Cyber Essentials for property management companies has quietly changed from a badge some firms collected to a condition of winning and keeping work. Local authorities, housing associations, build-to-rent investors, insurers and institutional landlords increasingly ask for the certificate before they hand a managing agent a portfolio. If you cannot produce one, you are not negotiating on price — you are not on the list at all.

The scheme itself also moved. On 26 April 2026 the Cyber Essentials question set changed from Willow to Danzell, and the change was not cosmetic. Three requirements that used to cost you points now fail the whole assessment outright. That is why Cyber Essentials for property management firms is a different exercise in 2026 than it was a year ago: a managing agent that certified comfortably in 2025 can fail without changing a single thing about how it operates.

This guide is written specifically for lettings agencies, block and estate management firms, build-to-rent operators and managing agents. It covers what Cyber Essentials for property management companies actually asks, where property businesses reliably trip, what it costs, how long it takes, and what the assessor wants to see. It builds on our IT support guide for property management companies and our Microsoft 365 security checklist for property firms, and on three certification guides that cover the scheme generically: why applications fail, Cyber Essentials Plus compared with ISO 27001 and what unsupported software does to a certification.

Where those guides ask what does the scheme require, this one asks what does the scheme require of a firm that manages other people’s buildings, money and tenants.

Why Cyber Essentials for Property Management Is Now a Contract Requirement

cyber essentials for property management companies b key bunch on ring

Cyber Essentials was designed by the UK government as a baseline: five technical controls that stop the commodity attacks which make up the overwhelming majority of incidents. It is not an information security management system and it does not pretend to be. What it does is prove, to a third party, that the basics are actually switched on. Framed that way, Cyber Essentials for property management is less a security project than a commercial credential with a technical exam attached.

Property firms hold an unusually rich data set

A managing agent is a data controller for a remarkably sensitive collection: passport and visa scans gathered for right-to-rent checks, bank details for standing orders and deposit returns, landlord statements, contractor invoices, tenancy agreements, vulnerability and adjustment records, key registers and alarm codes. It also moves money — rent, service charges, deposits and contractor payments — often through accounts it does not own. That combination is why Cyber Essentials for property management firms attracts more scrutiny than the headcount alone would suggest.

Where the certification demand actually comes from

Procurement Policy Note 014, which replaced PPN 09/23 and PPN 09/14, is the binding rule for central government departments, executive agencies, non-departmental public bodies and NHS organisations. It requires those buyers to apply proportionate cyber controls to relevant contracts and to state any Cyber Essentials requirement in the tender notice. Local authorities and housing associations are not formally in scope, but a great many of them apply the same standard when appointing managing agents — which is how Cyber Essentials for property management became a procurement question rather than an IT one.

The rule buyers forget to mention

PPN 014 also obliges in-scope buyers to accept equivalents, in line with section 56 of the Procurement Act 2023. In practice, “equivalent” means you must demonstrate the same controls to the buyer’s satisfaction — which is usually slower and more expensive than simply holding the certificate. For most agents, treating Cyber Essentials for property management as the default route is cheaper than arguing equivalence at every tender.

Who asksWhat they typically ask forWhen it comes up
Local authority housing teamsCyber Essentials, sometimes PlusTender and annual re-approval
Housing associationsCyber Essentials plus a data-protection annexSupplier onboarding
Institutional and BTR landlordsCyber Essentials PlusManagement agreement renewal
Cyber insurersCertificate as a rating factorRenewal questionnaire
Corporate landlords and fundsCertificate plus a security questionnaireDue diligence before instruction
Redress and client-money auditorsEvidence of access controlAnnual audit

The sector already has a regulatory scar

The Information Commissioner’s Office fined the London estate agency Life at Parliament View Limited £80,000 after the personal data of 18,610 tenants and landlords sat openly accessible for close to two years. The cause was mundane — an anonymous-authentication setting left switched on during a server transfer. Exposed records included bank statements, salary details, dates of birth and passport copies. That penalty landed under the Data Protection Act 1998; under UK GDPR the ceiling is £17.5 million or four per cent of global turnover.

Most of the sector has not done the basics

UK businesses with each control in place (Cyber Security Breaches Survey 2025/2026)
Two-factor authentication of any kind 47%
A formal incident response plan 25%
Any review of supplier cyber risk 15%
Holding a Cyber Essentials certificate 5%

Only five per cent of UK businesses hold the certificate at all. In a tender where three agents bid and one is certified, that number stops being a statistic and starts being a differentiator, which is the commercial case for Cyber Essentials for property management in one line. The same survey found 43 per cent of businesses — roughly 612,000 organisations — identified a breach or attack in the previous twelve months, with phishing involved in 38 per cent of cases and rated the most disruptive attack type by 69 per cent of those affected.

