Cyber Essentials for accountancy firms has quietly become a commercial document rather than a technical one. It started life as a government scheme to raise the floor on five basic controls, and it now turns up in framework tenders, client onboarding packs, professional indemnity renewals and network membership rules. A practice that can produce a current certificate answers the whole question in one line. A practice that cannot spends a fortnight writing prose about its firewalls and still loses the work.

The scheme itself is not difficult. What makes Cyber Essentials for accountancy awkward is the estate a modern practice actually runs: a practice management database somebody else hosts, tax software installed locally on partner laptops, ten separate cloud logins per client manager, an agent services account three people share because that is how it has always worked, and a January in which half the firm works from a kitchen table. Those are scoping problems rather than security problems, and scoping is exactly where certification attempts stall.

If you have read our guide to Cyber Essentials for hotels, the shape here will look familiar. An accountancy practice, though, carries a regulatory load that a hotel does not: anti-money-laundering supervision, Companies House identity verification, HMRC agent credentials and a duty of confidentiality written directly into your professional code. Cyber Essentials for accountancy sits underneath all four.

This guide to Cyber Essentials for accountancy firms covers what the scheme certifies, what changed with the Danzell v3.3 requirements in April 2026, how to draw a defensible scope boundary around a practice, what each of the five controls means at a desk in a tax department, what certification costs, what a Cyber Essentials Plus assessor tests, and a ninety-day plan to get there. It assumes you already have IT support for accountancy firms in some form, and that your tenant broadly follows our Microsoft 365 security checklist for accountancy firms.

Why Cyber Essentials for Accountancy Firms Stopped Being Optional

cyber essentials for accountancy firms 2026 uk guide b filing cabinet three drawers

Cyber Essentials for a village hall is a formality. For a firm holding the tax affairs of several hundred businesses it has become a filter applied before anyone reads your fee proposal.

The certificate is now a procurement gate

The public sector set the pattern. Procurement Policy Note 014 came into force on 24 February 2025, replacing PPN 09/14 and PPN 09/23, and it binds central government departments, executive agencies, non-departmental public bodies and NHS bodies. Any supplier handling the personal information of government employees, ministers or special advisers must meet the technical requirements.

A practice preparing payroll, expenses or personal tax returns for a public body sits squarely inside that wording. Evidence is required before contract award and must be renewed annually for the life of the contract. The note also tells buyers not to take a blanket approach, and equivalents are accepted under section 56 of the Procurement Act 2023. Cyber Essentials for accountancy is the cheapest way to satisfy the ask.

Larger clients copied the wording

Once the public sector normalised the question, corporate procurement teams followed. A practice bidding to become a preferred adviser now routinely receives a supplier security questionnaire, and Cyber Essentials for accountancy firms answers most of it in a single line. That is the practical case: not that the scheme prevents every attack, but that it converts three weeks of questionnaire correspondence into one verifiable statement.

The NCSC published its Cyber Essentials Supply Chain Playbook on 12 December 2025, explicitly telling large buyers to require the certificate of their suppliers rather than merely encourage it. It ships with the IASME Supplier Check, which lets a buyer bulk-check up to 5,000 suppliers at once. Assume your largest clients will run that check whether or not they mention it.

Insurers ask a version of the same question

Cyber insurance proposal forms and professional indemnity renewals have converged on the same five controls: perimeter firewalls, secure configuration, patching, access control and malware protection. A practice that can evidence all five through Cyber Essentials for accountancy usually gets a faster underwriting decision.

ICAEW’s professional indemnity insurance regulations, effective from 1 September 2024, set a minimum limit of indemnity of £2 million with a participating insurer. Nothing in those regulations mandates certification. But when a broker asks how you control access to client data, Cyber Essentials for accountancy firms is a third-party answer rather than a self-declaration.

The national numbers explain the leverage

The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found 43% of UK businesses had identified a breach or attack in the preceding twelve months. Exposure climbs steadily with headcount: 42% of micro businesses, 46% of small, 65% of medium and 69% of large.

Only 25% of businesses hold a formal incident response plan and only 31% have a board member with named responsibility for cyber security. Certification sits at 5% of businesses overall, up from 3%, reaching 12% of small businesses and 35% of large ones, while awareness of the scheme reaches just 17%. That gap is precisely why Cyber Essentials for accountancy still reads as a differentiator rather than a baseline.

