Cyber Essentials for Schools, Academies and Trusts
Cyber Essentials certification is a condition of DfE funding for colleges, which must certify and renew it annually, and for special post-16 institutions. It is not a certification requirement for schools, academies or multi-academy trusts, and the Academy trust handbook does not mention Cyber Essentials. DfE asks all schools and colleges to be working towards its cyber security core standard, one of 6 core standards, by 2030.
- IASME-accredited assessor
- Pre-submission gap analysis
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
WHO IT APPLIES TO
Do schools need Cyber Essentials?
For a school it is a decision about evidence and assurance, not a compliance obligation. No below means certification is not required; some funding agreements still ask you to work towards the requirements.
Schools
DfE’s wording is that some schools “may wish to complete it as part of their cyber security activities”. Its free plan technology for your school service tracks where you stand.
Academies and multi-academy trusts
The Academy trust handbook says trusts must put proportionate controls in place, and should be working towards the 6 core standards by 2030. Where a trust also draws 16 to 19 or adult skills funding, its conditions of funding add a commitment to work towards the requirements of Cyber Essentials and to show the evidence on request.
Colleges and special post-16 institutions
Colleges must achieve certification and renew it annually, and special post-16 institutions must achieve certification under their 2026/27 conditions of funding. The 2026/27 accountability agreement ties scope to the data the college submits and allows a sub-set scope where appropriate, so whole-organisation cover is a choice, not the contractual minimum.
Local authorities
A local authority that draws 16 to 19 or adult skills funding agrees in its conditions of funding to work towards meeting the requirements of Cyber Essentials. That binds the authority, not each maintained school.
We read the standard line by line in what the DfE cyber standard actually asks for.
WHAT YOU GET
What certification actually gets a school
Cyber Essentials certifies five technical controls, firewalls, secure configuration, security update management, user access control and malware protection, against NCSC’s Requirements for IT Infrastructure v3.3; our managed Cyber Essentials certification page covers each one.
The core standard asks for a cyber risk assessment annually, reviewed every term, with the SLT digital lead accountable. A Cyber Essentials assessment is evidence you can put in front of that review, not a substitute for it, and your governing board can point at it when it minutes the year.
DfE words multi-factor authentication as a must: MFA must be enabled for staff accounts with cloud or remote access and for IT admin accounts. Cyber Essentials tests the same control, so the work counts twice. Since the April 2026 update a cloud service with MFA available but not on is an automatic failure.
The assessment is marked by a qualified assessor and signed off by a board member, which is what a partner asking about your data controls wants to see. Since the April 2026 update it is marked against the Danzell question set, which sits on version 3.3 of the requirements.
Certify the whole organisation with funding under £20 million and you are eligible for included cyber liability insurance with a £25,000 limit of liability. That is IASME’s scheme insurance, separate from the Risk Protection Arrangement and on its own triggers.
PRICING
What Cyber Essentials costs a school
Managed self-assessment · 2 to 4 working days
We are the certification body, so the IASME scheme fee is already inside that figure.
Get a quoteAssessor-led audit · 5 to 15 days
The same five controls, tested by an assessor rather than self-assessed.
Get a quoteBoth figures are from our published price list. IASME’s guidance for schools and colleges sets out how staff numbers and separate networks affect scope, and it is worth asking whether the scheme fee sits inside any other price you are quoted.
SCOPE
Scoping a school or trust estate
Cloud services cannot be excluded from scope, so your Microsoft 365 or Google Workspace tenancy is in, and so is a cloud-hosted MIS.
IASME puts every device reaching organisational data and services in scope, including staff-owned devices and governors’ laptops. Only a genuinely segregated student or guest network comes out and still counts as whole organisation.
Where several schools share one network, one assessment must cover them all, so we scope the trust as a single estate. Leaving a school out means segregating it behind a VLAN or firewall first, and a single unpatched server can hold up every school on that network.
Where a trust’s schools sit on separate networks, IASME says it may be better to certify separately, and a trust funded above £20 million only becomes eligible for the insurance by applying school by school. Each school then holds its own certificate, scope and renewal date.
