Cyber Essentials for property management companies has quietly changed from a badge some firms collected to a condition of winning and keeping work. Local authorities, housing associations, build-to-rent investors, insurers and institutional landlords increasingly ask for the certificate before they hand a managing agent a portfolio. If you cannot produce one, you are not negotiating on price — you are not on the list at all.
The scheme itself also moved. On 26 April 2026 the Cyber Essentials question set changed from Willow to Danzell, and the change was not cosmetic. Three requirements that used to cost you points now fail the whole assessment outright. That is why Cyber Essentials for property management firms is a different exercise in 2026 than it was a year ago: a managing agent that certified comfortably in 2025 can fail without changing a single thing about how it operates.
This guide is written specifically for lettings agencies, block and estate management firms, build-to-rent operators and managing agents. It covers what Cyber Essentials for property management companies actually asks, where property businesses reliably trip, what it costs, how long it takes, and what the assessor wants to see. It builds on our IT support guide for property management companies and our Microsoft 365 security checklist for property firms, and on three certification guides that cover the scheme generically: why applications fail, Cyber Essentials Plus compared with ISO 27001 and what unsupported software does to a certification.
Where those guides ask what does the scheme require, this one asks what does the scheme require of a firm that manages other people’s buildings, money and tenants.
Table of contents
- Why Cyber Essentials for Property Management Is Now a Contract Requirement
- What Changed in April 2026: The Danzell Question Set
- The Five Controls Behind Cyber Essentials for Property Management
- Scoping Decisions That Decide Whether You Pass
- What Cyber Essentials for Property Management Costs in 2026
- Cyber Essentials Plus: What the Audit Actually Tests
- A 90-Day Route to Cyber Essentials for Property Management
- The Evidence Pack Your Assessor Will Ask For
- Where Cyber Essentials for Property Management Stops
- Cyber Essentials for Property Management FAQs
- References
Why Cyber Essentials for Property Management Is Now a Contract Requirement
Cyber Essentials was designed by the UK government as a baseline: five technical controls that stop the commodity attacks which make up the overwhelming majority of incidents. It is not an information security management system and it does not pretend to be. What it does is prove, to a third party, that the basics are actually switched on. Framed that way, Cyber Essentials for property management is less a security project than a commercial credential with a technical exam attached.
Property firms hold an unusually rich data set
A managing agent is a data controller for a remarkably sensitive collection: passport and visa scans gathered for right-to-rent checks, bank details for standing orders and deposit returns, landlord statements, contractor invoices, tenancy agreements, vulnerability and adjustment records, key registers and alarm codes. It also moves money — rent, service charges, deposits and contractor payments — often through accounts it does not own. That combination is why Cyber Essentials for property management firms attracts more scrutiny than the headcount alone would suggest.
Where the certification demand actually comes from
Procurement Policy Note 014, which replaced PPN 09/23 and PPN 09/14, is the binding rule for central government departments, executive agencies, non-departmental public bodies and NHS organisations. It requires those buyers to apply proportionate cyber controls to relevant contracts and to state any Cyber Essentials requirement in the tender notice. Local authorities and housing associations are not formally in scope, but a great many of them apply the same standard when appointing managing agents — which is how Cyber Essentials for property management became a procurement question rather than an IT one.
The rule buyers forget to mention
PPN 014 also obliges in-scope buyers to accept equivalents, in line with section 56 of the Procurement Act 2023. In practice, “equivalent” means you must demonstrate the same controls to the buyer’s satisfaction — which is usually slower and more expensive than simply holding the certificate. For most agents, treating Cyber Essentials for property management as the default route is cheaper than arguing equivalence at every tender.