UK businesses identifying a breach or attack, by size (2025/2026 survey)
Micro (1-9 staff) 42%
Small (10-49 staff) 46%
Medium (50-249 staff) 65%
Large (250+ staff) 69%

The profession has already ranked the risk first

An insurer survey of professional firms published on 24 April 2026 found 65% of respondents ranked cyber attacks as their main concern, more than three times the share given to economic pressures at 18%. Professional negligence claims took 9% and regulatory change 8%. Partners are not arguing about whether the risk is real; they are arguing about what to do on Monday. Cyber Essentials for accountancy firms is the cheapest available answer to that second question.

Top risk facing professional firms in 2026, as ranked by respondents
Cyber attacks 65%
Economic pressures 18%
Professional negligence claims 9%
Regulatory change 8%

What Cyber Essentials for Accountancy Actually Certifies

cyber essentials for accountancy firms 2026 uk guide c2 padlock locked body

Before scoping anything, be precise about what Cyber Essentials for accountancy does and does not certify. Overstating it in a tender response is how practices end up making claims they cannot support under scrutiny.

Five technical controls, nothing more

The scheme covers firewalls and internet gateways, secure configuration, security update management, user access control and malware protection. That is the entire standard, and Cyber Essentials for accountancy certifies those five controls and nothing beyond them. It does not cover physical security, staff vetting, engagement letters, business continuity, professional ethics or the way you handle a client complaint about their data.

Self-assessment against independent testing

Basic certification is a self-assessment questionnaire, answered by somebody who can genuinely speak for the whole estate and signed off at board level, then marked by a certification body. Cyber Essentials Plus keeps the identical technical requirements and adds an independent hands-on audit. The requirements do not get harder at Plus level; only the evidence does. Both routes award Cyber Essentials for accountancy, and only the depth of proof changes.

Backups still are not a control

Backups are discussed in the requirements and were repositioned in the latest version, but they remain outside the five controls. IASME states plainly that backing up your data is not a technical requirement of the scheme. A practice can hold a valid Cyber Essentials for accountancy certificate with a backup regime that would not survive a ransomware event on the last Friday in January. Treat the certificate as a floor, never a strategy.

It says nothing about your AML obligations

Cyber Essentials for accountancy firms and money laundering supervision are separate regimes that happen to touch the same records. Certification does not discharge a single duty under the Money Laundering Regulations 2017, and your supervisor will not accept it as evidence of customer due diligence. What it does is protect the systems those records live in.

Question a client asksDoes the certificate answer it?What actually answers it
Are your firewalls configured?YesControl 1, tested at Plus level
Is MFA on every cloud login?YesControl 4, an auto-fail since April 2026
Do you patch within 14 days?YesControl 3, questions A6.4 and A6.5
Can you restore after ransomware?NoA tested backup and recovery plan
How long do you keep client records?NoMLR 2017 and your retention policy
Who has verified your staff?NoRecruitment screening and supervision
Do you have a security certificate?YesCyber Essentials for accountancy, renewed annually

What Danzell v3.3 Changed for Cyber Essentials for Accountancy

cyber essentials for accountancy firms 2026 uk guide d magnifying glass round rim

The question set was refreshed for 2026. IASME published the new Danzell requirements on 13 February 2026 and they apply to assessment accounts created from late April 2026; IASME’s own article gives 26 April, while several certification bodies published 27 April, so quote the month rather than the day. Accounts opened before that date kept six months on the previous Willow question set.

MFA on cloud services is now an automatic fail

This is the single largest change to Cyber Essentials for accountancy in years. Multi-factor authentication is mandatory on every cloud service where it is available, and failing to switch it on is an automatic fail rather than a fixable non-compliance. Availability includes MFA that sits behind a higher licence tier, which removes the old excuse of “our plan does not include it”.

For Cyber Essentials for accountancy this is the question that decides most assessments. A typical practice authenticates against Microsoft 365, a practice management platform, two or three bookkeeping products, a tax filing product, a document portal, an e-signature service, HMRC and Companies House. Every one of them counts.

The fourteen-day patching questions

Two questions became auto-fails alongside MFA. A6.4 covers critical and high-risk updates to operating systems and to router and firewall firmware; A6.5 covers the same for applications, files and extensions. Both give you fourteen days from the vendor publishing the fix, not fourteen days from your scanner noticing it.