What Changed in April 2026: The Danzell Question Set

cyber essentials for property management companies c desk calendar block spiral binding

IASME published the Danzell question set on 13 February 2026 and it took effect on 26 April 2026, replacing Willow. Assessment accounts created before that date kept a six-month window to finish under the old rules; everyone renewing afterwards answers Danzell. Anyone planning Cyber Essentials for property management work in the current cycle is answering the new set.

Three answers that now fail the whole assessment

Under Willow these were major non-compliances that pulled your score down. Under Danzell each is an outright auto-fail with no remediation opportunity in that submission. Anyone preparing Cyber Essentials for property management work should treat these three as gating items rather than line items.

The first is multi-factor authentication on cloud services. If MFA is available on an in-scope cloud service and is not enabled for every user, the assessment fails — and “available” includes MFA that requires a higher licence tier. The second and third are the new questions A6.4 and A6.5: high-risk and critical updates must be installed within fourteen days of release, A6.4 covering operating systems and router and firewall firmware, A6.5 covering applications and their associated files and extensions.

Cloud services can no longer be scoped out

Danzell adds a formal definition of a cloud service — on-demand, scalable, on shared infrastructure, reached over the internet through an account, storing or processing your data — and states plainly that cloud services cannot be excluded from scope. For anyone doing Cyber Essentials for property management this is the single most consequential sentence in the document, because the property CRM, the maintenance portal, the accounting package and the document store are all cloud services and all now in scope by definition.

Scope descriptions and legal entities

Detailed scope descriptions are now unlimited in length. Anything you exclude must be described specifically and justified rather than waved away with a generic phrase, though that description is not published. Every legal entity inside the scope must be identified by name, registered address and company number — which matters more for Cyber Essentials for property management than most sectors, because lettings, block management and a maintenance arm so often sit in separate companies. Individual certificates for each entity are available for a small additional fee.

AreaWillow (to April 2026)Danzell (from 26 April 2026)
MFA on cloud servicesMajor non-complianceAuto-fail
14-day critical patchingMajor non-complianceAuto-fail via A6.4 and A6.5
Cloud service exclusionsPermitted in some casesNot permitted
Scope description lengthLimitedUnlimited, exclusions justified
Legal entity detailName onlyName, address, company number
Passwordless authenticationNot explicitly addressedFIDO2 recognised as MFA
Plus retestingOriginal sample retestedOriginal plus a new random sample
Amending self-assessment answersPossible during Plus testingLocked once Plus testing begins

What did not change

The five technical controls are the same: firewalls and internet gateways, secure configuration, user access control, malware protection and security update management. Backups moved to a more prominent position in the requirements document but remain a recommendation rather than a control — a distinction worth remembering when you scope Cyber Essentials for property management against your actual ransomware exposure. The “web applications” section was renamed “application development” and now references the UK Government Software Security Code of Practice, which matters only if you build your own tenant portal.

The Five Controls Behind Cyber Essentials for Property Management

cyber essentials for property management companies d five upright pillars in a row

The controls are generic by design. Translating them into a lettings and block management estate is where most of the real work sits, and it is where Cyber Essentials for property management diverges sharply from the same exercise in a single-site professional services firm.

Firewalls and internet gateways

A managing agent rarely has one network. It has a head office, two or three branches, and a scattering of site offices, concierge desks and residents’ rooms with their own broadband. Every internet-facing boundary counts, including the router in a branch that was set up by whoever opened it. Default administrative passwords on those routers are a common finding, as is remote administration left enabled from the internet.

Secure configuration

This is where the shared branch PC becomes a problem. Auto-run enabled, an unused guest account, a local administrator password shared with the negotiators, an out-of-the-box configuration on a site laptop nobody claims — each is a straightforward fail. Site tablets used for inspections and inventories are in scope and are frequently forgotten because nobody thinks of them as computers.

User access control

Property firms have high staff churn: weekend viewing staff, seasonal lettings negotiators, self-employed inventory clerks, contractors with portal logins. The control requires accounts to be provisioned deliberately, removed promptly and never shared. The shared branch inbox that everyone signs into with the same password is the classic sector failure, and it is now compounded by the MFA auto-fail — a shared account with no second factor fails immediately. In practice this control is where Cyber Essentials for property management firms most often turns into a genuine operational change rather than a paperwork exercise.