| Who asks | What they typically ask for | When it comes up |
|---|---|---|
| Local authority housing teams | Cyber Essentials, sometimes Plus | Tender and annual re-approval |
| Housing associations | Cyber Essentials plus a data-protection annex | Supplier onboarding |
| Institutional and BTR landlords | Cyber Essentials Plus | Management agreement renewal |
| Cyber insurers | Certificate as a rating factor | Renewal questionnaire |
| Corporate landlords and funds | Certificate plus a security questionnaire | Due diligence before instruction |
| Redress and client-money auditors | Evidence of access control | Annual audit |
The sector already has a regulatory scar
The Information Commissioner’s Office fined the London estate agency Life at Parliament View Limited £80,000 after the personal data of 18,610 tenants and landlords sat openly accessible for close to two years. The cause was mundane — an anonymous-authentication setting left switched on during a server transfer. Exposed records included bank statements, salary details, dates of birth and passport copies. That penalty landed under the Data Protection Act 1998; under UK GDPR the ceiling is £17.5 million or four per cent of global turnover.
Most of the sector has not done the basics
Only five per cent of UK businesses hold the certificate at all. In a tender where three agents bid and one is certified, that number stops being a statistic and starts being a differentiator, which is the commercial case for Cyber Essentials for property management in one line. The same survey found 43 per cent of businesses — roughly 612,000 organisations — identified a breach or attack in the previous twelve months, with phishing involved in 38 per cent of cases and rated the most disruptive attack type by 69 per cent of those affected.
What Changed in April 2026: The Danzell Question Set
IASME published the Danzell question set on 13 February 2026 and it took effect on 26 April 2026, replacing Willow. Assessment accounts created before that date kept a six-month window to finish under the old rules; everyone renewing afterwards answers Danzell. Anyone planning Cyber Essentials for property management work in the current cycle is answering the new set.
Three answers that now fail the whole assessment
Under Willow these were major non-compliances that pulled your score down. Under Danzell each is an outright auto-fail with no remediation opportunity in that submission. Anyone preparing Cyber Essentials for property management work should treat these three as gating items rather than line items.
The first is multi-factor authentication on cloud services. If MFA is available on an in-scope cloud service and is not enabled for every user, the assessment fails — and “available” includes MFA that requires a higher licence tier. The second and third are the new questions A6.4 and A6.5: high-risk and critical updates must be installed within fourteen days of release, A6.4 covering operating systems and router and firewall firmware, A6.5 covering applications and their associated files and extensions.
Cloud services can no longer be scoped out
Danzell adds a formal definition of a cloud service — on-demand, scalable, on shared infrastructure, reached over the internet through an account, storing or processing your data — and states plainly that cloud services cannot be excluded from scope. For anyone doing Cyber Essentials for property management this is the single most consequential sentence in the document, because the property CRM, the maintenance portal, the accounting package and the document store are all cloud services and all now in scope by definition.
Scope descriptions and legal entities
Detailed scope descriptions are now unlimited in length. Anything you exclude must be described specifically and justified rather than waved away with a generic phrase, though that description is not published. Every legal entity inside the scope must be identified by name, registered address and company number — which matters more for Cyber Essentials for property management than most sectors, because lettings, block management and a maintenance arm so often sit in separate companies. Individual certificates for each entity are available for a small additional fee.
| Area | Willow (to April 2026) | Danzell (from 26 April 2026) |
|---|---|---|
| MFA on cloud services | Major non-compliance | Auto-fail |
| 14-day critical patching | Major non-compliance | Auto-fail via A6.4 and A6.5 |
| Cloud service exclusions | Permitted in some cases | Not permitted |
| Scope description length | Limited | Unlimited, exclusions justified |
| Legal entity detail | Name only | Name, address, company number |
| Passwordless authentication | Not explicitly addressed | FIDO2 recognised as MFA |
| Plus retesting | Original sample retested | Original plus a new random sample |
| Amending self-assessment answers | Possible during Plus testing | Locked once Plus testing begins |
What did not change
The five technical controls are the same: firewalls and internet gateways, secure configuration, user access control, malware protection and security update management. Backups moved to a more prominent position in the requirements document but remain a recommendation rather than a control — a distinction worth remembering when you scope Cyber Essentials for property management against your actual ransomware exposure. The “web applications” section was renamed “application development” and now references the UK Government Software Security Code of Practice, which matters only if you build your own tenant portal.
