Cyber Essentials & Cyber Essentials Plus for UK SMEs
10 policies aligned to the 5 NCSC/IASME technical controls. Ready for self-assessment and CE Plus audit in days — not weeks.
InfoSec 38 Enterprise Pack pack
39 policies · £950 one-off
Covers CE, CE Plus and ISO 27001 in one pack · lifetime access
After checkout, answer questions about your business. Confirm your answers before generating policy drafts, then review and edit those drafts before use. The listed jurisdictions define this product’s coverage.
Free account · preview sample policies · buy pack when readyWhat is Cyber Essentials?
Quick answer. Cyber Essentials is a UK government-backed certification scheme delivered by the National Cyber Security Centre (NCSC) through accredited bodies (IASME being the principal partner). It tests five technical-control families — firewalls, secure configuration, user access control, malware protection and security update management. Cyber Essentials Plus adds an external technical audit; both require an underlying set of documented policies.
Cyber Essentials is the UK government-backed certification scheme, owned by the National Cyber Security Centre (NCSC) and delivered by the IASME Consortium. It verifies that your organisation has implemented five fundamental technical controls: boundary firewalls, secure configuration, user access control, malware protection, and security update management.
It comes in two tiers. Cyber Essentials (CE) is a self-assessment certification — you answer the IASME Question Set and an assessor marks it, typically £300–£500 depending on company size. Cyber Essentials Plus (CE+) adds an independent technical audit with vulnerability scanning and device sampling, typically £1,500–£3,000 for a UK SME.
Who needs Cyber Essentials?
Quick answer. UK SMEs bidding for central-government contracts above £5,000 (mandatory under PPN 09/14), defence-supply firms (DEFCON 658), NHS suppliers handling patient data, and a growing list of councils and housing associations that ask for it in tenders. Cyber-insurance underwriters increasingly prompt for it too. Cyber Essentials Plus is expected for higher-sensitivity engagements; the basic certificate is enough for most SME tenders.
- UK government suppliers — CE is mandatory for central government contracts handling personal data; CE+ is often required for MoD and sensitive contracts.
- NHS framework suppliers — DSPT and many NHS procurements specifically reference CE or CE+.
- Public sector suppliers — councils, universities, and housing associations increasingly require it in tenders.
- UK SMEs answering vendor risk questionnaires — it's the cheapest quick-win security credential enterprise buyers recognise.
- Cyber insurance applicants — many UK insurers now require CE as a baseline or offer premium discounts for it.
Policies you need for Cyber Essentials
Quick answer. NCSC and IASME do not prescribe a fixed list, but the audit tests the policies behind the five technical-control families. Most UK SMEs maintain 8 documented policies for Cyber Essentials Plus: information security, access control, acceptable use, malware protection, patch management, secure configuration / hardening, mobile device / BYOD and incident response. All eight are included in our cyber-essentials-aligned packs.
The IASME Question Set doesn't list policies by name but assessors expect documentation behind every "yes" answer. These 10 policies cover every one of the five technical controls — all included in our Startup Essentials and ISO 27001 packs:
Password Policy
Length, complexity, MFA, password manager, breached-password checks.
Access Control Policy
Joiner/mover/leaver, least privilege, admin account separation.
Patch Management Policy
14-day patching SLA for critical/high vulnerabilities, inventory.
Malware Protection Policy
Endpoint protection, allowlisting, device-control standards.
Firewall / Boundary Firewalls
Default-deny, admin password change, documented rulesets.
Secure Configuration
Hardened builds, removal of default accounts and unused services.
BYOD Policy
Personal device rules, MDM, segregation of corporate data.
Incident Response Policy
Detection, triage, reporting, lessons-learned — CE annex expectation.
Acceptable Use Policy
What staff can and can't do with company devices and networks.
Remote Working Policy
Home/hybrid controls, public Wi-Fi, VPN and device standards.
Realistic timeline to certification
Planning your rollout. There is no fixed readiness timetable. After purchase, complete the business questions and confirm your answers to generate editable drafts. Your team must review, approve and implement the policies. Evidence collection and any independent assessment take additional time.
Policy packs for Cyber Essentials
PolicySuite vs GRC platforms vs consultant vs DIY
Compare the scope. PolicySuite prepares editable policy drafts from your business answers. Compare the included documents and current shop price with the scope offered by a consultant, a template supplier or a governance platform. Implementation, specialist advice and independent assessment may require separate work.
Further reading
Frequently asked questions
What's the difference between CE and CE Plus?
Cyber Essentials is self-assessment against the IASME Question Set, marked by an assessor — typically £300–£500. CE Plus adds an independent technical audit: external vulnerability scan, internal authenticated scan, and sampled user-device testing, typically £1,500–£3,000 for a small SME. Many UK government contracts and NHS frameworks specifically require CE Plus.
What policies do I need for Cyber Essentials?
CE doesn't mandate a fixed list but assessors expect documented policies for password standards, patching, access control, malware protection, acceptable use, BYOD, incident response and remote working — backing up every "yes" in the Question Set. Our Startup Essentials pack covers all ten areas.
How long does Cyber Essentials take?
There is no fixed readiness timetable. After purchase, complete the business questions and confirm your answers to generate editable drafts. Your team must review, approve and implement the policies. Evidence collection and any independent assessment take additional time.
Is Cyber Essentials mandatory in the UK?
CE is mandatory for UK central government contracts handling personal or sensitive data, for MoD suppliers, and for most NHS supplier frameworks. Many UK enterprise buyers and councils also require it in RFPs. It is not legally mandatory for private-sector trading but is the de facto UK security baseline.
Who runs Cyber Essentials?
CE is owned by the NCSC and delivered by the IASME Consortium as sole Cyber Essentials Partner. You apply through an IASME-accredited Certification Body. Certificates are valid for 12 months and must be renewed annually.
Which PolicySuite pack is best for CE?
Startup Essentials (10 policies, £250) covers all five CE control areas. For CE Plus or companies heading towards ISO 27001, ISO 27001 Core Set (16 policies, £400) or InfoSec 38 gives deeper coverage. See live pricing on each product page.
Be CE-ready in days, not weeks
Get 39 bespoke policies covering CE, CE Plus, and ISO 27001 — lifetime access.
Get Started — £950References and primary sources
Quick answer. The framework guidance on this page is reviewed against the primary-source documents below. Each link resolves to an official regulator or standards-body publication so an auditor, procurement reviewer or DPO can verify the alignment without taking the page on trust.
- NCSC Cyber Essentials — the UK government scheme owner.
- IASME (delivery partner) — the body that operates the certification scheme.
- PPN 09/14 (gov.uk) — the procurement policy note that mandates Cyber Essentials for many UK public-sector contracts.
- NCSC 10 Steps — the broader baseline guidance Cyber Essentials sits within.
In our experience working with UK SMEs and similar organisations across the EU and US, the framework pages that survive enterprise vendor reviews are the ones that cite primary sources rather than secondary blog posts. Many UK SMEs typically discover this only after their first failed vendor questionnaire — the reviewer asked for a clause-to-source map and the standard reply pointed at a marketing page rather than the relevant regulator. The references above are the standing set we cite from inside the policies themselves so the chain stays intact end-to-end.