https://www.noxia.co.uk/field-notes/three-hundred-and-twenty-pounds · printed from noxia.co.uk · sources checked 24 September 2026
Field note · Security
£320 buys five controls, and £25,000 of cover if you tick the box.
We spend most of this site telling firms not to buy things. This is the exception: a government-backed scheme that costs less than a fortnight of most software subscriptions, is deliberately unambitious, and carries an insurance policy that comes with the certificate only if you tick for it when you apply.
- Security
- Cyber Essentials
- NCSC
- Supplier due diligence
- Small firms
The short answer
Cyber Essentials is the minimum cyber security standard recommended by government, built by the NCSC around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Certification starts at £320 plus VAT. Cyber Essentials Plus assesses the same five controls with independent technical testing. UK organisations under £20m turnover that certify their whole organisation can opt in to £25,000 of cyber liability cover at no extra cost.
On this page · 7 sections
The NCSC's own framing of why this works is the most useful sentence in the scheme: most cyber attacks are basic, and it compares them to a thief trying your front door to see whether it is unlocked.
That is the whole design philosophy. Cyber Essentials does not attempt to stop a determined, targeted adversary. It locks the door.
The insurance, and the box you have to tick
UK organisations with turnover under £20 million that certify their whole organisation are, in the NCSC’s words, “automatically entitled” to cyber liability insurance arranged by IASME, including round-the-clock incident response support covering technical, legal and crisis management services.
IASME, which arranges it, adds the two details that matter. The applicant has to opt in when completing the assessment — “only if they want the cover” — and the cover is a £25,000 limit of indemnity with a £1,000 excess, including a 24-hour incident helpline. The certification costs the same either way. The policy also expects you to install the automatic updates your software provider sends for critical business software, which is one of the five controls anyway.
Two things follow. If you are already certified, find out whether you opted in, because an incident response line you did not know about is useless at two in the morning. And if you are weighing the cost, £25,000 of cover belongs in the price comparison beside the £320 — measured against what your own policy already covers, not instead of it.
Where it stops being optional
Certification is voluntary until somebody asks for it, and increasingly somebody does. It appears in public sector procurement, in supplier questionnaires, and in the contract schedules that arrive when a larger client reviews its own supply chain.
That last route is the one to watch, because it is about to get busier. The Cyber Security and Resilience Bill brings managed service providers and data centres into scope and lets regulators designate critical suppliers, and obligations of that kind flow down by contract faster than they arrive by statute — which is the argument in the note on the 24-hour clock.
What it will not do
It will not make you secure. It is a floor, stated as a floor by the body that wrote it, and a firm that treats a certificate as the end of the conversation has misread a scheme that describes itself as the minimum.
It also says nothing about your data protection position. The Article 22C safeguards that came into force in February, the incident reporting duties, and everything about what your systems decide are separate questions with separate answers — the automated decision-making note covers the one most firms have not looked at.
Three honest observations
- The self-assessment is only as good as the answers. A firm can certify while getting the update management question wrong in good faith. Plus exists precisely because self-assessment has that failure mode.
- The controls are the value, not the certificate. Doing all five properly and never certifying leaves a firm better off than certifying and letting them drift. The certificate is the thing a client asks for; the controls are the thing that works.
- It expires. Annual recertification means the controls get re-checked, which is the scheme's quiet strength — most security postures decay silently and this one has a date attached.
What this does not tell you
We are not a security firm and we do not certify anybody. We are writing about it because it is one of the few things a small professional firm can buy where the cost is knowable, the scope is honest and the body recommending it is not selling it.
Prices quoted are the entry price from the NCSC's own page; Plus is quoted by network complexity, so ask. And knowing what you run is the prerequisite for all five controls — a firm that cannot list its own systems cannot honestly answer the questionnaire, which is where the stack check and the cleanup work start.
Questions people actually ask
How much does Cyber Essentials cost?
