Cyber Essentials and Your Web Hosting: What Actually Counts
What Cyber Essentials certification actually covers, why no hosting provider can certify you, where your website and hosting sit in scope, what changed in the April 2026 update, and what to ask a host.
If a client, a council or a prospective customer has asked whether you hold Cyber Essentials, you have probably also wondered whether your web hosting affects the answer. It does, but less than most hosting companies imply. This guide explains where hosting genuinely sits in the scheme, what changed in 2026, and what to ask a provider.
No hosting provider can make you Cyber Essentials compliant
Worth saying plainly, because a lot of hosting marketing blurs it. Cyber Essentials certifies an organisation, not a service you buy. You complete an assessment covering everything in your defined scope: laptops, phones, routers, cloud accounts and the people using them. A host with good security practices removes some friction. It does not certify you, and it cannot answer the questionnaire on your behalf.
For most small organisations, the bulk of the work is the devices your staff use, not the server your website sits on.
The five technical controls
Every assessment is graded against the same five controls:
- Firewalls – every device connecting to the internet needs firewall protection, and default passwords on routers and firewall interfaces have to be changed.
- Secure configuration – remove unnecessary functionality, disable unused and guest accounts, change default passwords before deployment. One of the most commonly failed controls.
- User access control – accounts limited to what each role needs, administrator rights granted deliberately rather than by default, and multi-factor authentication enabled wherever it is available.
- Malware protection – on every in-scope device.
- Security update management – updates applied within 14 days for anything the vendor rates critical or high risk, anything scoring 7 or above on CVSS v3, and anything where the vendor gives no severity rating at all.
What changed in 2026
The question set changed on 26 April 2026, from Willow to Danzell. Three changes matter most:
- Multi-factor authentication on cloud services is mandatory. Failing to enable it where the service offers it is an automatic fail, with no exceptions for internet-facing accounts.
- The 14-day patch window is now an auto-fail condition, not something you can explain your way around. The cPanel vulnerability disclosed in April 2026 is a useful worked example: at CVSS 9.8 it sat comfortably inside the window, and whether your host patched promptly was not something you could control.
- Cloud services are fully in scope. Anything holding your organisation’s data counts, including services individual staff signed up for without telling anyone.
If you certified under the older Willow question set, your renewal will be assessed against the newer requirements.
Where your website and hosting actually sit
Your website is usually in scope, and the control that bites hardest is security update management. That means the software you run, not just the server underneath it:
- PHP version. A site still on PHP 7.4 is running software with no security support at all. Moving to a current version is the single most useful thing most sites can do, and it makes them faster into the bargain. See our guide on how PHP versions affect performance.
- WordPress core, themes and plugins. Every one is software with its own update cycle, and an abandoned plugin is a compliance problem as much as a security one.
- Control panel and admin accounts. These fall under user access control: multi-factor authentication where available, no shared logins, and old staff or contractor accounts removed rather than left dormant.
Our WordPress security checklist covers most of this in practical terms.
What to ask a hosting provider
Useful questions, rather than reassuring ones:
- Which PHP versions can I run, and how long do you support each one?
- How quickly do you patch the server software, and do you publish anything about it?
- Does the control panel support multi-factor authentication?
- Can I create separate logins for staff and contractors with limited permissions?
- Where are the servers, and who has physical access to them?
- What happens if my site is compromised, and what do you expect me to do?
A provider’s own certifications are worth knowing about, but they answer a different question from the one your assessor will ask you.
Our guide to comparing UK hosting providers covers how to judge the answers you get, including how to check where a provider’s servers physically are rather than taking the marketing at face value.
That last question matters more than it looks. Knowing in advance what your host will do if your site is compromised, and what they expect you to do, is the difference between a contained incident and a fortnight of confusion. Our step-by-step guide to what to do when a WordPress site has been hacked is worth reading before you need it, and our guide to viewing and restoring backups covers choosing a restore point that predates the compromise, which is where most recoveries go wrong.
Who actually gets asked for this
Cyber Essentials rarely arrives as a spontaneous decision. It turns up as a question on somebody else’s form, and the sectors where that happens most are reasonably predictable. We have covered the hosting side for several of them:
- Law firms. Corporate client due diligence, lender panels and quality standards. See web hosting for solicitors.
- Accountancy practices. Supplier due diligence before appointment, particularly from larger clients. See web hosting for accountants.
- Schools and colleges. The Department for Education’s digital and technology standards point towards it, and trusts and insurers increasingly expect it. See web hosting for schools.
- Charities and non-profits. Grant bodies, local authorities and corporate partners ask before awarding. See charity WordPress hosting.
- Town and parish councils. Insurers, principal authorities and shared services arrangements. See web hosting for town councils.
- Startups selling to larger organisations. Often the first enterprise contract is where the question appears. See web hosting for startups.
Our wider professional services hosting guide covers the ground shared across regulated, client-facing businesses.
The two levels, and what they cost
Cyber Essentials is an independently reviewed self-assessment: you submit your answers, a board member or equivalent confirms they are accurate, and a qualified external assessor reviews them. Cyber Essentials Plus covers the same five controls but adds hands-on technical testing by a licensed assessor, including vulnerability scans on a sample of your devices. Both certificates last 12 months.
Standard certification starts at around ยฃ320 plus VAT, banded by organisation size. Plus costs more and scales with the size of your estate.
Most organisations do not choose their level. The contract or the tender chooses it for them.
Where to start
Before you open the questionnaire, build one accurate list of every device and cloud service that touches your organisation’s data, including home working and personal devices. Incomplete scope is the most common reason organisations fail, and you cannot certify controls on devices you cannot see.
Certification is delivered through IASME-accredited certification bodies, and the current requirements specification is published on the NCSC website.
Hosting that does not get in the way
Switchweb runs UK-based servers with current PHP versions, free SSL, daily backups and malware scanning as standard rather than as paid extras. None of that certifies you, but it does mean the hosting side of your assessment is one of the easier parts.
Looking to get started on Switchweb? Take a look at our website hosting plans or message us about a free trial.