That clock is unforgiving in a practice where tax software updates arrive on the vendor’s timetable and a partner’s laptop spends March in a client’s office. Cyber Essentials for accountancy firms lives or dies on whether somebody owns that fourteen-day window.

Cloud services cannot be excluded

The requirements now state it outright: cloud services cannot be excluded from scope. A cloud service is defined as an on-demand, scalable service hosted on shared infrastructure, accessed over the internet through an account, and used to store or process organisational data. That definition captures essentially every product a modern practice runs.

The old scoping trick of certifying the office network and quietly leaving the hosted practice system outside is dead. Cyber Essentials for accountancy now means the whole thing, including the platform your practice software vendor runs on your behalf.

Scope has to be described, and “everything” is not a description

Danzell asks you to define and document the scope: in-scope devices, users and network boundaries, plus a written description of anything excluded. Excluded areas must be specifically described and justified, and a scope that leaves out end-user devices is not acceptable. Certificates can now be issued per legal entity for a small fee, with the legal name, registered address and company number recorded. Cyber Essentials for accountancy is assessed against the description you write, so write it deliberately.

AreaWillow v3.2Danzell v3.3, from late April 2026
MFA on cloud servicesMajor non-complianceAutomatic fail, including MFA behind a paid tier
OS and firmware updatesScored questionA6.4, automatic fail beyond 14 days
Application updatesScored questionA6.5, automatic fail beyond 14 days
Cloud in scopeFrequently arguedCannot be excluded, with a formal definition
Scope descriptionLength limitedUnlimited, exclusions must be justified
FIDO2 security keysAmbiguousExplicitly regarded as MFA
CertificatesOne per assessmentPer legal entity, for a small additional fee
Plus retestOriginal sampleOriginal sample plus a fresh random sample

Scoping Cyber Essentials for Accountancy Firms

cyber essentials for accountancy firms 2026 uk guide e4 doorway access panel

Scope is where certification is won or lost. Almost every failed attempt at Cyber Essentials for accountancy traces back to a boundary somebody drew hopefully rather than accurately.

Start with the client data, not the devices

The useful question is not “which computers do we own” but “where does client data go”. Follow a single limited company client through the practice: the bookkeeping platform, the accounts production system, the tax filing product, the Companies House filing route, the document portal, the email thread with the finance director, the folder on the file server, the partner’s laptop on the train. Every stop on that journey is a candidate for the scope of Cyber Essentials for accountancy.

Practice software comes in three shapes

Accountancy software sits in one of three deployment models, and each is scoped differently. Locally installed products put the whole burden on the device. Hosted or virtual-desktop products put it on the supplier’s infrastructure plus your access controls. Genuinely cloud-native products put user access control squarely on you, always, whatever the shared responsibility model says elsewhere. Cyber Essentials for accountancy treats all three as in scope; only the evidence differs.

The estate is smaller than you fear and larger than you think

Practices consistently overestimate their server count and underestimate their cloud service count. Cyber Essentials for accountancy firms cares about both, but the cloud list is usually the one that has never been written down. Build it from your card statement and your single sign-on logs, not from memory.

Thing a practice runsIn scope?Why
Staff laptops and desktopsAlwaysEnd-user devices cannot be excluded
Hosted practice management platformYesA cloud service storing organisational data
Bookkeeping and tax filing productsYesCloud services; user access control is yours
HMRC agent services accountYesAn internet-facing account the firm owns
Practice-owned mobile phonesYesThey reach organisational data over the internet
Personal phone used only for an MFA appNoThe narrow BYOD carve-out covers MFA-only use
Personal laptop used to draft accountsYesA user device accessing organisational data
Firm laptop lent to a January contractorYesThe organisation owns it, so it stays in scope
Client’s own accounting systemNoNot your organisation’s device or account
Office router and firewallYesFirmware falls under A6.4
Reception PC visitors sign in onYesOwned by the firm, whoever touches it
Meeting room display with a browserUsuallyIt can reach the internet and the firm owns it

Sub-sets exist, but they are a real boundary

The requirements behind Cyber Essentials for accountancy allow a sub-set: part of the organisation whose network is segregated from the rest by a firewall or VLAN. Assessors verify segregation by technical means, so a sub-set has to be genuine rather than notional. It is a useful tool for a legacy machine that runs one client’s bespoke ledger, provided all internet traffic to and from it is genuinely blocked.