Malware protection

The requirement is straightforward on managed Windows machines and less so on the unmanaged Mac a director bought, the personal laptop a part-time bookkeeper uses, or the tablet a site manager charges in a plant room. All are in scope if they access organisational data, and all count against Cyber Essentials for property management whether or not the firm bought them.

Security update management

The fourteen-day clock is the control that catches property firms hardest, because their estates are dispersed and half the devices are rarely on the corporate network. A branch laptop that spends six weeks in a car boot is not receiving updates, and A6.4 does not care why. If one control decides whether Cyber Essentials for property management succeeds on the first attempt, it is this one.

Indicative IASME assessment fee by organisation size (ex VAT)
Micro, 1 to 9 staff £320
Small, 10 to 49 staff £440
Medium, 50 to 249 staff £500
Large, 250 or more staff £600

Scoping Decisions That Decide Whether You Pass

cyber essentials for property management companies e location marker pin upright

Scope is the first question on the form and the one that determines everything after it. Getting Cyber Essentials for property management wrong at this stage produces either a failed assessment or a certificate so narrow that the buyer asking for it rejects the scope.

Whole organisation or a defined sub-set

Whole-organisation scope is what buyers expect and what a certificate is worth most as. A sub-set scope is permitted, but it must be genuinely segregated by network or firewall rules, and Danzell requires you to describe and justify what sits outside. A managing agent that certifies only its head office while branches handle the same tenant data has a certificate that will not survive a buyer’s due diligence questions. For that reason most Cyber Essentials for property management projects are worth doing at whole-organisation scope from the outset.

The devices property firms forget

AssetIn scope?Why firms get it wrong
Inspection tablets and inventory devicesYesNot thought of as computers
Staff phones with work emailYesAssumed personal, so ignored
Property CRM and lettings platformYesTreated as the vendor’s problem
Branch routers and site broadbandYesInstalled by the landlord or a builder
Concierge desk PC in a managed blockUsually yesOwned by the freeholder, used by staff
Door entry and CCTV controllersDepends on segregationSit on the same flat network
Self-employed clerk’s own laptopYes if it touches your dataContractor assumed out of scope
Building management system in a plant roomUsually out, if segregatedSegregation is assumed, not proven

Cloud property software is in scope, full stop

Reapit, Alto, Jupix, MRI Qube, Arthur, Fixflo and every comparable platform meet Danzell’s definition of a cloud service. You cannot exclude them, and you are responsible for the parts you control: which accounts exist, whether MFA is enforced, whether leavers were removed, and how administrative rights are granted. The vendor secures the platform; you secure your tenancy of it. Any programme of Cyber Essentials for property management has to start with an honest list of every such platform in use, including the one a single branch bought on a card.

Contractors, BYOD and the people who are not employees

A device is in scope if it accesses organisational data or services, regardless of who owns it. A self-employed inventory clerk logging into your maintenance portal from a personal laptop brings that laptop into scope unless you restrict access to managed devices. The clean answer is usually to give contractors access only through a browser on a managed device, or to accept the device into scope with the controls that implies. Firms that have already been through Cyber Essentials for property management once tend to choose the first option at renewal.

What Cyber Essentials for Property Management Costs in 2026

cyber essentials for property management companies f stack of three closed books

The headline number is small and the real number is not. Budgeting Cyber Essentials for property management honestly means separating the assessment fee, the remediation, and the ongoing operational cost of staying compliant between renewals.

The IASME assessment fee

The self-assessment fee is set by IASME and tiered by headcount: £320 plus VAT for one to nine staff, £440 for ten to forty-nine, £500 for fifty to two hundred and forty-nine, and £600 for two hundred and fifty or more. The certificate lasts twelve months. For most independent agents that fee is the smallest line in a Cyber Essentials for property management project.

What the fee does not cover

It does not cover fixing what the assessment exposes. For a typical firm that means MFA rollout across every cloud platform, a patching regime that actually meets fourteen days on dispersed devices, replacing or isolating anything unsupported, and tidying up accounts left behind by departed staff. It also does not cover the pre-assessment gap analysis most certification bodies sell, which typically runs a few hundred pounds and is usually worth it on a first run at Cyber Essentials for property management.

Cost lineIndependent agent, 12 staffRegional firm, 60 staff
IASME assessment fee£440£500
Gap analysis or pre-assessment£200 to £500£500 to £1,500
Remediation effort2 to 4 weeks part-time6 to 10 weeks part-time
Device management toolingOften already licensedUsually a new line
Cyber Essentials Plus auditFrom about £1,400£2,500 to £5,000
Annual renewalFee plus a re-checkFee plus a re-check

Where the money actually goes

In most projects the assessment fee is under ten per cent of total cost. The bulk is internal time and the tooling needed to prove patching and device compliance across dispersed sites. Firms that already run a managed device estate certify cheaply; firms where every branch buys its own laptops do not. That gap is the real cost driver in Cyber Essentials for property management, and it is worth knowing before you promise a buyer a date.

