CYBER ESSENTIALS CERTIFICATION

Cyber Essentials for Schools, Academies and Trusts

Cyber Essentials certification is a condition of DfE funding for colleges, which must certify and renew it annually, and for special post-16 institutions. It is not a certification requirement for schools, academies or multi-academy trusts, and the Academy trust handbook does not mention Cyber Essentials. DfE asks all schools and colleges to be working towards its cyber security core standard, one of 6 core standards, by 2030.

  • IASME-accredited assessor
  • Pre-submission gap analysis
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori

WHO IT APPLIES TO

Do schools need Cyber Essentials?

For a school it is a decision about evidence and assurance, not a compliance obligation. No below means certification is not required; some funding agreements still ask you to work towards the requirements.

NO

Schools

DfE’s wording is that some schools “may wish to complete it as part of their cyber security activities”. Its free plan technology for your school service tracks where you stand.

NO

Academies and multi-academy trusts

The Academy trust handbook says trusts must put proportionate controls in place, and should be working towards the 6 core standards by 2030. Where a trust also draws 16 to 19 or adult skills funding, its conditions of funding add a commitment to work towards the requirements of Cyber Essentials and to show the evidence on request.

YES

Colleges and special post-16 institutions

Colleges must achieve certification and renew it annually, and special post-16 institutions must achieve certification under their 2026/27 conditions of funding. The 2026/27 accountability agreement ties scope to the data the college submits and allows a sub-set scope where appropriate, so whole-organisation cover is a choice, not the contractual minimum.

NO

Local authorities

A local authority that draws 16 to 19 or adult skills funding agrees in its conditions of funding to work towards meeting the requirements of Cyber Essentials. That binds the authority, not each maintained school.

We read the standard line by line in what the DfE cyber standard actually asks for.

WHAT YOU GET

What certification actually gets a school

Cyber Essentials certifies five technical controls, firewalls, secure configuration, security update management, user access control and malware protection, against NCSC’s Requirements for IT Infrastructure v3.3; our managed Cyber Essentials certification page covers each one.

Evidence for the DfE standard

The core standard asks for a cyber risk assessment annually, reviewed every term, with the SLT digital lead accountable. A Cyber Essentials assessment is evidence you can put in front of that review, not a substitute for it, and your governing board can point at it when it minutes the year.

The MFA overlap

DfE words multi-factor authentication as a must: MFA must be enabled for staff accounts with cloud or remote access and for IT admin accounts. Cyber Essentials tests the same control, so the work counts twice. Since the April 2026 update a cloud service with MFA available but not on is an automatic failure.

Assurance a partner can read

The assessment is marked by a qualified assessor and signed off by a board member, which is what a partner asking about your data controls wants to see. Since the April 2026 update it is marked against the Danzell question set, which sits on version 3.3 of the requirements.

Included insurance

Certify the whole organisation with funding under £20 million and you are eligible for included cyber liability insurance with a £25,000 limit of liability. That is IASME’s scheme insurance, separate from the Risk Protection Arrangement and on its own triggers.

PRICING

What Cyber Essentials costs a school

✦ INCLUDED IN EVERY CYBER ESSENTIALS PRICE ✦
IASME-accredited body
Scheme fee inside the price
Certificate issued in house
IASME registry listing
Pre-submission gap review
Free rescheduling
Letter of attestation
Certificate valid 12 months
Cyber Essentials
£400 to £600
Managed self-assessment · 2 to 4 working days

We are the certification body, so the IASME scheme fee is already inside that figure.

Get a quote
Cyber Essentials Plus
£1,200 to £3,500
Assessor-led audit · 5 to 15 days

The same five controls, tested by an assessor rather than self-assessed.

Get a quote

Both figures are from our published price list. IASME’s guidance for schools and colleges sets out how staff numbers and separate networks affect scope, and it is worth asking whether the scheme fee sits inside any other price you are quoted.

SCOPE

Scoping a school or trust estate

Cloud services cannot be excluded from scope, so your Microsoft 365 or Google Workspace tenancy is in, and so is a cloud-hosted MIS.