January is a scoping event, not a staffing one

Every practice changes shape between December and February. Seasonal contractors arrive, partners work from home, temporary logins get created and rarely get removed. Cyber Essentials for accountancy firms is assessed at a point in time, but a scope that only reflects a quiet week in September will not survive the first honest question about who had access in January.

Devices your suppliers use

Accounts the firm owns stay in scope even when an outsourced bookkeeping supplier uses them, and firm-owned laptops loaned to a subcontractor stay in scope too. The test is ownership rather than occupancy. Write that down before an assessor asks, because it changes the device count for Cyber Essentials for accountancy in a way that surprises partners.

The Five Controls Translated for Cyber Essentials for Accountancy

cyber essentials for accountancy firms 2026 uk guide f signpost three arrow boards

The requirements are written generically. Here is what each control means in a building where people prepare tax returns.

Firewalls and internet gateways

Every device must sit behind a correctly configured firewall, either the office boundary device or the software firewall on a laptop working elsewhere. Change the default administrative password on the router, disable remote administration from the internet unless it is protected by MFA or an allow list, and remove any port forwarding rule created years ago so a former partner could reach the server from home. Cyber Essentials for accountancy fails on that forgotten rule far more often than on anything exotic.

Secure configuration

Remove software nobody uses, disable accounts nobody needs, and turn off auto-run. The specific trap in a practice is the shared workstation: the scanning PC, the payroll machine in the corner, the reception desktop. Those tend to run a single local account with a password taped somewhere, which fails both this control and user access control at once. Cyber Essentials for accountancy treats that machine exactly like a partner laptop.

Security update management

Everything in scope must be supported and patched, with critical and high-risk fixes applied within fourteen days. Two things routinely break Cyber Essentials for accountancy here: an old accounts production package pinned to a Windows version that left support, and browser extensions nobody realised counted. Extensions are named explicitly in A6.5.

User access control

Individual accounts for individual people, least privilege by default, administrator rights separated from day-to-day accounts, and MFA on every cloud service. Shared logins are the single most common failure in this sector, and the HMRC agent accounts are usually the worst offender.

Malware protection

Anti-malware on every in-scope device, kept current, or an equivalent approach using application allow-listing. Nothing exotic is required. Defender configured properly and actually reporting to a console satisfies the control in most practices, and that is all Cyber Essentials for accountancy asks here.

ControlWhere practices fail itEvidence to have ready
FirewallsOld port forwarding to a file serverRouter config export and rule list
Secure configurationShared local account on the scanning PCAccount list per device
Update managementTax software pinned to an old OSPatch report with dates and versions
User access controlShared HMRC agent credentialsNamed account list and MFA status
Malware protectionContractor laptop outside the consoleEndpoint console coverage report

HMRC Agent Accounts and Cyber Essentials for Accountancy

Nothing tests user access control in this sector like the agent accounts. Helpfully, HMRC spent 2026 forcing the issue.

The rollout timetable

HMRC set out the schedule in Agent Update 141, published on 19 March 2026. Multi-factor authentication applies to web sign-in on GOV.UK for both the agent services account and the older HMRC online services for agents. It does not affect submissions made through Making Tax Digital software for VAT or PAYE.

Agents who submitted a request by 30 June 2026 had MFA switched on from 15 July 2026. Requests by 31 July 2026 were activated on 19 August 2026. Every remaining agent account is being switched on between 28 September and 15 October 2026, whether or not the practice asked. That timetable quietly does part of the work for Cyber Essentials for accountancy.

Request submitted byMFA switched onApplies to
30 June 202615 July 2026Government Gateway IDs you nominated
31 July 202619 August 2026Any further IDs you nominated
No request28 September to 15 October 2026All remaining agent accounts

Codes, seed keys and the shared-login problem

Codes arrive through an authenticator app, which HMRC prefers, by text message from 60551, or by automated voice call from 01749 608007. Text and voice codes are six digits and valid for fifteen minutes.

If several people currently share one Government Gateway ID, they all need the same authenticator seed key, which has to be distributed deliberately rather than by screenshot. That is the moment most practices discover how many shared credentials they really have, and it is the moment Cyber Essentials for accountancy stops being abstract.

Two administrators, always

Nobody can reset their own multi-factor authentication, so every account needs at least two administrators. A one-partner practice with a single admin and a lost phone is locked out of its own agent services account in the middle of a filing season. Build the second administrator before September, not after.

