Cyber Essentials for Schools and Businesses: How to Pass First Time
Cyber Essentials certification is a UK government-backed scheme, run by IASME on behalf of the National Cyber Security Centre, that verifies your organisation has five basic technical controls in place: firewalls, secure configuration, user access control, malware protection and security update management. You get certified by completing an online question set, having it signed off at board or senior leadership level, and submitting it to a licensed Certification Body for marking. Certification lasts twelve months.
Most organisations take four to eight weeks from a standing start, because the fixing takes longer than the paperwork. Cyber Essentials Plus adds a hands-on technical audit of your devices and cloud services, carried out within three months of passing the basic level. And if your honest answer to “would we pass today?” is “probably, but we don’t actually know”, this guide is for you.
Who This Is For
This guide is written for the people who get handed Cyber Essentials as a task rather than a choice. That usually means IT Managers and IT Directors in multi-academy trusts, independent schools and further education colleges, and School Business Managers who own compliance alongside finance and premises.
It is equally for Managing Directors of service businesses who have just been asked for certification by a client or an insurer. You may have an internal IT team, a single network manager or an outsourced provider. What you share is a deadline, a mixed estate of devices you did not choose, and no appetite for a failed submission.
The Real Problem Is Not the Questionnaire, It Is the Estate Behind It
The risk is not theoretical. The 2025/26 Cyber Security Breaches Survey found that 73% of secondary schools reported a breach or attack in the previous twelve months, against 43% of UK businesses overall. Education is one of the most targeted sectors in the country, and Cyber Essentials exists to close the basic gaps attackers exploit first.
Most organisations do not fail Cyber Essentials on knowledge. They fail on the honest answers. The question set asks whether every device that touches your data is patched within fourteen days, whether every cloud service has multi-factor authentication switched on, and whether any unsupported operating systems remain in use.
Schools discover a cupboard of iPads stuck on an old iOS version, shared staffroom logins and a legacy server that runs the library system. Service businesses find directors with local admin rights and personal laptops used for client work. The phrase we hear most often is, “we think we’re probably fine, but we don’t actually know.”
Find out where you stand before you commit to a submission date.
Take the Cyber Essentials Readiness Self-Assessment and get a gap list against all five controls in under fifteen minutes.
How Cyber Essentials Certification Actually Works
Cyber Essentials certification is a verified self-assessment, not an audit, and that distinction matters. You answer the current IASME question set online, a qualified assessor at a Certification Body marks your answers, and you either pass or receive feedback with a short window to correct and resubmit.
Your answers must cover every device, server and cloud service in the scope you declare. That includes staff-owned devices used for work and anything used by remote workers.
Scope is where organisations either save themselves or create problems. You can certify a subdivision, such as a single academy within a trust, but whole-organisation certification is what most insurers and tenders expect to see. It also unlocks the included cyber liability insurance for UK organisations with turnover under twenty million pounds, provided you opt in at application.
Cyber Essentials for Schools, Colleges and Service Businesses
The driver for certification differs by sector, and it changes how you should plan. For further education colleges it is no longer optional. The Department for Education confirms that Cyber Essentials is a requirement for colleges under their funding agreement, so renewal needs to sit in the annual compliance calendar alongside safeguarding and finance deadlines.
For schools and multi-academy trusts, certification is not a DfE requirement. However, the DfE cyber security standard is one of six core digital and technology standards that schools should be working towards by 2030, and the department positions those standards as a route to certification. Governors, trustees, auditors and insurers increasingly ask about it directly, and the evidence you gather often supports your filtering and monitoring duties too.
For service businesses, certification is commercial. Central government contracts involving personal or sensitive data have required it since 2014, and it has spread into private-sector supply chains and professional indemnity renewals. If a framework application or an insurance renewal is the trigger, work backwards from that date and allow eight weeks, not two.
The DMS Method: Assess, Fix, Submit
Our approach is deliberately practical. We assess the estate first, fix what fails and submit last, because a resubmission costs time you have usually already promised to someone else. In practice that breaks down into six steps.
- Fix your deadline and your scope. Identify what triggered the requirement (an insurance renewal, a tender, a college funding condition or a trust-wide compliance review). Then decide whether you are certifying the whole organisation or a defined subdivision, and write the scope down before you start.
