Questions

If your controls are already in place, the self-assessment can be completed in a few days and most assessments are turned around within a few working days of submission. Add remediation time if gaps exist, typically 2 to 6 weeks for a small business fixing MFA, patching and account separation issues. You have 6 months from purchase to complete the assessment.

The assessment fee is set by IASME and is the same through every Certification Body: £320 + VAT (0 to 9 employees), £440 + VAT (10 to 49), £500 + VAT (50 to 249), £600 + VAT (250+). Budget separately for any remediation and for optional guided support. See our Cyber Essentials cost guide for a full breakdown.

From 27 April 2026, assessments use the Danzell question set under Requirements v3.3. Key changes: MFA is mandatory on all cloud services where available (automatic failure if not), missing 14-day high/critical patching is an automatic failure, the definition of cloud services was clarified, and scoping rules for remote workers and BYOD were tightened.

It is not a legal requirement, but it is contractually mandatory for many UK central government contracts involving personal or sensitive data, and across large parts of the MOD supply chain. Increasingly, private-sector customers and insurers also request it as a minimum baseline.

Cyber Essentials is a verified self-assessment. Cyber Essentials Plus covers the same five controls but adds an independent technical audit: vulnerability scans and hands-on testing of a sample of your devices by an assessor. Plus must be achieved within 3 months of passing the basic assessment.

Yes. The 2026 (v3.3) definition of a cloud service is broad and explicit: if a subscribed service stores or processes organisational data and is accessed via an account, it is in scope, and that includes business social media accounts such as LinkedIn, Facebook and Instagram. Each needs to be on your asset list, with MFA enabled where the platform offers it and individual (not shared) logins.
📞 Call us Book a call