Cyber Essentials and Cyber Essentials Plus: what regulated firms need to know

September 24, 2026

If your firm works in financial services, legal, gaming or professional services, the question has probably landed in your inbox already. It sits on a client onboarding form, a supplier due diligence pack or an insurance renewal: do you hold Cyber Essentials or Cyber Essentials Plus?

For regulated firms, Cyber Essentials and Cyber Essentials Plus have become the quickest way to show clients, partners and insurers that the basics of cyber security are under control. This guide explains what each one involves, how they differ, why the people you work with are asking, and what changed in April 2026.

What is Cyber Essentials?

Cyber Essentials is the UK Government-backed baseline standard for cyber security. It was developed by the National Cyber Security Centre (NCSC) and is delivered by IASME through a network of certification bodies. It covers five technical controls:

  1. Firewalls. Controlling what can reach your network and devices from the internet.
  2. Secure configuration. Removing default passwords, unused accounts and software you do not need.
  3. Security update management. Keeping operating systems, firmware and applications patched and supported.
  4. User access control. Giving people only the access their role requires, and protecting admin accounts.
  5. Malware protection. Stopping malicious software before it gets a foothold.

These controls target the routes attackers use most often against small and mid-sized firms: stolen passwords, unpatched software and over-privileged accounts. The controls themselves are simple. Keeping them in place across every laptop, phone and cloud platform, all year round, is where the discipline comes in.

Certification is a verified self-assessment. You answer a standard question set, a board member signs to confirm the answers are true, and a qualified assessor marks them against the scheme’s published requirements. The certificate lasts 12 months, and you then re-certify against whatever requirements are current at the time.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five controls and use the same question set. The difference is how much is taken on trust. With Cyber Essentials, you declare that the controls are in place. With Cyber Essentials Plus, an independent assessor tests your systems and sees the evidence for themselves.

Cyber Essentials Cyber Essentials Plus
How you are assessed Self-assessment questionnaire, marked by a qualified assessor Everything in Cyber Essentials, plus a hands-on technical audit
What proves it Your answers, signed off by a board member An assessor tests your live systems
What gets checked Your written answers External vulnerability scan, a sample of laptops, servers, tablets and phones, patching within 14 days, malware protection, user accounts and MFA on cloud services
Typical timescale A few days to a few weeks, depending on what needs fixing Add a week or two for scheduling and the audit
Valid for 12 months 12 months
Best for Showing the basics are in place for lower-risk supplier requests Firms handling client money, legal matters, player data or other sensitive information, and anyone asked for independent proof

Which one does a regulated firm need?

For most regulated firms, Cyber Essentials Plus is the one worth aiming for. If you hold client money, confidential legal files, payment data or large volumes of personal information, the people relying on you want independent evidence. A signed questionnaire is a good start. A tested certificate carries far more weight with a bank’s third-party risk team, a law firm panel reviewer or an insurer.

A sensible route for many firms is to achieve Cyber Essentials first, fix what it uncovers, then move to Cyber Essentials Plus within the same 12-month window.

Why are clients, partners and insurers asking for it?

1. Your clients’ regulators are looking at their suppliers

Financial services firms have to manage the risk that comes from the third parties they rely on, and operational resilience rules make that risk their board’s responsibility. Firms serving EU financial entities are also seeing tougher supplier questions as DORA takes hold. The easiest way for a bank, lender or platform to tick the “basic cyber hygiene” box on your file is a current certificate.

2. Supply chain attacks start with the smaller firm

Attackers know that a large organisation is often easier to reach through its smaller suppliers and advisers. That is why the requirement keeps moving down the supply chain, and the results speak for themselves. Wealth manager St James’s Place required Cyber Essentials Plus across its network of more than 2,800 partner businesses and reported an 80% reduction in cyber security incidents.

3. Insurers price it in

According to UK Government figures, organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance than those without. Insurers have noticed, and it shows in the questions they ask before they quote. Smaller UK organisations that certify their whole business also get cyber liability insurance included, with access to a 24-hour incident response helpline.

4. It shortens due diligence

Regulated firms spend a surprising amount of time on security questionnaires, both sending them and answering them. A certificate answers a large part of that form in one document, from an independent scheme, and anyone can check it on the public certificate search. That means faster onboarding for your clients and fewer late nights for you.

5. Public sector work requires it

A current certificate is required to bid for central government contracts that involve personal or financial information, and a growing number of public sector frameworks ask for Cyber Essentials Plus. For professional services firms chasing that work, it is a condition of entry.

What does it look like across different regulated sectors?

  • FinTech and financial services. Expect it in bank partnership agreements, payment provider onboarding and investor due diligence. Trading platforms, CRM systems and open banking integrations are all in scope if they sit in the cloud.
  • LawTech and legal services. Law firms hold exactly the information criminals want, and conveyancing fraud keeps email security under scrutiny. Client panels and professional indemnity insurers increasingly ask for certification, and case management systems are in scope.
  • GameTech and gaming. Operators, platform providers and studios handle player data and payments, and payment partners and B2B customers expect evidence of good security. Development machines and build servers need to meet the same standard as office laptops.
  • Professional services. Accountants, consultants and advisers are often asked for Cyber Essentials before they can join a client’s supplier list, particularly where they access client systems or data.

What changed in April 2026?

If you certified a couple of years ago and expect renewal to be a formality, this section matters. A new question set, named Danzell, and updated Requirements for IT Infrastructure v3.3 apply to all assessment accounts created after 26 April 2026. The five controls are the same, but two issues now cause an automatic fail:

  • No multi-factor authentication on a cloud service where it is available. Free, included or paid, it makes no difference. If the service offers MFA and you have not switched it on, you fail.
  • High-risk and critical security updates not installed within 14 days. That covers operating systems, router and firewall firmware, and applications, including browser extensions.

Cloud services are now formally defined and cannot be left out of scope. If your firm runs on Microsoft 365, Google Workspace, Xero, a practice management system or a trading platform, it is part of the assessment.

How does Cyber Essentials fit with ISO 27001, DORA and FCA expectations?

Cyber Essentials is a baseline. It proves five technical controls are in place and can be achieved in weeks. ISO 27001 is a full information security management system covering policy, risk and governance, and it takes months. Regulatory frameworks such as the FCA’s operational resilience rules and DORA look wider still, at how your firm identifies, manages and recovers from disruption.

Cyber Essentials Plus gives you tested, independent evidence of the technical foundations those frameworks depend on, which makes it a sensible first step on the road to ISO 27001 and a useful piece of evidence in any regulatory conversation.

Want to know where your firm stands?

IT Backbone supports firms in FinTech, LawTech, GameTech and professional services, where security and compliance are part of everyday IT. We help you prepare for Cyber Essentials and Cyber Essentials Plus, fix what needs fixing first, and keep you certified year after year so the certificate is ready whenever a client, regulator or insurer asks.

Book a free consultation and we will give you a straight answer on where your IT stands today and what certification would involve for a firm like yours.

Book a meeting with me if you would like to discuss anything.

Connect with Jason Chaplin on LinkedIn: https://www.linkedin.com/in/jasonchaplin/

Key metrics

We’re proud of how we perform

15 mins

Avg. response time

< 2 hours

Avg. resolution time

100%

positive feedback

79%

First contact resolution