top of page

Cyber Essentials for schools and trusts: cost, scope and whether you need it

Aug 28
3 min read

Cyber Essentials reaches a trust board in one of two ways. Either a funder, insurer or contract has asked for it, or somebody has read that schools ought to have it.

Those lead to different decisions, so it is worth separating them before the conversation starts.


What it is

A UK government-backed certification scheme covering five technical controls: firewalls, secure configuration, user access control, malware protection, and security update management.


They are deliberately basic. That is the design — they are the controls that stop the large majority of untargeted attacks, which is most of what any school actually faces. The scheme is not trying to defend you against a determined, targeted adversary. It aims to make you a harder target than average.


The two levels

Cyber Essentials is a self-assessment. You answer questions about your own systems, and the answers are reviewed. Cyber Essentials Plus covers the same five controls, but an assessor independently tests your actual devices and network.

For most trusts, Essentials is the right level. Plus is generally driven by an external requirement rather than an internal risk decision. If nobody is asking for it, the additional assurance rarely justifies the additional cost on its own.


What it costs

Worth knowing before the conversation starts: the DfE updated its cyber security standard for schools in June 2026, reflecting the technical requirements introduced by the NCSC in the scheme's 2026 revision. A trust that assessed itself against the older wording may find some of the questions have moved.

Certification itself is modest, and priced by organisation size. That is not where the money goes.


The real cost is remediation. Working through the questions honestly tends to surface unsupported operating systems. These devices have drifted off the patching schedule, administrators use them for everyday work, and they run a longer list of applications than anyone expected. Fixing those is the expense, and it is the part you can't estimate in advance.


For a trust with several schools that have grown their technology separately, assume the assessment will find things. That is a reason to do it, not a reason to avoid it, but you should budget for it honestly rather than treat it as a certification fee.


Whether you need it

If a funder, an insurer or a contract requires it, the decision is already made, and the only question is timing.

If nothing external requires it, the honest position is that most of the value sits in the gap analysis rather than the certificate. Working through the questions tells you where you stand. The badge tells other people.

That is not an argument against certifying. Being able to demonstrate a baseline is genuinely useful, particularly when an insurer or a parent asks a trust about its arrangements. It is an argument for knowing which of the two things you are buying, so the board can judge whether the price is right.


The governance question underneath

For a multi-academy trust, a prior question matters more than the certificate: would the answers be true across every school, or only for the school that filled in the form?

Certification is usually scoped to a defined boundary. A trust can hold a valid certificate covering central systems while individual schools sit some distance from the same standard. That is not dishonest, and it is easy to miss from a board paper.

So the useful question at board level is not "do we have Cyber Essentials?" It is "what does our certificate cover, and where do the schools outside that scope actually stand?"

 
 
 

Comments


bottom of page