Cyber Essentials Certification Services

Cyber Essentials is the UK Government-backed certification scheme, owned by the National Cyber Security Centre (NCSC) and delivered by IASME, that verifies your organisation has five fundamental technical controls in place against the most common internet-based attacks.

RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services, backed by the same CREST-accredited security team that delivers our penetration testing, PCI DSS and ISO 27001 work.

Unlike box-ticking providers, we approach Cyber Essentials as security engineers: we help you scope honestly, fix real gaps, and pass the assessment under the current Danzell (v3.3) requirements first time.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Register Your Interest

Tell us about your organisation and we’ll contact you the day our Cyber Essentials service goes live. No obligation.

You’ll get our Danzell readiness checklist by reply, and one email when we launch. No mailing lists, ever.

Launching Soon RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Register your interest for priority assessment slots at launch and our free Danzell readiness checklist now.
UK-based CREST member · Danzell (v3.3) ready · Assessor-grade pre-review · Same-day scoping response · Renewal reminders included
Who this is for

This page is for you if you’re..

1
Bidding for UK contracts
Suppliers to central government, MOD or NHS supply chains where Cyber Essentials is a mandatory procurement requirement.
2
First-time certification
SMEs certifying for the first time who want to pass under the tougher 2026 (Danzell) rules without failed submissions.
3
Insurance & assurance
Organisations that want a recognised baseline, plus the included £25,000 cyber liability insurance for eligible UK businesses.

Cyber Essentials, Quick Facts

Last reviewed: 2026-07-21
Scheme owner
UK National Cyber Security Centre (NCSC); delivered by IASME through licensed Certification Bodies
Current requirements
Requirements for IT Infrastructure v3.3, assessed via the Danzell question set (from 27 April 2026)
The five controls
Firewalls, secure configuration, security update management, user access control, malware protection
Official assessment fee
Micro (0–9 staff) £320 + VAT · Small (10–49) £440 + VAT · Medium (50–249) £500 + VAT · Large (250+) £600 + VAT
Validity
12 months; annual recertification required to stay on the NCSC certified-organisations register
Included insurance
£25,000 cyber liability cover for UK organisations under £20m turnover certifying their whole organisation
5
Technical controls assessed
Danzell v3.3
Current question set (2026)
12 months
Certificate validity
From £320
Official IASME fee + VAT

What is Cyber Essentials?

Cyber Essentials is a verified self-assessment: your organisation answers the Danzell question set covering the five technical controls, a board member or equivalent signs the declaration, and a licensed assessor reviews and verifies the responses. It is deliberately scoped at the fundamentals, the controls that stop the commodity attacks responsible for the majority of breaches affecting UK SMEs.

The 2026 update raised the bar considerably. Multi-factor authentication is now mandatory on all cloud services where it is available, and failing to apply high or critical security updates within 14 days is now an automatic failure rather than a discretionary mark-down. Scope definitions were also tightened, so remote workers, BYOD devices used for work data, and cloud services can no longer be quietly excluded.

What Cyber Essentials certification gives you:
Eligibility for UK government, MOD and public-sector contracts that mandate it
A recognised, independently verified security baseline for customer due diligence
£25,000 cyber liability insurance included for eligible UK organisations
Demonstrable protection against the most common internet-borne attacks
A fast, affordable credential you can achieve in days rather than months
A sensible first rung before Cyber Essentials Plus and ISO 27001

For most UK SMEs, Cyber Essentials is the fastest and cheapest way to turn good security hygiene into a credential that procurement teams and insurers actually recognise.

Why organisations fail in 2026

Pass rates have tightened since the Danzell question set introduced automatic failure conditions. Most failures are avoidable, they come from misunderstanding scope or answering aspirationally rather than accurately. An assessor cannot pass an answer that describes what you intend to do; only what is true on the day you submit.

Because our team audits infrastructure for a living, we review your draft answers the way an assessor will read them, and tell you exactly what to fix before you submit, not after a failed attempt.

The most common reasons submissions fail:
MFA not enabled on every in-scope cloud service, now an automatic failure
Unsupported operating systems or software still in scope (e.g. old Windows versions)
High/critical updates not applied within 14 days across all in-scope devices
Remote worker and BYOD devices wrongly excluded from scope
Business social media accounts missing from the cloud service list, now explicitly in scope
Admin accounts used for day-to-day work, breaching account separation rules

Every failed submission costs time, and under the 2026 marking rules, some gaps mean an outright fail rather than a chance to clarify. Preparation is where certification is won.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

The five controls of Cyber Essentials

Every Cyber Essentials requirement hangs off these five technical controls. They are unchanged in the 2026 update, what changed is how strictly two of them are marked.

1
Firewalls
Every in-scope device sits behind a correctly configured boundary firewall, or, for remote workers, a properly configured software firewall on the device itself. Default administrative passwords changed, management interfaces protected.
2
Secure configuration
Default passwords changed everywhere, unused accounts and software removed, autorun disabled, and device locking (PIN/password/biometric) enforced on anything that touches organisational data.
3
Security update management
Only supported software in scope, updates enabled, and high or critical fixes applied within 14 days of release. Under Danzell (v3.3) this is now an automatic-failure condition, not a discretionary one.
4
User access control
Individual accounts per user, access granted on business need, separate accounts for administrative tasks, and multi-factor authentication on cloud services, the second Danzell automatic failure if missing where available.
5
Malware protection
Approved anti-malware active and current on all in-scope devices, or an approved alternative mechanism such as application allow-listing. Verified per device type, not assumed.

Be First in Line for Our Cyber Essentials Launch

Register your interest today. We’ll review your readiness against the Danzell (v3.3) requirements and contact you the day our certification service goes live.

Frequently Asked Questions

If your controls are already in place, the self-assessment can be completed in a few days and most assessments are turned around within a few working days of submission. Add remediation time if gaps exist, typically 2–6 weeks for a small business fixing MFA, patching and account separation issues. You have 6 months from purchase to complete the assessment.

The assessment fee is set by IASME and is the same through every Certification Body: £320 + VAT (0–9 employees), £440 + VAT (10–49), £500 + VAT (50–249), £600 + VAT (250+). Budget separately for any remediation and for optional guided support. See our Cyber Essentials cost guide for a full breakdown.

From 27 April 2026, assessments use the Danzell question set under Requirements v3.3. Key changes: MFA is mandatory on all cloud services where available (automatic failure if not), missing 14-day high/critical patching is an automatic failure, the definition of cloud services was clarified, and scoping rules for remote workers and BYOD were tightened.

It is not a legal requirement, but it is contractually mandatory for many UK central government contracts involving personal or sensitive data, and across large parts of the MOD supply chain. Increasingly, private-sector customers and insurers also request it as a minimum baseline.

Cyber Essentials is a verified self-assessment. Cyber Essentials Plus covers the same five controls but adds an independent technical audit: vulnerability scans and hands-on testing of a sample of your devices by an assessor. Plus must be achieved within 3 months of passing the basic assessment.

Yes. The 2026 (v3.3) definition of a cloud service is broad and explicit: if a subscribed service stores or processes organisational data and is accessed via an account, it is in scope, and that includes business social media accounts such as LinkedIn, Facebook and Instagram. Each needs to be on your asset list, with MFA enabled where the platform offers it and individual (not shared) logins.
📞 Call us Book a call