Cyber Essentials Plus: What the Audit Actually Tests

Plus is not a harder question set. It is the same question set, verified independently by an assessor who tests a sample of your actual devices. Buyers in build-to-rent and institutional portfolios increasingly specify it, so anyone planning Cyber Essentials for property management should know whether the Plus tier is coming before committing to a deadline.

The three-month window

You must hold a valid Cyber Essentials certificate before applying, and the Plus audit must complete within three months of that certificate’s issue date. Miss the window and you re-do the self-assessment. Under Danzell, your verified self-assessment answers are locked once Plus testing begins, so an answer you gave optimistically cannot be quietly corrected mid-audit. That single rule raises the cost of an inaccurate self-assessment considerably.

The device sample and the retest rule

The assessor selects a representative sample across your operating systems and device types, then tests them directly. For a property firm this usually means a mix of head-office desktops, branch laptops, at least one site tablet and a mobile device. Danzell tightened the retest: where update management fails, the assessor retests the original sample and a fresh random sample, and a second failure revokes the certificate rather than simply delaying it. Sampling is also why Cyber Essentials for property management firms rewards a genuinely uniform device estate — the assessor may test the branch laptop nobody manages.

FactorCyber EssentialsCyber Essentials Plus
How it is verifiedSelf-assessment, reviewedHands-on technical audit
Typical elapsed time4 to 8 weeks including prep6 to 12 weeks
Indicative cost£320 to £600 plus VAT£1,400 to £5,000 plus
Devices examinedNone directlyRepresentative sample tested
Certificate validity12 months12 months
Usual buyerCouncils, insurers, most landlordsBTR, institutional, larger public bodies

A 90-Day Route to Cyber Essentials for Property Management

Most failed first attempts are failures of sequencing rather than effort. This plan front-loads the two auto-fail controls, because nothing else matters while either is outstanding. It assumes a firm of ten to sixty staff with two or three sites and no dedicated security function, which is the shape of most Cyber Essentials for property management projects.

Days 1 to 14: establish what you actually own

Build one list of every device and every cloud service, including the platforms a single branch signed up for. This is the step firms skip and the step that decides the outcome. Reconcile the device list against payroll and against the accounts in each cloud platform; the difference between those lists is usually a set of live accounts belonging to people who left. No Cyber Essentials for property management submission is safe until that reconciliation is done.

Days 15 to 35: multi-factor authentication everywhere

Enable MFA on every cloud service that offers it, for every user without exception, including shared and generic accounts. Where a platform only offers MFA on a higher tier, the assessment treats it as available — budget the upgrade or migrate. Convert shared branch mailboxes to properly licensed accounts or delegated access so that each sign-in belongs to a named person.

Days 36 to 60: make fourteen days achievable

Fourteen days is not a policy, it is a measurement. You need automatic updates on where possible, a reporting mechanism that tells you which devices are behind, and a route to reach laptops that rarely touch the office network. Anything that cannot be patched — an old inventory tablet, a legacy access-control PC — must be replaced or segregated before you submit. This is usually the longest phase of Cyber Essentials for property management and it is the one worth starting early.

Days 61 to 75: access, configuration and boundaries

Remove leavers, strip administrative rights from day-to-day accounts, change default router credentials at every site, disable remote administration from the internet, and confirm malware protection is active and reporting on every in-scope device including Macs.

Days 76 to 90: submit and evidence

Complete the self-assessment with the evidence to hand. Answer accurately: under Danzell there is no partial credit on the auto-fail questions, so an optimistic answer converts a fixable problem into a failed submission and a re-application fee. Honest answers are the cheapest part of Cyber Essentials for property management.

WindowFocusDone when
Days 1 to 14Asset and cloud service inventoryOne list, reconciled to payroll
Days 15 to 35MFA on every cloud serviceNo account without a second factor
Days 36 to 6014-day patching, measurableA report proves the window is met
Days 61 to 75Access control and configurationNo leavers, no shared admin, no defaults
Days 76 to 90Submission and evidenceAnswers match reality, certificate issued

The Evidence Pack Your Assessor Will Ask For

Cyber Essentials is a self-assessment, but the reviewer can and does query answers, and Plus verifies them directly. Assembling the evidence as you go turns a stressful fortnight into an afternoon, and it is the difference between a smooth renewal of Cyber Essentials for property management and an annual scramble.

