AEO Answer

What Does Cyber Essentials Cover? The 5 Technical Controls Explained

A clear, direct answer to this question — written for UK business owners and IT decision-makers.

Direct Answer

Cyber Essentials covers five technical controls: firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management. Together these controls prevent the majority of common internet-borne attacks. They do not cover physical security, social engineering, or advanced threats — which is why Cyber Essentials is a baseline, not a complete security programme.

Key Points

What you need to know.

The Short Answer

55,995 Cyber Essentials certificates were awarded in 2025; 42,288 at CE level and 13,707 at CE Plus.

For UK Businesses

Only 3% of all UK businesses are Cyber Essentials certified — rising to 21% among large businesses.

Cost Considerations

Only 12% of businesses are aware of the Cyber Essentials scheme (51% among large businesses).

Next Steps

Organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance.

Quick Comparison

Feature
Option A
Option B

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.