It does not certify itself

Switching MFA on for agent accounts satisfies part of one control. It does not deliver Cyber Essentials for accountancy firms by itself, because the same requirement applies to every other cloud service the practice touches, including the ones the partners signed up for personally and expensed.

Companies House, ACSP Duties and Cyber Essentials for Accountancy

Identity verification became a legal requirement on 18 November 2025 under the Economic Crime and Corporate Transparency Act, with a twelve-month transition for existing directors, persons with significant control and LLP members that closes on 18 November 2026.

What an authorised agent has to be

An Authorised Corporate Service Provider must be supervised for anti-money-laundering purposes by one of the twenty-five UK supervisory bodies. Registration opened on 18 March 2025 and costs £55. From no earlier than November 2026, any third party filing on behalf of clients needs to be registered. Those duties sit alongside Cyber Essentials for accountancy rather than inside it.

The records this creates

An ACSP must keep identity-check records for seven years and must notify Companies House within fourteen days of any relevant change, including the loss of its AML supervision. Those records are personal identity documents held in bulk, which is precisely the category of data that makes a practice worth attacking.

Three retention clocks, one filing system

Practices end up running several retention periods at once, and the systems holding them all sit inside the scope of Cyber Essentials for accountancy. Mapping them once saves an argument later.

Record typeRetentionSource of the duty
Customer due diligence and transactions5 yearsMoney Laundering Regulations 2017, regulation 40
Tax correspondence and working papersCommonly 6 yearsPractice policy and engagement terms
ACSP identity verification checks7 yearsCompanies House ACSP requirements
Change of ACSP circumstancesNotify within 14 daysCompanies House ACSP requirements

What Cyber Essentials for Accountancy Firms Costs

The assessment fee is published, small and rarely the real cost. Remediation is the real cost, and it varies enormously with how tidy the estate already is.

The IASME assessment fee bands

Assessment fees are set by headcount, excluding VAT, and the certificate lasts twelve months: £320 for a micro organisation of one to nine people, £440 for a small organisation of ten to forty-nine, £500 for a medium organisation of fifty to two hundred and forty-nine, and £600 for a large organisation of two hundred and fifty or more. Most independent practices land in the first two bands, which puts Cyber Essentials for accountancy in the same order of cost as a single professional subscription.

IASME assessment fee by size band, scaled against the £600 large-organisation fee
Micro, 1-9 people: £320
Small, 10-49 people: £440
Medium, 50-249 people: £500
Large, 250+ people: £600

Cyber Essentials Plus is a different order of money

The Plus audit is priced by the certification body rather than by IASME, and starts from roughly £1,400 excluding VAT for a micro organisation. It must be completed within three months of the underlying certificate, so book the audit slot when you start the self-assessment, not when you pass it.

The cover that comes with it

Certifying through an IASME-licensed body includes £25,000 of cyber liability cover for UK businesses turning over less than £20 million. It is not a substitute for a real cyber policy and it is not a discount on your professional indemnity premium, but it is included in the fee.

The costs nobody budgets

Remediation is where the money goes: licence upgrades to reach MFA, replacing a machine that cannot leave an unsupported operating system, buying endpoint management for laptops that have never had any, and the partner time spent listing cloud services. Budget for those before quoting a total for Cyber Essentials for accountancy firms to the board.

LineBasic certificationPlus certification
Assessment fee£320 to £600 ex VAT by headcountFrom about £1,400 ex VAT, body-priced
Assessment methodMarked self-assessment questionnaireHands-on independent technical audit
Timing constraintCertificate valid twelve monthsWithin three months of the certificate
Retry on failureAnswers can be corrected before markingNo remediation once testing has begun
Included insurance£25,000 cover under £20m turnoverSame cover, via the underlying certificate

Cyber Essentials for Accountancy at Plus Level: What an Assessor Tests

Plus is where Cyber Essentials for accountancy stops being a questionnaire and becomes an audit. The test specification is still version 3.2, published in April 2025; there is no separate v3.3 test document.

The five test cases

An assessor runs a remote vulnerability assessment against every external IP address, an authenticated scan of a sample of devices, malware tests delivered by email and by browser download, an MFA check on all cloud services, and an account separation check on every sampled device. The malware and MFA tests are the ones practices underestimate when they take Cyber Essentials for accountancy to Plus level.