Screenshots that prove the control, not the intention

A screenshot of a policy page is not evidence that a control is enforced. What proves it is the enforcement state: the conditional access or MFA enforcement report showing every user covered, the update compliance report showing devices patched inside fourteen days, the account list showing no enabled logins for people who left, the firewall configuration showing remote administration disabled. Those four reports carry most of a Cyber Essentials for property management evidence pack on their own.

The asset register that keeps working

Keep the inventory current rather than rebuilding it each year. Record device, owner, operating system, whether it is managed, and which cloud platforms each person can reach. Property firms churn devices and staff faster than most sectors, so a register that is only accurate in April is worthless in October — and Cyber Essentials for property management is a point-in-time statement anyway, now formally defined as the date the certificate is issued.

Policies that people actually follow

You need a small number of short documents that match what happens: an acceptable use statement, a joiner and leaver process, a patching standard naming the fourteen-day window, and a rule covering contractor and personal device access. Longer documents do not score better. Documents that contradict your technical reality lose you the assessment.

Where Cyber Essentials for Property Management Stops

The certificate is a floor, not a ceiling, and treating it as a finish line is the most common strategic error. Understanding the limits of Cyber Essentials for property management is what turns it from a procurement chore into an actual risk decision.

It does not stop payment redirection fraud

The most expensive incident in this sector is usually not ransomware — it is a fraudulent change of bank details on a completion payment, a deposit return or a contractor invoice. That attack succeeds through process, not malware, and no technical control in the scheme prevents it. Cyber Essentials for property management will not save a client account from a convincing email. You need call-back verification on any change of bank details, using a number you already held, and dual authorisation on client account payments above a threshold.

It says almost nothing about your suppliers

Your contractors, your CRM vendor and your outsourced accounts function all touch tenant and landlord data, and your own certificate says nothing about theirs. Given that only 15 per cent of UK businesses review supplier cyber risk at all, this is where genuine exposure hides. Our supplier cyber-risk assessment checklist covers the proportionate version of that review for a firm without a procurement team.

Backups are not a certification control

Backups are prominent in the Danzell requirements document but remain a recommendation. Ransomware recovery for a managing agent means being able to restore the property database, the document store and the mailboxes, and having tested that restore. Cyber Essentials for property management will not ask; your business continuity depends on it anyway. Good cybersecurity practice extends well past the five controls.

When ISO 27001 becomes the better answer

Once you manage institutional portfolios, employ a data protection lead, or field detailed security questionnaires several times a year, the certificate stops being enough on its own. That is the point to look at ISO 27001 readiness — a management system with risk treatment and continual improvement rather than a point-in-time technical baseline. Most firms run both, with the technical baseline certified annually inside the wider system.

Cyber Essentials for Property Management FAQs

How long does Cyber Essentials for property management take from a standing start?

Four to eight weeks is realistic for a firm with managed devices and MFA already deployed. Ninety days is the honest planning figure for a firm starting with dispersed, unmanaged laptops and a shared branch mailbox, which describes most independent agents.

Does the certificate cover our branches automatically?

Only if they are inside the scope you declare. Whole-organisation scope covers them; a head-office-only scope does not, and Danzell requires you to justify the exclusion. Buyers reading a narrow Cyber Essentials for property management scope tend to ask why.

Our property CRM is the vendor’s system. Is it in scope?

Yes. Danzell states that cloud services cannot be excluded. The vendor is responsible for the platform; you are responsible for accounts, MFA enforcement, administrative rights and removing leavers.

One landlord asks for Plus and the rest do not. Do we need it?

If a material contract requires it, yes. Otherwise start with the base certificate, get the controls genuinely working, and add Plus at the next renewal — remembering the audit must complete within three months of the certificate being issued.

What happens if our Cyber Essentials for property management submission fails?

A failed self-assessment can normally be resubmitted after remediation, usually with a further fee, and certification bodies often allow a short free window for minor issues. The auto-fail questions are the exception worth respecting: they end that submission outright.

Does the certificate reduce our cyber insurance premium?

Insurers commonly treat Cyber Essentials for property management as a positive rating factor and some make it a condition of cover, but pricing varies by underwriter. Treat it as a factor in the renewal conversation rather than a guaranteed discount, and expect questions about MFA and backups regardless.

Do we need certification if we never bid for public contracts?

Legally, no — Cyber Essentials for property management is voluntary outside contractual requirements. Practically, institutional landlords, insurers and an increasing number of freeholder clients ask for it, so most growing firms end up needing it anyway. A managed IT provider can usually run the whole process alongside your existing support arrangement.

References