More than 61,000 Cyber Essentials certificates were awarded in the UK in the year to June 2026, covering both Cyber Essentials and Cyber Essentials Plus. The scheme is growing. It is still the larger organisations doing most of the certifying.

Government figures published in April put the gap plainly. Thirty five per cent of large businesses hold Cyber Essentials, against twelve per cent of small ones.

Part of that is awareness. Only a quarter of small businesses, and fourteen per cent of micro businesses, have heard of the scheme at all. For the ones that have, the barrier is usually capacity.

In a small organisation, the person responsible for IT is often the person running the business. Security work competes with everything else that needs attention, so certification stays on the list because something more urgent keeps taking priority.

What Cyber Essentials is designed to do

Cyber Essentials was created to give organisations a practical baseline against the attacks that happen most often. It covers five areas: firewalls, secure configuration of devices, keeping software updated, controlling who has access to what, and malware protection. Multi-factor authentication is mandatory on cloud services wherever it is available.

None of that is especially complex, and that is the point of the scheme. It is not asking a smaller organisation to build a security operations centre. It is asking it to get the fundamentals right.

For an organisation without a dedicated cyber team, that structure is useful. Instead of working out which of hundreds of possible measures matter most, there is a clear place to start.

Why certification can still feel difficult

Before an organisation can certify, somebody has to understand which devices are in scope, which services are in use, whether updates are being applied and how user accounts are managed. If IT is outsourced, the business may also need answers from its provider before it can say any of that with confidence.

Smaller organisations tend to get stuck at that point. The problem is rarely a major security weakness. It is working out what is already in place, finding the gaps and making time to deal with them.

It is also why the process is worth more than the certificate. Going through it makes ownership clearer and shows where assumptions have been standing in for evidence.

The certificate is not the finish line

There is a second risk once certification is achieved, which is assuming the job is done. Cyber Essentials is assessed at a point in time. The controls underneath it have to keep working afterwards.

A business can pass the assessment and drift away from the standard within months. New devices arrive, people change roles, accounts stay open longer than they should, and updates slip when nobody is checking.

Could we still meet the standard six months after certification?

That is a more useful question than asking whether the certificate exists. If the answer is uncertain, it usually points to ownership and routine rather than technology. Twenty four per cent of businesses told the same government survey they have controls in all five areas, well above the five per cent that hold the certificate. The controls are the part that has to survive the year.

A practical way to approach it

For smaller organisations, Cyber Essentials works best treated as an operational exercise rather than a security programme.

  1. Understand what is already in place, including anything an IT provider manages on your behalf.
  2. Identify the gaps that genuinely need attention, and be honest about which are quick and which are not.
  3. Give the basics an owner by name, not by department.
  4. Keep those responsibilities running after the certificate has been issued.

The strongest controls are rarely the most complicated ones. They are the ones that are consistently maintained.

Sources: UK Government, Cyber Essentials management information, updated 16 September 2026; Cyber security breaches survey 2025/2026, published 30 April 2026; National Cyber Security Centre, Cyber Essentials overview.

If Cyber Essentials has been sitting on your to-do list, we can work through what is already in place, find the gaps and get you through certification without it becoming another project. Talk to an expert.