Cyber Essentials for a small team: what actually has to change

Certification is the paperwork. The five controls behind it are ordinary engineering decisions, and most small teams are closer to passing than they think.
5 September 2026
3 min read

Most small businesses meet Cyber Essentials for the first time as a procurement obstacle: a customer, an insurer, or a public-sector framework asks for it, and suddenly a certification nobody had planned for is on the critical path to revenue.

The good news is that the five controls behind it are not exotic. They are the things a competent IT setup does anyway. Here is what actually has to change in a typical twenty-person company.

The five controls, in plain terms

  • Firewalls. Every device that connects to the internet sits behind a properly configured firewall, with default administrative passwords changed and no management interface exposed to the public internet.
  • Secure configuration. Default accounts removed, unnecessary software and services uninstalled, and no auto-run of untrusted content.
  • User access control. Named accounts, no shared logins, administrative rights granted only where needed, and access removed promptly when someone leaves.
  • Malware protection. Anti-malware active and updating on every device, or an equivalent control such as application allow-listing.
  • Patch management. Operating systems and applications supported by their vendor and patched within fourteen days for high-severity issues.

Where small teams actually fail

In practice, the certification questionnaire is rarely failed on firewalls or antivirus. It is failed on three unglamorous things.

The first is leavers. Nearly every small company has an offboarding process for the laptop and none for the twelve SaaS accounts. Someone who left eight months ago still has access to the file store, and nobody can say so with confidence because there is no list.

The second is unsupported software. A machine still running an operating system past end-of-life, or a business-critical application whose vendor stopped shipping security updates two years ago, fails the assessment outright, and no amount of policy writing fixes it.

The third is personal devices. If staff read company email on their own phones, those phones are in scope. That surprises people, and it is usually solved with a mobile management policy rather than a purchase.

What good preparation looks like

Start with an honest inventory: every device, every account, every piece of software, and who has access to what. Most of the real risk closes in the first phase: multi-factor authentication switched on everywhere, encryption enabled, patching automated, backups verified by an actual restore rather than a green tick in a console.

Then close the gaps the inventory exposed, evidence each one as you go, and only then approach the certification body. Preparing properly and applying once is cheaper than applying, failing, and remediating under a deadline.

A note on what certification does and does not prove

Cyber Essentials demonstrates that a baseline of sensible controls is in place. It does not mean an organisation cannot be breached, and treating it as a finish line is how companies end up with a certificate on the wall and no incident runbook.

The controls are worth implementing whether or not a customer is asking for the badge. The badge is worth having because it opens procurement doors, and because working through it forces the leaver problem to finally get solved.

Delisys Technologies prepares small and mid-sized businesses for Cyber Essentials and ISO 27001: controls implemented, evidence collected, gaps closed. The certificate is issued by the certification body, not by us. Our part is making sure the assessment is a formality by the time you get there.