The fail threshold is sharp

A finding fails if the vendor rates it critical or high, or if it scores CVSS v3 seven or above, and a fix has been available for more than fourteen days. Virtual patching is explicitly not an acceptable mitigation. Any single failure fails the whole assessment, with only a narrow discretion for marginal deviation. Cyber Essentials for accountancy at Plus level is genuinely pass or fail.

Sampling follows variation, not headcount

The sample is drawn to cover the variety of builds in the estate, not a percentage of staff. A practice with one standard laptop image and one odd machine in the payroll room will see both. Numeric sample-size tables circulating online come from delivery-partner methodology rather than the NCSC specification, so treat them as indicative.

Retest and revocation

A retest now covers the original sample plus a fresh random sample, which stops a practice patching only the machines it knows will be examined. A second failure revokes the certificate. Once Plus testing begins, the verified self-assessment answers are locked and cannot be adjusted.

The Threats Cyber Essentials for Accountancy Actually Blunts

Certification is not a shield. It is a set of controls that happen to sit in front of the attacks this profession genuinely sees.

Credential theft and the mailbox in the middle

The pattern is dull and effective: phish a credential, sign in from somewhere unremarkable, sit quietly in the mailbox, wait for a payment conversation. MFA on every cloud service is the control that breaks it, which is precisely why Danzell made it an automatic fail and why Cyber Essentials for accountancy now turns on it.

Payment and mandate fraud

UK Finance’s Annual Fraud Report 2026 recorded £1.28 billion of payment fraud losses in 2025, a 4% rise, across 4.06 million confirmed cases. Authorised push payment losses reached £576.4 million, of which £354.3 million, about 61%, was reimbursed. Encouragingly, invoice and mandate fraud together with impersonation fraud fell to multi-year lows and now account for under a quarter of APP losses, down from more than half in 2020. Controls of the kind Cyber Essentials for accountancy requires are part of why.

Tax-season phishing aimed at your clients

HMRC received more than 170,000 scam referrals in the twelve months to 31 July 2025, down 12% year on year, of which more than 47,000 concerned fake tax refund claims. Separately, HMRC told the Treasury Select Committee on 4 June 2025 that around 100,000 PAYE accounts, roughly 0.2% of that service’s users, had been used to claim about £47 million in fraudulent repayments. Your clients are being targeted with your profession’s vocabulary.

The volume that makes January dangerous

11,489,825 Self Assessment returns were received by 31 January 2026 against 12,029,168 expected, with 11,173,825 filed online and 316,000 on paper. Around a million people missed the deadline entirely and 475,772 filed on the final day. That concentration of deadline pressure is when staff click things, and it is the worst possible month to be locked out of a system.

Third parties you do not control

Ernst & Young told clients on 13 July 2026 that an unauthorised party had accessed a third-party platform holding client investment data used to prepare tax filings, between 28 March and 12 April 2026, with anomalous activity identified on 23 April 2026. A firm of that size runs controls far beyond the scheme’s five. The lesson for Cyber Essentials for accountancy firms is narrower: the platform holding your client data is in scope precisely because you cannot see inside it.

What a regulator does about it afterwards

The ICO fined DPP Law Ltd £60,000 in a penalty published in April 2025 after attackers brute-forced an infrequently used administrator account that had no multi-factor authentication, moved laterally, and stole 32GB of data. The firm only learned of it when the National Crime Agency reported client information on the dark web. The infringements cited were Articles 5(1)(f), 32(1), 32(2) and 33(1). It is a law firm rather than a practice, but the failure is the one Cyber Essentials for accountancy is designed to catch.

The wider enforcement climate

The ICO issued 28 monetary penalty notices during 2025, its highest annual total under UK GDPR, and the average penalty rose from roughly £150,000 to over £2.8 million, including a £14 million fine against Capita on 15 October 2025. Sound cybersecurity is now a financial argument as much as an ethical one.

What certification will not stop

It will not stop a convincing invoice from a genuine supplier’s compromised mailbox, an insider copying a client list, or a supplier’s own breach. Pair Cyber Essentials for accountancy firms with callback verification on bank detail changes, tested backups and an incident response plan, and the picture is genuinely different.

Worked Example: Cyber Essentials for Accountancy at 26 People

Numbers make the scope argument concrete. Take a two-office practice with 26 staff: 18 in the main office, 8 in the second, with a mix of audit, tax, payroll and bookkeeping work.

