For a typical small business running Microsoft 365 or Google Workspace on modern laptops, Cyber Essentials rarely requires buying anything new. The work is configuration: enforcing MFA everywhere, turning on automatic updates and verifying they apply within 14 days, removing admin rights from daily-use accounts, checking firewall settings, and confirming malware protection is active on every device.
The harder part for SMEs is scope honesty under the 2026 rules. The personal laptop a director uses for email, the phone that syncs work files, the contractor with a company login, all in scope. Getting scope right up front is the difference between a smooth pass and a failed submission.
Do those six things and you have covered the majority of what the Danzell question set will ask, and materially cut your real-world breach risk at the same time.
Most SMEs delay certification for the same reasons: it looks like bureaucracy, nobody owns it internally, and the questionnaire language feels written for IT departments. Meanwhile, tenders pass by, supplier questionnaires get harder to answer, and the business carries risk the five controls would have removed.
The irony is that for a 15-person business, the whole process, done properly, is usually days of effort spread over a few weeks. The certificate then does its job all year: shortening due diligence, satisfying procurement, and backing your insurance position.
The worst time to start Cyber Essentials is the week a contract requires it. The best time is before you need it, while remediation can happen calmly.
Work through these in order over a fortnight, most SMEs need nothing beyond built-in tools and admin-console settings.
Register your interest and we’ll send you our SME readiness checklist for the 2026 rules, then contact you the day our certification service launches.