Cyber Essentials and Cyber Essentials Plus Explained: The Certification That Blocks 80% of Attacks

Table of contents
Subscribe to newsletter
Cyber Essentials is the UK government's baseline cybersecurity certification, covering five technical controls verified through a self-assessment. Cyber Essentials Plus adds an independent technical audit of those same controls. Together, the National Cyber Security Centre estimates the scheme blocks around 80% of common internet-based attacks, yet certified organizations still get breached, because most serious attacks today start with a person rather than a system. Closing that gap means pairing the certification with a continuous, behavior-based layer of visibility, which is exactly what Human Risk Intelligence is built to provide.
IN THIS ARTICLE
· What Is Cyber Essentials?
· What Does Cyber Essentials Plus Add?
· What Are the Five Technical Controls in Cyber Essentials?
· What Does Certification Not Test?
· How Attackers Get Past a Certified Organization: The Marks and Spencer Case
· What Do the Numbers Say About the Gap?
· What Changed in the April 2026 Update?
· How Does Human Risk Intelligence Close the Gap?
· A Certification and Beyond Checklist
· Frequently Asked Questions
What Is Cyber Essentials?
Cyber Essentials is the United Kingdom's baseline cybersecurity certification, backed by the National Cyber Security Centre and delivered through the scheme operator IASME. It sets out five technical controls and is designed as the minimum standard recommended for organizations of any size, from a two-person consultancy to a multinational supplier bidding for public sector work. Certification is renewed every twelve months and is based on a verified self-assessment questionnaire: an organization answers a defined set of questions about its own systems, a senior leader signs a declaration confirming the answers are accurate, and an independent assessor reviews the submission before a certificate is issued. As of 2026, pricing is tiered by organization size, starting at roughly £320 plus VAT for organizations with up to nine employees, a deliberately low entry cost given how foundational the standard is meant to be.
What Does Cyber Essentials Plus Add?

Cyber Essentials Plus tests the same five controls, but it replaces self-reporting with independent verification. A qualified assessor runs a technical audit across a representative sample of an organization's devices, every internet facing gateway, and every server exposed to the internet, checking that the controls described in the self-assessment are actually configured the way the paperwork claims. A passed Cyber Essentials self-assessment is a prerequisite for attempting Cyber Essentials Plus, and the relationship runs both ways under current scheme rules: if an organization fails its Cyber Essentials Plus audit, IASME can revoke the underlying Cyber Essentials certificate entirely. That single rule tells you what the scheme actually values. A policy on paper only counts once someone outside the organization has confirmed it is real.
What Are the Five Technical Controls in Cyber Essentials?

Every Cyber Essentials certification, at either level, is built on the same five controls.
1. Firewalls. Boundary firewalls and internet gateways configured to block unauthorized access from the internet into internal networks.
2. Secure configuration. Removing or disabling default accounts, unnecessary software, and factory settings that widen the attack surface before a system ever goes live.
3. Security update management. Applying vendor patches for internet facing software and operating systems within a defined window, commonly fourteen days of release for critical and high severity fixes.
4. User access control. Limiting administrative privileges to the people who genuinely need them and removing access as soon as a role changes or a person leaves.
5. Malware protection. Deploying and maintaining anti malware software or application allow listing across every device that can reach the internet.
The National Cyber Security Centre has stated publicly that these five controls, properly implemented, help defend against around 80% of common internet-based attacks. That is a genuinely strong return for a scheme costing a few hundred pounds a year at its smallest tier. It is also, by design, a statement about the 20% the scheme was never built to touch.
What Does Certification Not Test?
None of the five controls, and no part of the Cyber Essentials Plus audit, tests what happens when an attacker picks up a phone. The scheme checks whether a firewall rule is correctly configured. It does not check whether a helpdesk agent will reset multi factor authentication for someone who sounds confident and knows an employee's name. It does not check whether a finance team member will approve a payment change requested over a message pretending to be from a director. Those are process and behavior questions, not technical configuration questions, and they sit entirely outside the scope of what a firewall audit or patch review can capture.
That gap is visible in the data. Across incident response cases reviewed by Sophos in its 2026 ransomware research, 67% of root causes were identity related, and multi factor authentication was missing exactly where it mattered in 59% of cases, even though 97% of victims where stolen credentials were the root cause had some form of MFA enabled somewhere in their environment. 79% of ransomware attacks in the same research began with an identity-based approach rather than a purely technical exploit. A technical certificate can confirm that a control exists. It cannot confirm that the control was used correctly by the person standing in front of it at two in the morning.
How Attackers Get Past a Certified Organization: The Marks and Spencer Case

The clearest recent illustration of this gap did not involve a small business cutting corners. In April 2025, the British retailer Marks and Spencer disclosed a ransomware attack that had actually begun as early as February that year, attributed to the Scattered Spider collective, also tracked as UNC3944. The attackers did not exploit a missing patch or an open port. They called the IT helpdesk run by a third-party contractor, impersonated an employee, and persuaded a helpdesk agent to reset multi factor authentication on a privileged account. With that single reset, the attackers had an authenticated foothold. From there they moved through Active Directory, extracted the domain controller's NTDS.dit database of password hashes, cracked those hashes offline, and used the resulting credentials to deploy DragonForce ransomware across the retailer's infrastructure.
The business impact was severe by any measure. Online ordering was suspended for 46 days, warehouse operations were disrupted badly enough that staff reverted to tracking stock on paper, and the company later told investors the incident would cost roughly £300 million in lost profit, alongside a stock market value drop of more than half a billion pounds. The UK's Cyber Monitoring Centre subsequently assessed the Marks and Spencer incident together with a closely related attack on the retailer Co-op as a single combined cyber event, estimating the combined financial impact at somewhere between £270 million and £440 million.
None of that began with a technical failure a Cyber Essentials Plus audit would have caught. It began with a phone call and a helpdesk process that trusted a confident voice over a verified identity. A retailer of that scale almost certainly had mature perimeter security, patched systems, and access controls that would satisfy any technical audit. The weak point was a human one, sitting inside a process that certification simply does not reach.
What Do the Numbers Say About the Gap?