The Five Controls Behind Cyber Essentials for Property Management
The controls are generic by design. Translating them into a lettings and block management estate is where most of the real work sits, and it is where Cyber Essentials for property management diverges sharply from the same exercise in a single-site professional services firm.
Firewalls and internet gateways
A managing agent rarely has one network. It has a head office, two or three branches, and a scattering of site offices, concierge desks and residents’ rooms with their own broadband. Every internet-facing boundary counts, including the router in a branch that was set up by whoever opened it. Default administrative passwords on those routers are a common finding, as is remote administration left enabled from the internet.
Secure configuration
This is where the shared branch PC becomes a problem. Auto-run enabled, an unused guest account, a local administrator password shared with the negotiators, an out-of-the-box configuration on a site laptop nobody claims — each is a straightforward fail. Site tablets used for inspections and inventories are in scope and are frequently forgotten because nobody thinks of them as computers.
User access control
Property firms have high staff churn: weekend viewing staff, seasonal lettings negotiators, self-employed inventory clerks, contractors with portal logins. The control requires accounts to be provisioned deliberately, removed promptly and never shared. The shared branch inbox that everyone signs into with the same password is the classic sector failure, and it is now compounded by the MFA auto-fail — a shared account with no second factor fails immediately. In practice this control is where Cyber Essentials for property management firms most often turns into a genuine operational change rather than a paperwork exercise.
Malware protection
The requirement is straightforward on managed Windows machines and less so on the unmanaged Mac a director bought, the personal laptop a part-time bookkeeper uses, or the tablet a site manager charges in a plant room. All are in scope if they access organisational data, and all count against Cyber Essentials for property management whether or not the firm bought them.
Security update management
The fourteen-day clock is the control that catches property firms hardest, because their estates are dispersed and half the devices are rarely on the corporate network. A branch laptop that spends six weeks in a car boot is not receiving updates, and A6.4 does not care why. If one control decides whether Cyber Essentials for property management succeeds on the first attempt, it is this one.
Scoping Decisions That Decide Whether You Pass
Scope is the first question on the form and the one that determines everything after it. Getting Cyber Essentials for property management wrong at this stage produces either a failed assessment or a certificate so narrow that the buyer asking for it rejects the scope.
Whole organisation or a defined sub-set
Whole-organisation scope is what buyers expect and what a certificate is worth most as. A sub-set scope is permitted, but it must be genuinely segregated by network or firewall rules, and Danzell requires you to describe and justify what sits outside. A managing agent that certifies only its head office while branches handle the same tenant data has a certificate that will not survive a buyer’s due diligence questions. For that reason most Cyber Essentials for property management projects are worth doing at whole-organisation scope from the outset.
The devices property firms forget
| Asset | In scope? | Why firms get it wrong |
|---|---|---|
| Inspection tablets and inventory devices | Yes | Not thought of as computers |
| Staff phones with work email | Yes | Assumed personal, so ignored |
| Property CRM and lettings platform | Yes | Treated as the vendor’s problem |
| Branch routers and site broadband | Yes | Installed by the landlord or a builder |
| Concierge desk PC in a managed block | Usually yes | Owned by the freeholder, used by staff |
| Door entry and CCTV controllers | Depends on segregation | Sit on the same flat network |
| Self-employed clerk’s own laptop | Yes if it touches your data | Contractor assumed out of scope |
| Building management system in a plant room | Usually out, if segregated | Segregation is assumed, not proven |
Cloud property software is in scope, full stop
Reapit, Alto, Jupix, MRI Qube, Arthur, Fixflo and every comparable platform meet Danzell’s definition of a cloud service. You cannot exclude them, and you are responsible for the parts you control: which accounts exist, whether MFA is enforced, whether leavers were removed, and how administrative rights are granted. The vendor secures the platform; you secure your tenancy of it. Any programme of Cyber Essentials for property management has to start with an honest list of every such platform in use, including the one a single branch bought on a card.
