Skip to main content
Security Best Practices

Cyber Essentials vs PCI DSS: Which Does Your Business Need?

One is a UK government-backed security badge, the other a contractual requirement from your bank. Here is what Cyber Essentials and PCI DSS each cover, what they cost, and when you need one — or both.

Fraud Defence First
14 July 2026
6 min read

Two names come up again and again when UK businesses look into security accreditation: Cyber Essentials and PCI DSS. They sound similar, both involve an annual assessment, and both end with something you can show a customer or a bank. But they answer different questions, are enforced by different people, and — crucially — one of them is not optional if you take card payments. This guide explains what each scheme covers, what each costs, where they overlap and how to decide which your business needs.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered through IASME and its network of certification bodies. Its purpose is basic cyber hygiene: demonstrating that your organisation has five fundamental technical controls in place across its IT.

  • Firewalls — a protected boundary between your network and the internet.
  • Secure configuration — default passwords changed, unnecessary software and accounts removed.
  • Security update management — patches applied promptly, especially critical ones.
  • User access control — accounts and admin rights limited to the people who need them.
  • Malware protection — anti-malware software or equivalent controls on your devices.

Certification at the basic level is an annual self-assessment questionnaire, signed off at board level and verified by an assessor. A second tier, Cyber Essentials Plus, adds an independent technical audit of your systems for a higher fee. Certificates are valid for twelve months, so it is a yearly exercise either way.

What is PCI DSS?

PCI DSS — the Payment Card Industry Data Security Standard, currently at version 4.0.1 — is the card brands' security standard for anyone who stores, processes or transmits cardholder data. It is not government-run and not voluntary: it is a contractual requirement in your merchant agreement with your acquirer, the bank that settles your card takings. Most smaller businesses validate through a Self-Assessment Questionnaire (SAQ) matched to how they take payments. If the standard is new to you, start with our plain-English explainer, what is PCI DSS compliance?, or the complete PCI DSS compliance guide.

Who enforces each one — and what happens if you skip it?

Nobody 'enforces' Cyber Essentials the way a bank enforces PCI. It is voluntary unless a contract demands it: skip it and the consequence is simply that you cannot bid for work that requires it, and you lose a useful signal of good practice. There is no monthly penalty for not holding it.

PCI DSS is different. If you accept card payments, your merchant agreement already obliges you to comply, and your acquirer checks. Fail to validate and most acquirers add a non-compliance fee — typically £5 to £25 a month — to your statement until you do. Suffer a card data breach while non-compliant and you face investigation costs, card-brand fines and liability that can run into thousands. One scheme is a badge you choose to earn; the other is a standing obligation you already signed up to.

When do you need Cyber Essentials?

Cyber Essentials earns its keep in three situations:

  • Public-sector bids — many UK central government contracts, particularly those involving personal data or the supply of certain IT services, require suppliers to hold Cyber Essentials, and the Ministry of Defence requires it widely across its supply chain.
  • Supply-chain requirements — larger private-sector customers increasingly ask for it before they will onboard you as a supplier.
  • Baseline assurance — it is a recognised, affordable way to show customers and insurers that the fundamentals are covered, and some insurers view certified businesses more favourably.

When do you need PCI DSS?

The moment you accept card payments — in person, online or over the phone. It is not sector-specific, not size-dependent and not a choice. Even if payments are fully outsourced to a hosted checkout and card data never touches your systems, you still validate annually, usually with the short SAQ A. There is no turnover threshold below which PCI DSS stops applying; a market stall with a card reader is in scope just as a supermarket is.

Where do the two schemes overlap?

There is genuine common ground, which is why businesses that hold one find the other easier. Both expect prompt patching of software, both require access to systems to be restricted and accounts to be individually identifiable, both demand malware protection and sensibly configured firewalls, and both now expect multi-factor authentication in key places — Cyber Essentials for access to cloud services, PCI DSS v4.0.1 for access into the environment where card data lives. Do the groundwork for one and you have made a start on the other.

The differences matter just as much. Scope is the big one: Cyber Essentials looks at your whole organisation's IT at a baseline level, while PCI DSS looks deeply — and only — at whatever touches cardholder data. Cyber Essentials says nothing about how staff handle card numbers over the phone; PCI DSS says a great deal. And the assessments differ in shape: Cyber Essentials is one fixed questionnaire for everyone, while PCI DSS routes you to one of several SAQs (A, A-EP, B, B-IP, C, C-VT or D) depending on how payments flow through your business — picking the right one is half the battle.

What does each cost?

Basic Cyber Essentials certification is priced by organisation size and typically costs between £300 and £600 + VAT a year through a certification body; Cyber Essentials Plus, with its hands-on audit, usually runs to four figures. PCI DSS costs depend on how you validate: doing it yourself costs time more than money (though many acquirers charge programme fees regardless), while our fully managed PCI compliance service handles the whole thing — correct SAQ, evidence, scans where needed, filing — for £100 + VAT a year. Ignoring PCI is the expensive option: £5 to £25 a month in non-compliance fees is £60 to £300 a year for precisely nothing.

A worked example: a twelve-person design agency bids for public-sector work and takes client payments by card. It sensibly holds both — say £440 + VAT for Cyber Essentials at its size band, plus £100 + VAT for managed PCI compliance. That is £540 + VAT a year for both certifications, which is less than many agencies bill for a single day. Compare that with losing one public tender for want of Cyber Essentials, or quietly paying a £15 monthly PCI penalty (£180 a year) because nobody completed an SAQ.

So which does your business need?

  • You take card payments — you need PCI DSS. This is not optional and no other certificate substitutes for it.
  • You bid for government, MoD or larger corporate contracts — you likely need Cyber Essentials (or Plus, where specified).
  • You do both — hold both; the overlap means the second is noticeably easier than the first.
  • You take no card payments and face no contractual demands — Cyber Essentials is still a sensible, affordable baseline; PCI DSS simply does not apply to you.

One final point of confusion worth clearing up: neither scheme is data-protection law. Holding Cyber Essentials or a validated SAQ does not make you 'GDPR compliant', although both help you evidence security measures. For how PCI DSS sits alongside the UK GDPR, see PCI DSS vs GDPR.

Need Expert PCI Compliance Help?

Our PCI compliance specialists are here to guide your business through the certification process. Get personalised advice and ensure your business stays compliant.

27/06/2026
7 min

PCI DSS vs GDPR vs Cyber Essentials: How They Fit Together

PCI DSS, UK GDPR and Cyber Essentials are three different things businesses often confuse. Here's what each covers, where they overlap, and why you may need all three.

Read Article
14/07/2026
6 min

'My Provider Handles PCI for Me' — What Your Acquirer Actually Does (and Doesn't)

Your payment provider secures its systems — but PCI validation, your premises and your staff stay your responsibility. Here is where the line really sits, and how to stop paying for the misunderstanding.

Read Article
14/07/2026
6 min

PCI Compliance for Hotels and B&Bs: Phone, Online and Front-Desk Payments

Phone bookings, OTA virtual cards and no-show guarantees make accommodation one of the riskiest sectors for card data. Here is how hotels, guest houses and B&Bs get PCI DSS right.

Read Article