Blog Cyber Essentials

Cyber Essentials for the one-person business, everything you need to know

9 August 2026 · 8 min read

If you run a business on your own, a consultancy, a freelance practice, a one-person legal firm, an independent contractor working for larger clients, you have probably been asked about Cyber Essentials. The question usually comes from a prospective client. It usually comes at the moment you are about to sign a contract. And it usually contains the phrase "we need to see your Cyber Essentials certificate before we can proceed".

The good news is that Cyber Essentials was not designed only for large enterprises. The government-backed scheme, run under the National Cyber Security Centre (NCSC) and administered by IASME, is explicitly open to organisations of any size. Sole traders and one-person limited companies pass every day.

The less good news is that most of the guidance you find online was written for firms with an IT team. This article rewrites the five controls for the situation you actually face: one person, one laptop, maybe a phone, using cloud tools bought from other people, without an IT department.

What Cyber Essentials actually is

Cyber Essentials is a certification. The scheme sets out five areas of technical control. To achieve certification, you answer a self-assessment questionnaire that confirms your systems meet the requirements in each area. An accredited certification body reviews your answers. If they pass, you get a certificate valid for one year.

There are two levels. Cyber Essentials (basic) is a self-assessment, verified against your answers. Cyber Essentials Plus requires an external technical assessor to actually test your systems by running vulnerability scans and checking configurations, on top of the questionnaire.

For most one-person businesses, basic Cyber Essentials is the right starting point. Plus is worth considering later when you are being asked for it specifically by clients in regulated sectors, or when you handle particularly sensitive data.

Certification is not just paperwork. It comes with free automatic cyber insurance for UK-domiciled organisations with a turnover under £20 million. The insurance is limited but real: up to £25,000 of cover for cyber incidents, subject to the certificate remaining valid. This alone is worth more than the certification cost for most sole traders.

Whether a one-person business is eligible

Yes. The scheme covers organisations of all sizes, from central government departments to individual freelancers. There is no minimum headcount.

The only practical constraint is that you must define what is inside the certification "scope". For a sole trader this is straightforward: the scope is everything you use for work. Your work laptop, your work phone, the cloud accounts you use to deliver client services (email, cloud storage, accounting software), and the network you connect from.

If you have any personal-only devices that never touch work data, they sit outside scope. If your work and personal use overlap on the same device (as it often does for sole traders), that device is in scope and must meet all the controls.

The five controls in plain English

Cyber Essentials specifies five families of technical control. Here is what each means for a one-person business.

1. Firewalls

The purpose of the firewall control is to make sure that connections from the internet into your devices, and from your devices out to the internet, are properly filtered.

For a sole trader this comes down to two things. First, the router your internet provider supplied should have its default administrative password changed to something only you know. This is by far the most common Cyber Essentials failure at the small-business end, the router still has the sticker with the default password taped to the side. Change it. Write the new one down in a password manager.

Second, the built-in firewall on your laptop and phone must be turned on. On Windows this is the Windows Defender Firewall; on macOS it is under System Settings → Network → Firewall. Both are on by default on modern devices, but you need to be able to confirm this on the assessment.

2. Secure configuration

This control is about making sure the devices and software you use are not still running default settings that would make them easier to compromise.

Three concrete steps cover most of this for a sole trader.

Turn off any features you do not use, an unused Bluetooth radio, unused user accounts on a shared laptop, guest network access on the router if you never need it. Remove any pre-installed software you never open (Windows machines especially tend to arrive with trial software that can quietly become a security liability if it stops receiving updates).

If your device has autoplay enabled for USB drives or SD cards, turn it off. This has been a standard malware vector for two decades and is still exploited today.

Set an automatic screen lock. Ten minutes is the maximum most Cyber Essentials assessors will accept for a work device. Five is better.

3. Security update management

This is the most-failed control at every scale, from sole traders to enterprises. Applications and operating systems need to receive security updates promptly.

The Cyber Essentials requirement is that "high-risk or critical" security updates must be applied within 14 days of release. If an update is not installed in that window and it fixes a serious vulnerability, you fail this control.

For a one-person business the safest position is to turn on automatic updates for everything. On your laptop, enable automatic operating system updates. In every application you use, check for the "install updates automatically" setting and turn it on. On your phone, allow overnight automatic updates.

Any software that has stopped receiving vendor updates (an old version of Photoshop, a discontinued email client, an unsupported Windows version) must be removed from any device in scope. There is no exception for "but I only use it occasionally".