Contractors, BYOD and the people who are not employees
A device is in scope if it accesses organisational data or services, regardless of who owns it. A self-employed inventory clerk logging into your maintenance portal from a personal laptop brings that laptop into scope unless you restrict access to managed devices. The clean answer is usually to give contractors access only through a browser on a managed device, or to accept the device into scope with the controls that implies. Firms that have already been through Cyber Essentials for property management once tend to choose the first option at renewal.
What Cyber Essentials for Property Management Costs in 2026
The headline number is small and the real number is not. Budgeting Cyber Essentials for property management honestly means separating the assessment fee, the remediation, and the ongoing operational cost of staying compliant between renewals.
The IASME assessment fee
The self-assessment fee is set by IASME and tiered by headcount: £320 plus VAT for one to nine staff, £440 for ten to forty-nine, £500 for fifty to two hundred and forty-nine, and £600 for two hundred and fifty or more. The certificate lasts twelve months. For most independent agents that fee is the smallest line in a Cyber Essentials for property management project.
What the fee does not cover
It does not cover fixing what the assessment exposes. For a typical firm that means MFA rollout across every cloud platform, a patching regime that actually meets fourteen days on dispersed devices, replacing or isolating anything unsupported, and tidying up accounts left behind by departed staff. It also does not cover the pre-assessment gap analysis most certification bodies sell, which typically runs a few hundred pounds and is usually worth it on a first run at Cyber Essentials for property management.
| Cost line | Independent agent, 12 staff | Regional firm, 60 staff |
|---|---|---|
| IASME assessment fee | £440 | £500 |
| Gap analysis or pre-assessment | £200 to £500 | £500 to £1,500 |
| Remediation effort | 2 to 4 weeks part-time | 6 to 10 weeks part-time |
| Device management tooling | Often already licensed | Usually a new line |
| Cyber Essentials Plus audit | From about £1,400 | £2,500 to £5,000 |
| Annual renewal | Fee plus a re-check | Fee plus a re-check |
Where the money actually goes
In most projects the assessment fee is under ten per cent of total cost. The bulk is internal time and the tooling needed to prove patching and device compliance across dispersed sites. Firms that already run a managed device estate certify cheaply; firms where every branch buys its own laptops do not. That gap is the real cost driver in Cyber Essentials for property management, and it is worth knowing before you promise a buyer a date.
Cyber Essentials Plus: What the Audit Actually Tests
Plus is not a harder question set. It is the same question set, verified independently by an assessor who tests a sample of your actual devices. Buyers in build-to-rent and institutional portfolios increasingly specify it, so anyone planning Cyber Essentials for property management should know whether the Plus tier is coming before committing to a deadline.
The three-month window
You must hold a valid Cyber Essentials certificate before applying, and the Plus audit must complete within three months of that certificate’s issue date. Miss the window and you re-do the self-assessment. Under Danzell, your verified self-assessment answers are locked once Plus testing begins, so an answer you gave optimistically cannot be quietly corrected mid-audit. That single rule raises the cost of an inaccurate self-assessment considerably.