Updates for critical or high-risk vulnerabilities, anything with a CVSS v3 base score of 7 or above, and updates with no vendor severity detail must be applied within 14 days. That clock does not stop for half term, so we scope around term dates.
LIMITS
What Cyber Essentials does not get you
Neither Cyber Essentials nor the Cyber Essentials Plus audit is a penetration test.
CE Plus is an assessor-led audit, which NCSC describes as more rigorous, independent technical testing of the same protections. It does not look for what an attacker could reach beyond those controls; that is penetration testing for schools and MATs. Since the April 2026 update a second failure at the update management retest revokes the verified self-assessment certificate.
Cyber Essentials does not appear in the Risk Protection Arrangement membership rules, so it will not on its own satisfy a cover condition. What the rules do ask a member to evidence is set out in our school cyber security audit.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a fixed Cyber Essentials quote in 24 hours
A fixed-price Cyber Essentials quote back in one business day from a named IASME-accredited assessor, with an optional pre-submission gap analysis. No sales pipeline.
- IASME-accredited assessor delivery. Cyber Essentials certification your auditors and clients already recognise.
- Pre-submission gap analysis so you meet the standard first time. Issues identified before you submit.
- Direct IASME certificate issuance, listed on the IASME registry.
- Fixed price, agreed after a short scoping call. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named IASME-accredited assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Pre-submission gap analysis identifies issues before you submit, and we advise you on exactly what to implement so you meet the standard first time.
- We send the Cyber Essentials questionnaire and analyse your responses.
- Once your submission is compliant, we issue your IASME-stamped certificate and list it on the IASME registry.
Get your fixed Cyber Essentials quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named IASME-accredited assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
BY SECTOR
Sectors we test
Law firms
Client files and case systems.
Law firms sector pageHealthcare
Patient data and clinical systems.
Healthcare sector pageFintech
Payment flows and FCA-regulated estates.
Fintech sector pageSaaS
Multi-tenant platforms and customer APIs.
SaaS sector pagePublic sector
Testing evidence procurement teams accept.
Public sector pageInsurance
Policyholder data and underwriting platforms.
Insurance sector pageWe deliver on-site or remotely UK-wide; for the capital, see penetration testing London, or browse all sectors.
FAQ
Frequently asked questions
What happens if our answers do not meet the standard first time?
Cyber Essentials is a standard you either meet or do not yet meet, not an exam with a mark. Your assessor marks each answer compliant or non-compliant against NCSC’s Requirements for IT Infrastructure. IASME’s guidance is that you need to be compliant in nearly all of the questions, and a few answers, such as using unsupported software in scope, rule out certification on their own. Anything that falls short comes back with the assessor’s reasons, and you correct it and resubmit. IASME carries out one further assessment free of charge, and the scheme terms require that resubmission within 48 hours of the notice, and IASME’s own FAQ puts it as two working days, so we work to the 48 hours. After that you reapply and pay the fee again.
Against a funding deadline the number that matters more is the six months you get to complete an assessment once your account is open, with assessors aiming to mark a submission in around three days. Since the April 2026 update, which applies to assessment accounts opened from late April 2026, a small number of answers are an automatic failure on their own, including missing multi-factor authentication on a cloud service that offers it, and high-risk or critical updates not installed within 14 days. Those are not 48-hour fixes across a trust, which is why we close them before you submit.
Do students count towards our organisation size?
No. IASME treats students as customers rather than employees. Size is the paid staff you present, plus governors who access organisational data.
What evidence does a school produce, and who produces it?
Your answers to the IASME question set, evidence that MFA is on for staff cloud and admin accounts, that in-scope software is patched inside the 14-day window, and a board-level sign-off. The SLT digital lead is accountable; IT support or your MSP does the work.
When in the school year should we certify?
Pick a renewal month you can defend every year. We scope around term dates, and in our experience schools avoid the last fortnight of summer term, when nobody is free to fix a finding in time.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a Cyber Essentials quote for your school
Tell us your paid staff count, your sites, and whether your schools share a network.



