What is Cyber Essentials, and does Microsoft 365 help me pass it?
The short answer: Cyber Essentials is the UK government-backed certification that shows your business has the basic security controls in place to stop the most common cyber attacks. Microsoft 365 can help you meet a lot of it, especially through multi-factor authentication (MFA), device management and malware protection. But passing depends on how it's set up, not just on which licences you pay for.
What Cyber Essentials is
Cyber Essentials is run by IASME on behalf of the National Cyber Security Centre (NCSC). It comes in two levels:
- Cyber Essentials is a self-assessment. You answer a set of questions online about how your IT is set up, and an independent assessor reviews your answers.
- Cyber Essentials Plus has the same requirements, but an assessor also tests your systems technically, checking a sample of your devices and accounts to confirm things really are as you said.
Certification lasts 12 months, so you renew each year.
Why businesses get it
- Government contracts. It's often required for UK government contracts, particularly where personal information is handled.
- Customers and supply chains. Larger customers increasingly ask suppliers for it.
- Insurance. Cyber insurers often ask whether you have it.
- Peace of mind. The controls genuinely block a large share of everyday attacks, such as stolen passwords and unpatched software.
The five control areas
Everything in Cyber Essentials falls under five headings:
- Firewalls. Devices and your internet connection are protected by a properly configured firewall.
- Secure configuration. Default passwords are changed, unnecessary software and accounts are removed, and devices lock when not in use.
- User access control. People only have the access they need, admin accounts are used only for admin tasks, and accounts are protected with strong passwords and MFA.
- Malware protection. Devices have anti-malware protection, or only allow approved apps.
- Security update management. Software and operating systems are supported and kept up to date.
What's changed in the latest version
The requirements are updated from time to time. The current version, v3.3, uses a question set called Danzell and applies to assessment accounts created from late April 2026, replacing v3.2 (the Willow question set). The changes that matter most for small businesses are:
- MFA on cloud services is now a must. If a cloud service you use offers MFA, it must be switched on. Missing MFA on an in-scope cloud service is an automatic fail.
- Cloud services can't be left out. Services like Microsoft 365, Xero or your CRM are in scope and can't be excluded.
- Updates within 14 days. Security updates rated high-risk or critical must be applied within 14 days of release.
If you last certified under an older version, don't assume you'll pass the same way again.
How Microsoft 365 helps
Microsoft 365 includes many of the tools you need, particularly on Business Premium:
- MFA and Conditional Access protect sign-ins and can block access from risky or unmanaged devices.
- Intune lets you enforce settings across laptops and phones: screen locks, encryption, firewall on, and Windows updates installed on time.
- Microsoft Defender provides malware protection and helps you spot devices that aren't up to date.
Business Basic and Standard include MFA, but not Intune or Conditional Access, which makes the device side much harder to manage and prove. See Business Basic vs Standard vs Premium for the differences.
It's the setup that counts
Owning Business Premium doesn't mean you'll pass. The features have to be switched on, configured properly and applied to every person and device in scope. Common sticking points are:
- one or two accounts without MFA, often an old admin account or a shared login
- laptops not enrolled in Intune, so updates aren't enforced
- people working as local administrators on their own computers
- old devices running software that no longer gets security updates
Our free Microsoft 365 audit checks many of these settings and shows where the gaps are before an assessor finds them.
Common questions
How long does it take to get certified?
If your setup is already in good shape, the self-assessment can be completed in a few days. Most of the time goes into fixing the gaps it uncovers, such as switching on MFA or updating old devices.
Do I need Cyber Essentials Plus?
Only if a customer, contract or insurer asks for it. Many small businesses start with Cyber Essentials and move to Plus later. The requirements are the same; Plus just adds independent testing.
Do staff phones and home computers count?
Usually, yes. Any device that accesses your business data or services, including personal phones used for work email, is normally in scope. This is often the trickiest part for small businesses.
Can Microsoft 365 alone get us certified?
It covers a lot, but not everything. Things like your office router or firewall, and any non-Microsoft software or cloud services, are also part of the assessment.
Want us to check yours?
Our free Microsoft 365 audit looks at your licences, security, email and backups, and tells you in plain English what to fix first. No card, no obligation.