The device sample and the retest rule
The assessor selects a representative sample across your operating systems and device types, then tests them directly. For a property firm this usually means a mix of head-office desktops, branch laptops, at least one site tablet and a mobile device. Danzell tightened the retest: where update management fails, the assessor retests the original sample and a fresh random sample, and a second failure revokes the certificate rather than simply delaying it. Sampling is also why Cyber Essentials for property management firms rewards a genuinely uniform device estate — the assessor may test the branch laptop nobody manages.
| Factor | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| How it is verified | Self-assessment, reviewed | Hands-on technical audit |
| Typical elapsed time | 4 to 8 weeks including prep | 6 to 12 weeks |
| Indicative cost | £320 to £600 plus VAT | £1,400 to £5,000 plus |
| Devices examined | None directly | Representative sample tested |
| Certificate validity | 12 months | 12 months |
| Usual buyer | Councils, insurers, most landlords | BTR, institutional, larger public bodies |
A 90-Day Route to Cyber Essentials for Property Management
Most failed first attempts are failures of sequencing rather than effort. This plan front-loads the two auto-fail controls, because nothing else matters while either is outstanding. It assumes a firm of ten to sixty staff with two or three sites and no dedicated security function, which is the shape of most Cyber Essentials for property management projects.
Days 1 to 14: establish what you actually own
Build one list of every device and every cloud service, including the platforms a single branch signed up for. This is the step firms skip and the step that decides the outcome. Reconcile the device list against payroll and against the accounts in each cloud platform; the difference between those lists is usually a set of live accounts belonging to people who left. No Cyber Essentials for property management submission is safe until that reconciliation is done.
Days 15 to 35: multi-factor authentication everywhere
Enable MFA on every cloud service that offers it, for every user without exception, including shared and generic accounts. Where a platform only offers MFA on a higher tier, the assessment treats it as available — budget the upgrade or migrate. Convert shared branch mailboxes to properly licensed accounts or delegated access so that each sign-in belongs to a named person.
Days 36 to 60: make fourteen days achievable
Fourteen days is not a policy, it is a measurement. You need automatic updates on where possible, a reporting mechanism that tells you which devices are behind, and a route to reach laptops that rarely touch the office network. Anything that cannot be patched — an old inventory tablet, a legacy access-control PC — must be replaced or segregated before you submit. This is usually the longest phase of Cyber Essentials for property management and it is the one worth starting early.
Days 61 to 75: access, configuration and boundaries
Remove leavers, strip administrative rights from day-to-day accounts, change default router credentials at every site, disable remote administration from the internet, and confirm malware protection is active and reporting on every in-scope device including Macs.
Days 76 to 90: submit and evidence
Complete the self-assessment with the evidence to hand. Answer accurately: under Danzell there is no partial credit on the auto-fail questions, so an optimistic answer converts a fixable problem into a failed submission and a re-application fee. Honest answers are the cheapest part of Cyber Essentials for property management.
| Window | Focus | Done when |
|---|---|---|
| Days 1 to 14 | Asset and cloud service inventory | One list, reconciled to payroll |
| Days 15 to 35 | MFA on every cloud service | No account without a second factor |
| Days 36 to 60 | 14-day patching, measurable | A report proves the window is met |
| Days 61 to 75 | Access control and configuration | No leavers, no shared admin, no defaults |
| Days 76 to 90 | Submission and evidence | Answers match reality, certificate issued |
The Evidence Pack Your Assessor Will Ask For
Cyber Essentials is a self-assessment, but the reviewer can and does query answers, and Plus verifies them directly. Assembling the evidence as you go turns a stressful fortnight into an afternoon, and it is the difference between a smooth renewal of Cyber Essentials for property management and an annual scramble.
Screenshots that prove the control, not the intention
A screenshot of a policy page is not evidence that a control is enforced. What proves it is the enforcement state: the conditional access or MFA enforcement report showing every user covered, the update compliance report showing devices patched inside fourteen days, the account list showing no enabled logins for people who left, the firewall configuration showing remote administration disabled. Those four reports carry most of a Cyber Essentials for property management evidence pack on their own.
The asset register that keeps working
Keep the inventory current rather than rebuilding it each year. Record device, owner, operating system, whether it is managed, and which cloud platforms each person can reach. Property firms churn devices and staff faster than most sectors, so a register that is only accurate in April is worthless in October — and Cyber Essentials for property management is a point-in-time statement anyway, now formally defined as the date the certificate is issued.
