The tender packs keep doing this to people. Thirty pages, and question 14 asks for a certificate number and an expiry date. The office manager opening it has a renewal email from the insurance broker in one folder and something from an IT company in another. Both mention cyber. Neither obviously answers question 14.
The short version: Cyber Essentials is a certification that says your business meets a defined security baseline. Cyber insurance is a policy that pays out when something goes wrong. One describes the state of your business; the other describes what happens after. Question 14 almost always wants the certificate.
But the confusion is more reasonable than it looks, and it’s worth saying why before going further.
Is insurance really included with Cyber Essentials?
Yes, and this is half the reason the two get merged in people’s heads. Cyber Essentials certification includes cyber liability insurance for organisations with UK turnover under £20 million that certify their whole organisation. It’s arranged by IASME and comes with incident response support. That’s not a sales add-on someone invented; it’s described in the NCSC’s own guidance on the scheme.
So a business owner who says “we got certified, so we’re covered” isn’t being sloppy. They’re describing something that exists. What they usually mean, and what matters when a claim form appears, is that they hold a small included policy attached to a certification, which isn’t the same thing as a cyber insurance policy chosen for their actual risk. Both can be true at once.
What is Cyber Essentials, exactly?
Cyber Essentials is a UK government-backed certification, developed by the NCSC (the National Cyber Security Centre, the government body responsible for cyber security guidance) and run by IASME, its official delivery partner, through a network of certification bodies.
It covers five technical control areas: firewalls, secure configuration, security update management, user access control, and malware protection. That’s the whole scope, and it’s meant to be. The five areas cover the things that go wrong most ordinarily, not every threat a business could theoretically face.
The basic certification is a self-assessment: the business answers the questions, someone at board level signs it off, and an assessor marks it. Cyber Essentials Plus covers the same five areas but adds independent hands-on testing; an assessor checks the controls really work rather than taking the answers on trust. Basic certification starts from £320 plus VAT, and both renew annually.
The current requirements document is Requirements for IT Infrastructure v3.3, applying to assessment accounts created from late April 2026, with a transition period for existing accounts. Three things in it are worth knowing before you start. Multi-factor authentication on cloud services, where available, is an auto-fail question: answer it wrong and the assessment fails outright. Two of the security-update questions work the same way. And the scope reaches further than people expect: cloud services can’t be excluded, and staff phones and laptops used for work are in scope too, including personal ones that open work email.
What does cyber insurance actually do?
Cyber insurance is a commercial policy. You buy it, usually through a broker, and it pays out under defined conditions: business interruption after an incident, the cost of getting systems back, legal and notification costs, sometimes ransom-related expenses depending on the policy. It renews annually, like the certification, which is part of why the two end up in the same mental drawer.
What it doesn’t do is make your business more secure. A policy has no opinion on whether your firewall is configured properly. It has an opinion on what it will pay if the firewall wasn’t.
Cover varies enormously between insurers and between policies from the same insurer. If you want to know what yours actually covers, the schedule is the only reliable answer, and it’s usually a shorter read than people expect.
The two-documents rule
A certificate is not a payout. A policy is not a control.
Cyber Essentials describes your business as it is today: these five things are in place, an assessor checked, here’s a number and a date. Cyber insurance describes a future conditional: if this happens, we’ll pay for that.
You can hold a certificate and have no insurance beyond the included policy. You can hold substantial insurance and fail the assessment on the multi-factor authentication question. Neither situation is contradictory; they measure different things. A prospective client asking about your security wants the certificate. A finance director asking about your exposure wants the policy schedule.
We see the two confused in both directions, and one of them costs more. When we ask a business whether they hold any cyber certifications, the answer is quite often that the insurance was renewed in March. Fair answer, wrong document. The reverse mistake is quieter: treating the certificate as if it were the protection, when what the insurer actually relies on is the answers given at renewal still being true.
Which document does the form want?
When a tender or client questionnaire asks for a certificate number, it wants the Cyber Essentials certificate: the number issued by the certification body, plus the expiry date. Insurance policy numbers don’t go in that box. If the form wants proof of insurance it will usually ask separately, for a certificate of insurance or a liability schedule, and it will ask about cover limits, which certifications don’t have.
Public sector contracts and larger private buyers often specify a minimum: Cyber Essentials, or Cyber Essentials Plus. If the form says Plus and you hold basic, those are different certificates, and the gap between them is real assessment work rather than paperwork.
What’s worth writing down?
Most of the confusion disappears the moment both documents live in one place with four facts each. Copy this wherever your business actually looks:
- Cyber Essentials certificate · issued by a certification body accredited by IASME, the NCSC’s delivery partner · proves the five control areas were met at the point of assessment · expires one year from certification.
- Cyber insurance policy · issued by your insurer, usually via a broker · promises defined losses will be covered up to defined limits, subject to conditions · expires at the policy renewal date.
Add the certificate number and the policy number, and question 14 takes about ninety seconds next time.
Would we still pass in month six?
Passing the assessment and being able to demonstrate the same controls eleven months later are different achievements. Cyber Essentials is a point-in-time check. Staff join, someone in accounts signs up for a new cloud service, a laptop quietly falls out of the management console and stops taking updates.
None of that makes the certificate dishonest. It means the useful question around month six isn’t “are we certified” but “would we pass today”. It’s the someone’s-word test applied to your own answers: if nobody’s checked since the assessment, you don’t have the controls, you’ve got last year’s word for them. And the same aging problem applies to the declarations on your insurance proposal form, which is the quieter risk of the two, because nothing audits those between renewals either.
For businesses whose IT we manage day to day, certification is roughly a day’s work plus the certificate fee, because the five controls are already the day job; that’s the position managed IT support is meant to put you in. If the answer to “would we pass today” is yes, renewal is paperwork. If it’s uncertain, the gap is easier to close now than the week before the assessment window opens, and easier still than explaining it on a claim form.
Quick answers
Do we need Cyber Essentials Plus or is basic enough? Let the contracts decide. If the tenders and client questionnaires you chase name Plus, you need Plus; if they name Cyber Essentials without qualification, basic satisfies them. Buying Plus speculatively is rarely the right first move; winning work that demands it is.
Does holding the certificate reduce insurance premiums? Sometimes insurers ask about it, and demonstrating the five controls can’t hurt the conversation. But pricing varies too much to promise a discount, and the more direct benefit is fewer awkward gaps between what the proposal form claims and what’s actually in place.
We’re a five-person business. Is certification worth it? If you sell to the public sector or to larger firms, the question tends to answer itself the first time a tender asks. If you don’t, the five controls are still the right baseline, and the honest option is implementing them without the certificate until a contract makes the badge worth its fee.
How fast can we get certified? It depends entirely on how far your current setup sits from the five controls. The assessment itself is quick; closing gaps (multi-factor authentication everywhere, update management that actually enforces, tidy access control) is where the calendar time goes. Get the gaps reviewed before you book the assessment, not after.
If you would like any help or advice, get in touch today!
