If you run a dental practice, a care service or any small organisation that handles other people's data, you have probably heard of Cyber Essentials without being entirely sure what it involves. It is one of the most commonly requested certifications in NHS contracts, insurance renewals and supplier onboarding forms, yet the guidance around it is often written for IT specialists rather than practice managers. This guide sets out what Cyber Essentials actually covers, what an assessment looks for, and how it sits alongside other obligations such as the DSPT.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre and delivered through accreditation bodies such as IASME. It gives small and medium organisations a straightforward way to demonstrate that basic technical controls are in place against the most common types of cyber attack.
It is not a full technical audit of your entire network. It is a focused check against five areas that, together, close off the routes that most opportunistic attacks rely on. For a dental practice, care provider or similar regulated small organisation, it is usually the first serious step towards proving that patient or client data is properly protected, and it complements the requirements set out in our guide to the DSPT for dental practices.
Cyber Essentials or Cyber Essentials Plus?
There are two versions of the certification, and it is worth being clear on the difference before you apply.
Cyber Essentials is a self-assessment. You complete a questionnaire about your systems, an assessor reviews your answers, and if everything meets the required standard you are certified.
Cyber Essentials Plus adds an independent technical verification. An assessor actually tests your systems, checking that what is on paper matches reality.
Most small organisations start with the standard certification and move to Plus once they need to satisfy a larger client, an insurer or an NHS commissioner who asks for verified evidence rather than a self-declaration.
The five technical controls
Whichever version you go for, the assessment covers the same five control areas.
Firewalls and internet gateways
Every device connecting to the internet needs to sit behind a properly configured firewall, whether that is a dedicated network firewall or the software firewall built into an operating system. Assessors want to see that default settings have been reviewed, not left exactly as the manufacturer shipped them.
Secure configuration
New devices and software are rarely secure straight out of the box. Default passwords, unnecessary accounts and unused services all widen your attack surface. Secure configuration means switching off what you do not need and changing what should never have been left on default settings in the first place.
User access control
Staff should only have access to the systems and data they actually need for their role, and every account should be protected by a strong, unique password or, better still, multi-factor authentication. Former employees' accounts need to be removed promptly, and administrator-level access should be limited to the smallest possible number of people.
Malware protection
Anti-malware software, application allow-listing or sandboxing: at least one of these needs to be in place on every device that handles your organisation's data, kept up to date and actively scanning.
Security update management
This is the control most organisations fall down on. Operating systems, applications and firmware all need security updates applied within 14 days of release wherever the vendor rates them as critical or high severity, and software that is no longer supported by its vendor cannot be used at all.
Why it matters if you handle patient or client data
For dental practices and care providers, Cyber Essentials rarely stands alone. It sits alongside the DSPT, UK GDPR and, where you carry out direct marketing or use cookies, PECR. Together these form the backbone of what we check for regulated small organisations, because a data breach involving health or care records carries reputational and regulatory consequences well beyond those facing a typical small business. Certification will not, by itself, satisfy every one of those obligations, but it gives you a documented, government-recognised baseline to build the rest of your compliance on.
How the certification process actually works
The process is more approachable than most people expect. You complete an online self-assessment questionnaire covering the five controls above, a qualified assessor reviews your answers against the current technical requirements, and any gaps are flagged for you to fix before certification is granted. Certification lasts twelve months, after which you renew with a fresh assessment. If you would like to see how our own reviews are structured, take a look at how it works.
Common reasons organisations fail first time
A handful of issues account for most first-attempt failures:
- Unsupported software still in use, most often an old version of Windows or a legacy line-of-business application nobody has migrated away from.
- No multi-factor authentication on cloud email or administrator accounts.
- Personal devices used for work without any of the same controls applied.
- No clear record of which devices and software are actually in use, so gaps go unnoticed until the assessor asks.
- Home working setups that were never brought inside the same security policy as the office.
None of these are difficult to fix once identified. They are simply the sort of gaps that build up quietly when nobody has looked at the whole picture in one go.
What it costs and how long it takes
Certification fees for Cyber Essentials are modest, typically in the low hundreds of pounds, with Cyber Essentials Plus costing more because of the added technical testing. For an organisation that already has reasonable IT hygiene, the self-assessment can be completed in a few hours. For one that has never looked at these controls systematically, allow two to four weeks to close the gaps first. That preparation time is where most of the value sits: it is the process of finding and fixing the gaps that actually reduces your risk, not the certificate itself.
Getting started
If you are not sure where your organisation currently stands, start with an inventory: list every device, every piece of software and every cloud service that touches your data. From there, work through the five controls one at a time rather than trying to fix everything at once. You can see current fees for ongoing assurance work on our pricing page.
Not sure where you stand?
Book a free, no-obligation audit and we will tell you honestly where the gaps are, before you commit to a certification date.
Request your free auditCyber Essentials is not a box-ticking exercise if you use it properly. Treated seriously, it is a genuinely useful discipline that keeps the basics in place year after year, and it gives patients, clients and commissioners a clear, independently recognised signal that you take their data seriously.