Policies that people actually follow
You need a small number of short documents that match what happens: an acceptable use statement, a joiner and leaver process, a patching standard naming the fourteen-day window, and a rule covering contractor and personal device access. Longer documents do not score better. Documents that contradict your technical reality lose you the assessment.
Where Cyber Essentials for Property Management Stops
The certificate is a floor, not a ceiling, and treating it as a finish line is the most common strategic error. Understanding the limits of Cyber Essentials for property management is what turns it from a procurement chore into an actual risk decision.
It does not stop payment redirection fraud
The most expensive incident in this sector is usually not ransomware — it is a fraudulent change of bank details on a completion payment, a deposit return or a contractor invoice. That attack succeeds through process, not malware, and no technical control in the scheme prevents it. Cyber Essentials for property management will not save a client account from a convincing email. You need call-back verification on any change of bank details, using a number you already held, and dual authorisation on client account payments above a threshold.
It says almost nothing about your suppliers
Your contractors, your CRM vendor and your outsourced accounts function all touch tenant and landlord data, and your own certificate says nothing about theirs. Given that only 15 per cent of UK businesses review supplier cyber risk at all, this is where genuine exposure hides. Our supplier cyber-risk assessment checklist covers the proportionate version of that review for a firm without a procurement team.
Backups are not a certification control
Backups are prominent in the Danzell requirements document but remain a recommendation. Ransomware recovery for a managing agent means being able to restore the property database, the document store and the mailboxes, and having tested that restore. Cyber Essentials for property management will not ask; your business continuity depends on it anyway. Good cybersecurity practice extends well past the five controls.
When ISO 27001 becomes the better answer
Once you manage institutional portfolios, employ a data protection lead, or field detailed security questionnaires several times a year, the certificate stops being enough on its own. That is the point to look at ISO 27001 readiness — a management system with risk treatment and continual improvement rather than a point-in-time technical baseline. Most firms run both, with the technical baseline certified annually inside the wider system.
Cyber Essentials for Property Management FAQs
How long does Cyber Essentials for property management take from a standing start?
Four to eight weeks is realistic for a firm with managed devices and MFA already deployed. Ninety days is the honest planning figure for a firm starting with dispersed, unmanaged laptops and a shared branch mailbox, which describes most independent agents.
Does the certificate cover our branches automatically?
Only if they are inside the scope you declare. Whole-organisation scope covers them; a head-office-only scope does not, and Danzell requires you to justify the exclusion. Buyers reading a narrow Cyber Essentials for property management scope tend to ask why.
Our property CRM is the vendor’s system. Is it in scope?
Yes. Danzell states that cloud services cannot be excluded. The vendor is responsible for the platform; you are responsible for accounts, MFA enforcement, administrative rights and removing leavers.
One landlord asks for Plus and the rest do not. Do we need it?
If a material contract requires it, yes. Otherwise start with the base certificate, get the controls genuinely working, and add Plus at the next renewal — remembering the audit must complete within three months of the certificate being issued.
What happens if our Cyber Essentials for property management submission fails?
A failed self-assessment can normally be resubmitted after remediation, usually with a further fee, and certification bodies often allow a short free window for minor issues. The auto-fail questions are the exception worth respecting: they end that submission outright.
Does the certificate reduce our cyber insurance premium?
Insurers commonly treat Cyber Essentials for property management as a positive rating factor and some make it a condition of cover, but pricing varies by underwriter. Treat it as a factor in the renewal conversation rather than a guaranteed discount, and expect questions about MFA and backups regardless.
Do we need certification if we never bid for public contracts?
Legally, no — Cyber Essentials for property management is voluntary outside contractual requirements. Practically, institutional landlords, insurers and an increasing number of freeholder clients ask for it, so most growing firms end up needing it anyway. A managed IT provider can usually run the whole process alongside your existing support arrangement.