Cyber Essentials for SMEs

Cyber Essentials was designed with small and medium-sized businesses in mind: five practical controls, a fixed low fee, and a certificate that opens government contract doors and reassures customers, without the overhead of a full ISO programme.

RedSecLabs is preparing to offer Cyber Essentials certification services built for SMEs without in-house IT security. We translate the Danzell question set into plain English, tell you exactly what to change in Microsoft 365 or Google Workspace, and review your answers before submission.

Most small businesses are closer to certification than they think, the gap is usually configuration, not spend.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Register Your Interest

Tell us about your organisation and we’ll contact you the day our Cyber Essentials service goes live. No obligation.

You’ll get our Danzell readiness checklist by reply, and one email when we launch. No mailing lists, ever.

Launching Soon RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Register your interest for priority assessment slots at launch and our free Danzell readiness checklist now.
Plain-English guidance · Microsoft 365 & Google Workspace expertise · Fixed IASME fee, from £320 + VAT · No jargon, no upsell pressure · Renewal reminders included
Who this is for

This page is for you if you’re..

1
1–50 employees
Micro and small businesses certifying for the first time, often with outsourced or part-time IT support.
2
Winning bigger clients
SMEs asked for Cyber Essentials in supplier questionnaires from enterprise or public-sector customers.
3
No security team
Owner-managed businesses that need someone to translate the requirements into a to-do list.

Cyber Essentials for SMEs, Quick Facts

Last reviewed: 2026-07-21
Fee for most SMEs
£320 + VAT (0–9 staff) or £440 + VAT (10–49 staff), set by IASME, identical via every Certification Body
Typical timeline
1–2 weeks if controls are in place; 4–8 weeks including remediation for a typical first-timer
Biggest 2026 change
MFA now mandatory on all cloud services where available, an automatic failure if missing
What's usually in scope
Laptops/desktops, mobile devices accessing work data, firewalls/routers, and cloud services like Microsoft 365
Included insurance
£25,000 cyber liability cover for eligible UK organisations under £20m turnover
Renewal
Annual; lapsed certificates are removed from the NCSC register
£320+
IASME fee for micro businesses (+VAT)
5
Controls, all achievable with built-in tools
80%+
Of common attacks mitigated by the five controls, per NCSC
12 months
Certificate validity

What SMEs actually need to do

For a typical small business running Microsoft 365 or Google Workspace on modern laptops, Cyber Essentials rarely requires buying anything new. The work is configuration: enforcing MFA everywhere, turning on automatic updates and verifying they apply within 14 days, removing admin rights from daily-use accounts, checking firewall settings, and confirming malware protection is active on every device.

The harder part for SMEs is scope honesty under the 2026 rules. The personal laptop a director uses for email, the phone that syncs work files, the contractor with a company login, all in scope. Getting scope right up front is the difference between a smooth pass and a failed submission.

Quick wins for most SMEs before applying:
Enforce MFA on Microsoft 365 / Google Workspace for every user, no exceptions
Turn on automatic updates for operating systems and browsers, and verify compliance
Create separate admin accounts; strip admin rights from everyday logins
Retire or isolate anything running unsupported software
List every cloud service holding company data, the 2026 definition is broad
Set a screen-lock, password and account-removal policy and actually apply it

Do those six things and you have covered the majority of what the Danzell question set will ask, and materially cut your real-world breach risk at the same time.

Why SMEs put it off, and why that costs them

Most SMEs delay certification for the same reasons: it looks like bureaucracy, nobody owns it internally, and the questionnaire language feels written for IT departments. Meanwhile, tenders pass by, supplier questionnaires get harder to answer, and the business carries risk the five controls would have removed.

The irony is that for a 15-person business, the whole process, done properly, is usually days of effort spread over a few weeks. The certificate then does its job all year: shortening due diligence, satisfying procurement, and backing your insurance position.

What delaying certification typically costs SMEs:
Exclusion from government and MOD supply-chain tenders that mandate certification
Lost enterprise deals where security questionnaires stall the sale
Higher cyber insurance friction, more questions, worse terms
No independent baseline when a customer asks “how do we know you're secure?”
Exposure to the commodity attacks the five controls are designed to stop
A rushed, error-prone application when a contract suddenly demands it

The worst time to start Cyber Essentials is the week a contract requires it. The best time is before you need it, while remediation can happen calmly.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

The small-business Cyber Essentials checklist

Work through these in order over a fortnight, most SMEs need nothing beyond built-in tools and admin-console settings.

1
Week 1: inventory
List every laptop, desktop and phone that touches work data (including personal ones), your router/firewall, and every cloud service, check billing records and password managers so nothing is missed, including business social media accounts, which are in scope under the 2026 rules.
2
Week 1: kill the auto-fails
Enforce MFA on every cloud service that supports it, and confirm every device runs supported software with automatic updates on. These two are automatic failures under Danzell, clear them before anything else.
3
Week 2: accounts and access
Individual logins for everyone (no shared accounts), admin rights moved to separate admin-only accounts, leavers removed, and screen locks with PINs/passwords enforced on all devices.
4
Week 2: configuration sweep
Change any default passwords (router especially), uninstall software nobody uses, confirm malware protection is on and updating on every device, and enable device encryption where available.
5
Submit with confidence
Download the free Danzell question set, draft answers describing what is now true, have whoever runs your IT sanity-check them, brief the director signing the declaration, then purchase and submit.

SME-Friendly Cyber Essentials, Coming Soon

Register your interest and we’ll send you our SME readiness checklist for the 2026 rules, then contact you the day our certification service launches.

Frequently Asked Questions

Usually yes. The fee for a micro business is £320 + VAT, the five controls materially reduce the most common attack risks, eligible businesses get £25,000 of cyber liability insurance included, and a growing share of customers and public-sector buyers expect it. Few security investments return more per pound at this size.

Broadly, yes: your laptops and desktops, mobile devices that access work email or files, your firewall/router, and cloud services including Microsoft 365 are in scope. Under the 2026 rules, BYOD devices used for work data and remote workers' setups count too.

Rarely. Most SME requirements are met with what you already have: built-in OS security features, Microsoft Defender or equivalent, and correct configuration of your cloud tenancy. The main exception is genuinely unsupported hardware or software, which must be replaced, isolated or removed from scope.

If your IT is reasonably modern: often 1–2 weeks. First-timers with gaps (MFA, patching, admin separation) typically need 4–8 weeks. You get 6 months from purchase to submit, so there's room to fix things properly.

They can do much of the technical remediation, but the questionnaire must accurately describe your organisation and a board member (or equivalent) must sign the declaration. We work alongside SME IT providers routinely, they fix, we verify readiness and guide the submission.

Under the current scheme you typically get the chance to correct minor issues within a short window; substantive failures (like missing MFA on cloud services under the 2026 rules) mean reapplying. Our pre-submission review exists precisely so you never find out about a gap from the assessor.
📞 Call us Book a call