Devices in scope

IASME puts every device reaching organisational data and services in scope, including staff-owned devices and governors’ laptops. Only a genuinely segregated student or guest network comes out and still counts as whole organisation.

Schools on one network

Where several schools share one network, one assessment must cover them all, so we scope the trust as a single estate. Leaving a school out means segregating it behind a VLAN or firewall first, and a single unpatched server can hold up every school on that network.

Schools on separate networks

Where a trust’s schools sit on separate networks, IASME says it may be better to certify separately, and a trust funded above £20 million only becomes eligible for the insurance by applying school by school. Each school then holds its own certificate, scope and renewal date.

The 14-day update clock

Updates for critical or high-risk vulnerabilities, anything with a CVSS v3 base score of 7 or above, and updates with no vendor severity detail must be applied within 14 days. That clock does not stop for half term, so we scope around term dates.

LIMITS

What Cyber Essentials does not get you

Neither Cyber Essentials nor the Cyber Essentials Plus audit is a penetration test.

What CE Plus actually is

CE Plus is an assessor-led audit, which NCSC describes as more rigorous, independent technical testing of the same protections. It does not look for what an attacker could reach beyond those controls; that is penetration testing for schools and MATs. Since the April 2026 update a second failure at the update management retest revokes the verified self-assessment certificate.

RPA cover

Cyber Essentials does not appear in the Risk Protection Arrangement membership rules, so it will not on its own satisfy a cover condition. What the rules do ask a member to evidence is set out in our school cyber security audit.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a fixed Cyber Essentials quote in 24 hours

A fixed-price Cyber Essentials quote back in one business day from a named IASME-accredited assessor, with an optional pre-submission gap analysis. No sales pipeline.

  • IASME-accredited assessor delivery. Cyber Essentials certification your auditors and clients already recognise.
  • Pre-submission gap analysis so you meet the standard first time. Issues identified before you submit.
  • Direct IASME certificate issuance, listed on the IASME registry.
  • Fixed price, agreed after a short scoping call. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named IASME-accredited assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Pre-submission gap analysis identifies issues before you submit, and we advise you on exactly what to implement so you meet the standard first time.
  4. We send the Cyber Essentials questionnaire and analyse your responses.
  5. Once your submission is compliant, we issue your IASME-stamped certificate and list it on the IASME registry.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed Cyber Essentials quote in 24 hours

24h reply IASME assessor Gap analysis

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

FAQ

Frequently asked questions

What happens if our answers do not meet the standard first time?

Cyber Essentials is a standard you either meet or do not yet meet, not an exam with a mark. Your assessor marks each answer compliant or non-compliant against NCSC’s Requirements for IT Infrastructure. IASME’s guidance is that you need to be compliant in nearly all of the questions, and a few answers, such as using unsupported software in scope, rule out certification on their own. Anything that falls short comes back with the assessor’s reasons, and you correct it and resubmit. IASME carries out one further assessment free of charge, and the scheme terms require that resubmission within 48 hours of the notice, and IASME’s own FAQ puts it as two working days, so we work to the 48 hours. After that you reapply and pay the fee again.

Against a funding deadline the number that matters more is the six months you get to complete an assessment once your account is open, with assessors aiming to mark a submission in around three days. Since the April 2026 update, which applies to assessment accounts opened from late April 2026, a small number of answers are an automatic failure on their own, including missing multi-factor authentication on a cloud service that offers it, and high-risk or critical updates not installed within 14 days. Those are not 48-hour fixes across a trust, which is why we close them before you submit.

Do students count towards our organisation size?

No. IASME treats students as customers rather than employees. Size is the paid staff you present, plus governors who access organisational data.

What evidence does a school produce, and who produces it?

Your answers to the IASME question set, evidence that MFA is on for staff cloud and admin accounts, that in-scope software is patched inside the 14-day window, and a board-level sign-off. The SLT digital lead is accountable; IT support or your MSP does the work.

When in the school year should we certify?

Pick a renewal month you can defend every year. We scope around term dates, and in our experience schools avoid the last fortnight of summer term, when nobody is free to fix a finding in time.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a Cyber Essentials quote for your school

Tell us your paid staff count, your sites, and whether your schools share a network.