Certification starts at £320 plus VAT according to the NCSC. Cyber Essentials Plus, which assesses the same five controls with independent technical testing, is quoted based on the complexity of the network rather than at a fixed price.
What are the five Cyber Essentials controls?
Firewalls, secure configuration, security update management, user access control and malware protection. Both Cyber Essentials and Cyber Essentials Plus assess the same five; the difference is that Plus includes independent technical testing to verify they work in practice.
Does Cyber Essentials include insurance?
For UK organisations with turnover under £20 million that certify their whole organisation, yes — if they opt in when completing the assessment. IASME, which arranges it, describes a £25,000 limit of indemnity with a £1,000 excess, including a 24-hour incident response helpline, and the certification costs the same whether or not you opt in.
Is Cyber Essentials enough on its own?
No, and it does not claim to be. The NCSC describes it as the minimum standard, designed against attacks it compares to a thief trying your front door. It is a floor rather than a security programme, and it says nothing about data protection obligations or what your systems are permitted to decide.
Sources
- National Cyber Security Centre, “Cyber Essentials” overview, read 23 September 2026: “Cyber Essentials is the minimum standard of cyber security recommended by the Government for organisations of all sizes”; five technical controls — firewalls, secure configuration, security update management, user access control, malware protection; “most cyber-attacks are basic in nature”, compared to “a thief trying your front door to see if it’s unlocked”; Cyber Essentials starts at £320 + VAT, Plus quoted on network complexity and adding independent technical testing for “higher assurance”; UK organisations under £20m turnover that certify their whole organisation are “automatically entitled to Cyber Liability Insurance arranged by our Cyber Essentials’ Delivery Partner, IASME”, including round-the-clock incident response support with technical, legal and crisis management services. The page does not state the cover’s value or cost. ncsc.gov.uk ↗ — primary; the national technical authority’s own scheme, and it does not sell the certification itself re-checked every 30 days
- IASME, “Cyber Liability Insurance”, read 24 September 2026: “When completing the Cyber Essentials assessment, those eligible for the insurance will be asked to opt-in only if they want the cover”; “a £25,000 limit of indemnity” with “a £1,000 excess (increasing to £5,000 for claims emanating from activities in the USA or Canada)”; a “24hr helpline to report a cyber incident”; “The cost of the Certification remains the same whether or not you opt-in”; a condition to “install & maintain automatically provided updates from your software provider for critical business software”. iasme.co.uk ↗ — primary; the body that arranges the cover, describing its own policy re-checked every 30 days
- The observation that the controls matter more than the certificate, and that supply-chain contracts will make this compulsory before legislation does, are ours. — our own argument, labelled as such
Checked 24 September 2026. Next scheduled check 24 October 2026. Numbers that move — leaderboards, live indices — are re-checked every 30 days; annual datasets and rules in force every six months; dated research once a year. If something here has gone stale before we got to it, tell us and we will correct it and say what changed.
Cite this note
Noxia, “£320 buys five controls, and £25,000 of cover if you tick the box”, Field notes, 23 September 2026; sources checked 24 September 2026. https://www.noxia.co.uk/field-notes/three-hundred-and-twenty-pounds
You cannot answer the questionnaire without knowing what you run.
All five controls assume an inventory — what exists, what it connects to, who owns it, when it was last updated. Most firms do not have one. We build it, keep it current automatically, and it turns out to be the same list you need when a client’s procurement team asks.
Talk to us about thisRead next
Security
A 24-hour clock, and your IT supplier is in scope.
Light-touch notification within 24 hours, full report within 72. Managed service providers and data centres come into scope for the first time.
Advice & compliance
What your agent is allowed to decide on its own, since February.
Article 22 of the UK GDPR was replaced on 5 February 2026 by Articles 22A to 22D. The rule on automated decisions flipped from prohibition-with-exceptions to permission-with-safeguards.
Security
Two hundred people is where a new duty starts.
Standard tier at 200 to 799 expected people, enhanced at 800 and above. The regulator is the Security Industry Authority, which expects the Act to come into force in spring 2027.