4. User access control

The point of this control is to make sure only you can access the systems that hold your work data, and that even if someone steals your laptop, they cannot easily become you.

Three requirements matter for a sole trader.

Use a proper password on every account, and store it in a password manager. Reused passwords are the single biggest reason breaches spread. A password manager (Bitwarden, 1Password, or the one built into your browser if it is your only device) removes the incentive to reuse. Do not write passwords in a notes app.

Turn on multi-factor authentication (MFA) on every account that supports it. Email first, then cloud storage, then accounting, then everything else. If a client's platform does not offer MFA in 2026, that is a signal about the client's own security posture worth noticing.

Do not use an administrator account for everyday work. On Windows this means creating a standard user account for daily use and only switching to the administrator account when you need to install software. On macOS the same principle applies. This alone prevents a large percentage of malware from being able to install itself.

5. Malware protection

You need either anti-malware software, or an application allow-list, or a sandboxed device, one of the three, on every in-scope device.

For most sole traders the practical answer is "use the built-in anti-malware that your operating system already provides". Windows Defender on Windows 11 is more than adequate to pass Cyber Essentials. macOS ships with XProtect and Gatekeeper built in, and the assessor will accept these. You do not need to buy third-party anti-virus software for this control.

You do need to make sure the built-in protection is switched on and receiving updates automatically, see the previous section.

The three routes to certification

You can approach Cyber Essentials three ways.

Self-serve. Register directly with IASME, complete the online questionnaire yourself, and submit for review. This is the cheapest option. Typical cost sits at £320 to £600 depending on organisation size band. A sole trader falls in the lowest band.

Consultant-assisted. Engage a specialist to help you complete the questionnaire, remediate any gaps in your controls, and submit for you. This costs more (£800 to £1,500 for a sole trader typically), but reduces the risk of failing your first assessment and having to remediate anyway.

Managed service. A cyber security firm handles the whole thing including ongoing maintenance of the controls between annual renewals. This is the highest-cost option (£2,000 upward per year) but the least effort on your side.

For most one-person businesses, self-serve is the correct starting point. Read the question set in advance, spend a weekend making the changes described above, then submit. If you fail, most certification bodies give you a short window to remediate and resubmit at no additional cost.

What it costs in 2026

Certification costs are set by IASME and depend on the size of your organisation. For a sole trader or one-person limited company:

The Cyber Essentials basic certificate should be treated as an operating cost, not a one-off project. It renews annually. Setting a calendar reminder for two months before expiry avoids the awkward moment of realising your certificate has lapsed the week a new client asks for it.

Common mistakes that cause a first-time failure

Four things trip up sole traders on their first attempt:

  1. Old software still installed but unused. Assessors ask what software is on your devices, not what you actively use. If there is an unsupported version of anything installed, remove it before applying.
  2. Personal devices used for work but out of scope on paper. If your personal iPad is where you check work email in the evening, that iPad is in scope. Either declare it and secure it, or genuinely stop using it for work.
  3. Router with default admin password. The single most common failure. Log into your router today and change it.
  4. MFA missing on a cloud service you had forgotten about. Old accounts from previous projects can quietly become the weakest link. Audit every cloud service you have credentials for.

Cyber Essentials is not a difficult certification. It is a documentation exercise on top of a small amount of practical hardening. The value is that it forces you to actually do the hardening, and it gives clients the certificate they need to see before they can engage you.

Sources

  1. National Cyber Security Centre (NCSC), Cyber Essentials overview, https://www.ncsc.gov.uk/cyberessentials/overview
  2. IASME, official Cyber Essentials certification body, https://iasme.co.uk/cyber-essentials/
  3. IASME, preview of the Cyber Essentials self-assessment questions, https://iasme.co.uk/cyber-essentials/preview-the-self-assessment-questions-for-cyber-essentials/
  4. GOV.UK, Cyber Essentials scheme overview, https://www.gov.uk/government/publications/cyber-essentials-scheme-overview
  5. NCSC guidance on multi-factor authentication, https://www.ncsc.gov.uk/collection/passwords/updating-your-approach
  6. IASME cyber insurance eligibility criteria, https://iasme.co.uk/cyber-essentials/cyber-liability-insurance/

Want to know where you stand?

We assess your public web and email surface and send you a written report. No charge, no obligation.

Book a free audit

← Back to the blog