The device count

Count what the firm owns: 26 staff laptops, 3 shared desktop PCs (two on the main reception and scanning desks, one in the second office), 1 on-premises server holding the practice file share, 6 practice-owned mobile phones, and 4 laptops issued to January contractors. That is 26 + 3 + 1 + 6 + 4 = 40 in-scope devices, every one of them inside the scope of Cyber Essentials for accountancy.

40 in-scope devices in the worked example, by category
Staff laptops, 26 of 40 65%
Practice mobile phones, 6 of 40 15%
Contractor laptops, 4 of 40 10%
Shared desktop PCs, 3 of 40 7.5%
On-premises server, 1 of 40 2.5%

The cloud service count

List the accounts: Microsoft 365, the hosted practice management platform, two bookkeeping products, a tax filing product, a document portal, an e-signature service, a receipt capture tool, the HMRC agent services account and Companies House. That is 10 cloud services, every one of which needs multi-factor authentication before Cyber Essentials for accountancy can be awarded.

The remediation list

Of those 40 devices, the 3 shared PCs and the 4 contractor laptops carry the work: shared local accounts on the first group, no endpoint management on the second. That is 7 of 40 devices, 17.5% of the estate, generating most of the effort. Of the 10 cloud services, assume 3 lack MFA today; that is 30% of the list and every one is an automatic fail.

The fee

At 26 staff the practice sits in the small band of ten to forty-nine people, so the assessment fee is £440 excluding VAT for twelve months. Adding a Plus audit from about £1,400 excluding VAT gives an all-in certification cost of roughly £1,840 before remediation, or £70.77 per head across 26 people.

A 90-Day Plan for Cyber Essentials for Accountancy Firms

Ninety days is realistic for a practice starting from a reasonable Microsoft 365 tenant and no certificate. It is not realistic if you are also replacing a server.

Days 1 to 30: scope and inventory

Write the scope statement. List every device the firm owns and every cloud service it pays for, then reconcile the second list against the card statement. Identify shared logins, unsupported operating systems and anything that cannot take MFA. Nominate the two administrators for each critical account, including HMRC. Do not buy anything yet. This is the month that decides whether Cyber Essentials for accountancy takes ninety days or nine months.

Days 31 to 60: remediate

Turn on multi-factor authentication everywhere it exists, starting with email and the agent accounts. Replace shared local accounts with named ones. Separate administrator accounts from daily-use accounts. Get every device into a management console so patch status is reportable. Fix or remove anything running unsupported software. Almost every remediation task for Cyber Essentials for accountancy lands in this window.

Days 61 to 90: evidence and submit

Produce the patch report, the account list, the MFA status list and the endpoint coverage report. Answer the questionnaire against evidence rather than memory, have it reviewed by somebody who can genuinely speak for the estate, get board sign-off, and submit. Book the Plus audit at the same time if you need it, because Cyber Essentials for accountancy at Plus level has a three-month window.

WindowMain outputOwner
Days 1-30Scope statement, device and cloud inventoryPractice manager with IT support
Days 31-60MFA everywhere, named accounts, managed devicesIT support, signed off by a partner
Days 61-90Evidence pack, submission, board sign-offPartner responsible for risk
Month 4Plus audit, if required by a clientCertification body

Why Practices Fail Cyber Essentials for Accountancy

Failures cluster into a small number of predictable shapes. Every one of them is cheaper to fix before submission than after.

A cloud service nobody declared

Somebody expensed a document-signing subscription two years ago and it now holds signed engagement letters. It is a cloud service holding organisational data, it cannot be excluded, and it probably has no MFA. It is the most common single reason a practice fails Cyber Essentials for accountancy.

An unsupported operating system doing one useful job

The machine running an old ledger package for a long-standing client. Either move it into a genuine sub-set with all internet traffic blocked, or replace it. There is no third answer that passes Cyber Essentials for accountancy.

Answering from memory

The questionnaire asks about the estate as it is, not as the partner remembers it. Answers that cannot be evidenced fail at Plus level immediately, and Cyber Essentials for accountancy firms at Plus offers no remediation window once testing starts.

Treating January as out of scope

Temporary accounts created in the busy season and never disabled are the most common finding of all in a practice-sized estate assessed for Cyber Essentials for accountancy. Build the leaver process before you certify, not because the scheme asks for it but because the account list is the evidence.