- Build an accurate asset list. Record every laptop, desktop, tablet, mobile, server, firewall and cloud service, with its operating system version and support status. Include staff-owned devices used for work, which are in scope whether you like it or not.
- Run a gap assessment against the five controls. Compare what you found against the current question set rather than last year’s version. Separate the quick configuration changes from the items that need budget or procurement.
- Remediate in priority order. Remove or isolate unsupported devices and enable multi-factor authentication on all cloud and administrative accounts. Strip unnecessary admin rights, confirm critical and high-severity updates are applied within fourteen days, and check for default passwords and accounts.
- Complete the question set and secure senior sign-off. A board-level or equivalent representative must confirm the answers are accurate, so brief them early rather than chasing a signature on submission day.
- Submit, respond, then plan the next twelve months. Answer any assessor feedback promptly, diarise your renewal, and decide whether Cyber Essentials Plus is needed within the three-month window.
What to Watch Out For
- Unsupported devices you forgot about. End-of-life iPads, Chromebooks past their auto-update expiry date and any Windows version no longer receiving security updates will fail you outright unless removed from scope or replaced.
- Shared and generic accounts. Staffroom logins, a single “admin” account for the MIS and class accounts used by multiple people all breach the user access control requirement.
- Cloud services treated as out of scope. Every SaaS platform holding your data is in scope, including systems bought by departments without IT’s knowledge.
- Leaving senior sign-off to the end. A Managing Director or trust CEO on leave can stall a submission for a fortnight.
- Assuming last year’s answers still apply. The question set is updated regularly, and requirements tighten.
Quick Checklist
- Confirm the deadline driving certification and who is accountable for it internally.
- List every device and cloud service, with operating system version and vendor support end date.
- Check multi-factor authentication is enabled on all administrative and cloud accounts, including the finance system.
- Verify critical and high-severity patches are applied within fourteen days across servers, laptops, tablets and mobiles.
- Remove local administrator rights from standard user accounts and document who retains them and why.
- Change or disable all default and unused accounts, including on firewalls, switches and printers.
- Decide whether you need whole-organisation scope to qualify for the included cyber insurance.
- Book the senior sign-off conversation now, not on submission day.
Frequently Asked Questions
How much does Cyber Essentials certification cost?
Pricing is banded by organisation size, starting at a few hundred pounds plus VAT for micro organisations with fewer than ten staff and rising for small, medium and large organisations. That fee covers the assessment and marking only, not the remediation work or any hardware you need to replace.
Budget separately for device replacement if you are carrying unsupported kit, as that is usually the larger cost. Cyber Essentials Plus is priced separately because it involves an on-site or remote technical audit.
How long does it take to get Cyber Essentials?
Completing the question set takes a few hours if your information is to hand, and assessors typically return a result within a few working days of submission. The realistic timeline from decision to certificate is four to eight weeks for most organisations, because remediation dominates the schedule. Schools replacing end-of-life devices should allow longer and align the work with a holiday period.
Is Cyber Essentials mandatory for schools and colleges?
For colleges, yes. The Department for Education makes Cyber Essentials a requirement under the college funding agreement. For schools and academy trusts it is not a requirement, but the DfE cyber security standards are designed to help schools work towards certification, and trustees, auditors and insurers increasingly treat it as expected practice.
Some local authorities, dioceses and insurers also make it a condition of cover or of a specific contract, which is why many multi-academy trusts choose to certify across all their sites.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment that an external assessor marks, while Cyber Essentials Plus adds an independent technical audit of a sample of your devices, cloud accounts and email filtering. Plus must be completed within three months of passing the basic level, using the same scope. If a tender or insurer specifies Plus, plan for both as one continuous piece of work rather than two separate projects.
Check the Estate Before You Answer the Questions
You now have two choices. You can answer the question set based on what you believe is true and hope the assessor agrees, or you can check the estate first and submit knowing the answer.
Organisations that fail almost always fail on something they did not know was there: a forgotten tablet trolley, a legacy server, a shared login nobody has audited since 2019. Autumn renewals and new-term compliance reviews have a habit of compressing timelines, and the work does not get smaller if you start in December. “Probably fine” is not an answer an assessor accepts.
See exactly which of the five controls you would pass today.
Start the Cyber Essentials readiness check
Or talk to our team about cyber security support for schools and service businesses.