Per the UK government's 2025/2026 Cyber Security Breaches Survey, carried out by Ipsos for the Department for Science, Innovation and Technology and the Home Office, 42% of micro businesses and 46% of small businesses reported a breach or attack in the past year, rising to 65% for medium sized organizations and 69% for large ones. Phishing remains the most common attack type by a wide margin, experienced by 38% of businesses surveyed and rated the most disruptive form of breach by 69% of those affected.
Under half of UK businesses use two factor authentication, and only 31% place cybersecurity responsibility at board level. Analysis of the same survey dataset puts Cyber Essentials adoption at roughly 5% of all UK businesses, a figure that points to awareness and inertia as the real barrier, given how low the entry cost already is.
On the recovery side, IBM's 2025 research found that a tested incident response plan saves an average of $2.66 million per breach, a reduction that has nothing to do with firewalls and everything to do with whether people know what to do in the first hour.
What Changed in the April 2026 Update?
The scheme itself has moved to close part of this gap. From 27 April 2026, all new Cyber Essentials assessments are evaluated against version 3.3 of the NCSC's Requirements for IT Infrastructure, delivered through what IASME refers to as the Danzell question set. The headline changes include mandatory multi factor authentication wherever a platform supports it, more detailed cloud service requirements, a rule requiring separate administrative and daily use accounts rather than shared admin logins, and a stricter Cyber Essentials Plus verification process introduced specifically in response to assessors finding organizations applying controls inconsistently across their estate. The board level declaration signed as part of the verified self-assessment has also been rewritten to make clear that compliance is an ongoing responsibility across the full 12-month certificate period, not a single statement made on assessment day.
These are sensible, overdue changes but they still focus technical configuration. They still cannot certify that an employee will ask a second verification question before resetting a login for someone who says the right name with enough confidence.
How Does Human Risk Intelligence Close the Gap?

This is where a different category of visibility becomes necessary, one built around people rather than infrastructure. Human Risk Intelligence treats employee behavior itself as a continuously monitored signal, not a once-a-year training completion percentage. Rather than checking a box that says awareness training happened in January, it tracks how real people actually behave across real channels over time: who clicks a simulated phishing email and who reports it, how quickly a suspicious message gets flagged, which teams or departments show rising risk indicators before an incident rather than after one, and where a helpdesk or finance process depends on a human judgment call that has never been tested under pressure.
The distinction matters because a certification audit and a behavior signal answer two different questions. Cyber Essentials Plus can confirm that a firewall rule is configured correctly on the day an assessor looks at it. A continuous, behavior-based layer can show that the same organization's helpdesk team has been receiving more, not fewer, plausible sounding impersonation attempts over the past quarter, well before one of them succeeds. Put the two together, a technical baseline that blocks the largest share of common attacks and a live view of where human judgment is being tested, and an organization is looking at something much closer to its actual exposure, rather than a snapshot of its infrastructure alone.
Frequently Asked Questions
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is based on a verified self-assessment questionnaire covering five technical controls. Cyber Essentials Plus tests the same five controls through an independent technical audit of a sample of devices, gateways, and servers, rather than relying on self-reported answers.
How much does Cyber Essentials Plus cost?
Pricing depends on organization size and the certification body chosen, and it typically costs more than standard Cyber Essentials because it includes on site or remote technical testing rather than a questionnaire alone. Organizations should request a quote from an IASME approved certification body for an exact figure.
Is Cyber Essentials mandatory for UK businesses?
It is not a legal requirement for most private organizations, though it is commonly required to bid for UK government contracts and is increasingly requested by larger customers and insurers as a condition of doing business.
Does holding Cyber Essentials certification mean an organization cannot be breached?
No. NCSC has stated the five controls help defend against a large share, commonly cited as around 80%, of common internet-based attacks, but certification does not test social engineering, helpdesk processes, or employee decision making, which is where a growing share of serious breaches now begin.
What is Human Risk Intelligence?
It is a continuous, behavior-based way of measuring how people across an organization actually respond to phishing, suspicious requests, and everyday security decisions, rather than relying on training completion figures or a once-a-year assessment.
In a nutshell: Cyber Essentials and Cyber Essentials Plus remain a genuinely good use of a few hundred pounds and a technical review. They stop a large share of the attacks that would otherwise succeed. What they were never designed to stop human risk, that is precisely where the next serious breach is more likely to start. Treat certification as the floor, and build a continuous view of human behavior on top of it. Book a demo to learn more about Cyber Essentials, Cyber Essentials Plus and Human Risk Intelligence.
BOOK A DEMO
See usecure in action
A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.
Subscribe to newsletter
Discover how professional services firms reduce human risk with usecure
See how IT teams in professional services use usecure to protect sensitive client data, maintain compliance, and safeguard reputation — without disrupting billable work.
Related posts
Explore more insights, updates, and resources from usecure.

NIS2 Directive: Why Human Risk Intelligence Is Now Mandatory for EU Organizations

EU AI Act: AI Literacy As a Legal Requirement

