Fifteen plain English questions covering all five Cyber Essentials technical controls. Answer honestly and get an instant breakdown of where you stand -- and what needs to change before you submit for formal certification.
This is an informal self-assessment, not the official IASME questionnaire. It does not represent, replace or guarantee the outcome of a formal Cyber Essentials assessment.
Please answer all three questions before continuing.
Cyber Essentials is built around five controls that address the most common ways organisations are compromised online. Certification requires all five to be in place, for all devices and users within your defined scope.
The full requirements document is published by IASME and covers every control in detail, including what counts as in-scope and what evidence assessors expect.
Cyber Essentials is a UK government-backed certification scheme managed by IASME on behalf of the NCSC. It covers five technical controls and is designed to protect organisations against the most common internet-based threats. There are two levels: Cyber Essentials (self-assessed with independent verification) and Cyber Essentials Plus (self-assessed plus an independent technical audit). More information is available from the NCSC.
Cyber Essentials requires you to complete a structured self-assessment questionnaire, signed off by a board-level signatory, which is then reviewed by an independent assessor. Cyber Essentials Plus includes everything in Cyber Essentials plus a hands-on technical audit where an independent assessor verifies that your controls are actually in place. You cannot go straight to Plus -- you need a current Cyber Essentials certificate first, and the Plus audit must be completed within three months of that certification date. Plus carries more weight with larger buyers and is required for some government contracts.
Cyber Essentials self-assessment fees start from £320 plus VAT for small organisations, with the cost scaling with organisation size. Cyber Essentials Plus costs more because it includes a technical audit. You may also pay for external support to prepare, which varies depending on how much remediation your environment needs.
For most small businesses, the process from initial gap assessment to receiving certification takes two to four weeks, depending on how much remediation is needed. If your controls are already close to compliant, it can be faster. Certification is valid for twelve months and must be renewed annually.
If you fail, your assessor will identify the specific controls that are not compliant. You can then remediate those gaps and resubmit. The most common reasons for failure are missing multi-factor authentication on cloud services, out-of-date or unsupported software, and incomplete coverage of devices within scope.
Our team guides UK businesses through the full Cyber Essentials process -- gap assessment, remediation support and certification submission -- with CREST-certified expertise throughout.
Our Cyber Essentials ServiceAlso free: our Website & Email Security Checker, Password Strength & Breach Checker and Phishing Awareness Quiz -- no signup required for any of them.