Cyber security compliance for UK small businesses: what you actually need
11 September 2026 · 6 min read
Cyber security compliance sounds like something that belongs to large organisations with a security team. For most UK small businesses it comes down to three things: a recognised baseline such as Cyber Essentials, sensible handling of personal data under UK GDPR, and whatever your own customers write into their contracts.
Start with the baseline. Cyber Essentials covers five technical controls — firewalls, secure configuration, security updates, user access control and malware protection. It is the standard most UK buyers ask about by name, and it is the fastest way to turn a vague security question in a tender into a certificate you can attach.
Then handle data. UK GDPR does not prescribe technology, but it does expect appropriate measures. In practice, the same controls that pass Cyber Essentials — individual accounts, multi-factor authentication, supported software and current updates — are the measures an ICO enquiry would ask about.
Contracts are the third source of obligations, and the one that catches people out. Larger clients increasingly require certification, an incident response contact and evidence that leavers lose access promptly. Read the security schedule before you sign, not after.
You can safely postpone the rest. ISO 27001, SOC 2 and formal risk registers matter when your customers demand them or your headcount grows; they are rarely the right first investment for a ten-person firm.
Kept keeps the essentials in one place: a free scan of your cloud services, the policies assessors ask for, an evidence register that builds itself month by month, and renewal reminders so the certificate never lapses.
Kept