After Cyber Essentials for Accountancy: What Comes Next

Certification is a floor. The sensible question afterwards is what to add, and in what order, without buying a framework you do not need.

Cyber Essentials Plus, when a client asks

Do not buy Plus speculatively. Buy Cyber Essentials for accountancy at Plus level when a tender, a client contract or an insurer asks for it. Then keep it, because the annual rhythm is easier than restarting.

ISO 27001, only if the market demands it

ISO 27001 is a management system rather than a control set, and it costs an order of magnitude more in time. It is right for a practice bidding for work where an information security management system is specified, and premature for almost everyone else.

The things the scheme deliberately ignores

Tested backups, an incident response plan, phishing simulation for staff, callback verification on bank detail changes, and a supplier register. None of them are certified by Cyber Essentials for accountancy, and all of them matter more the year after you pass than the year before.

Making Tax Digital widens the estate again

Making Tax Digital for Income Tax began on 6 April 2026 for qualifying income above £50,000, drops to £30,000 from 6 April 2027 and to £20,000 from 6 April 2028. Each phase pulls more clients into digital record keeping and more software into your scope. Re-run the cloud service inventory annually, at renewal, because Cyber Essentials for accountancy firms is a point-in-time certificate against an estate that keeps growing.

Frequently Asked Questions

Is Cyber Essentials mandatory for accountancy firms?

No. Cyber Essentials for accountancy is not mandated by ICAEW, ACCA or AAT. It becomes effectively mandatory the moment a client, a tender or an insurer asks, which for most practices is a question of when rather than whether.

How long does certification take?

The self-assessment itself can be completed in days. Ninety days is a realistic end-to-end plan for Cyber Essentials for accountancy in a practice that needs to fix shared logins, MFA gaps and unmanaged devices first.

Does the certificate cover our hosted practice software?

Yes, and it must. Cloud services cannot be excluded from scope under the Danzell requirements, so a hosted practice management platform is inside the scope of Cyber Essentials for accountancy even though the supplier runs the infrastructure.

Do partners’ personal phones need to be in scope?

Only if they are used for more than native voice, native text and an authenticator app. A phone reading practice email is a user device accessing organisational data and is in scope for Cyber Essentials for accountancy.

What happens if we miss the fourteen-day patch window?

Under Danzell that is an automatic fail on question A6.4 or A6.5, and Cyber Essentials for accountancy is refused. The clock starts when the vendor publishes the fix, so patch reporting has to be routine rather than reactive.

Does it replace our AML or data protection obligations?

No. Cyber Essentials for accountancy is a technical control set. Money laundering supervision, UK GDPR duties and Companies House ACSP requirements are separate and unaffected.

References

NCSC: Cyber Essentials overview

IASME: Important update, changes to Cyber Essentials for April 2026

IASME: Defining the scope of a Cyber Essentials assessment

NCSC: Cyber Essentials Supply Chain Playbook

NCSC: Cyber Essentials help and resources

DSIT: Cyber Security Breaches Survey 2025/2026

Cabinet Office: Procurement Policy Note 014, Cyber Essentials scheme

Procurement Act 2023, section 56

HMRC: 11.48 million beat the Self Assessment deadline

HMRC: Find out if and when you need to use Making Tax Digital for Income Tax

ATT: Multi-factor authentication, how can agents prepare?

HMRC: Agent Update issue 141, March 2026

Companies House: Authorised Corporate Service Providers

Companies House: Get ready to register as an Authorised Corporate Service Provider

Money Laundering Regulations 2017, regulation 40

Economic Crime and Corporate Transparency Act 2023

ICO: Enforcement action we have taken

UK GDPR Article 32, security of processing

UK Finance Annual Fraud Report 2026: payment fraud losses reach £1.28 billion

Infosecurity Magazine: NCSC playbook embeds Cyber Essentials in supply chains

HMRC: Report suspicious emails, websites and phishing

NCSC: Phishing attacks, defending your organisation

NCSC: Device security guidance

ICAEW: Professional indemnity insurance regulations

Xero: Multi-factor authentication FAQs

Microsoft: Mandatory multifactor authentication for Microsoft services

SecurityBrief UK: Cyber attacks top risk for professional firms in 2026

Cyber Daily: Ernst & Young informs clients of third-party data breach

Cyber Essentials scheme background