Cyber Essentials for a 1 to 9 Person Business, the Microbusiness Scope Playbook

Net Sec Group is an IASME and NCSC certification body. Across our 800-plus engagement history, the microbusiness band (1 to 9 employees), what UK government guidance also calls a small business at the lower end of the SME range, is the fastest-passing scope shape we see. Fewer asset edges, simpler cloud architecture, and direct line-of-sight from founder to evidence pack mean a typical microbusiness preparation time, with multi-factor authentication already in place on cloud admin, sits in the 5 to 7 day band rather than the 2 to 4 week band that mid-size firms experience. A 1 to 3 person business with no contractors and a single cloud platform can compress this further; the 7-day plan remains the published floor for the typical microbusiness. This article is the scope playbook for that band, the questions a founder needs to answer, and the worked examples from real engagements.

The article sits on the scope-decisions hub. The other scope-decision spokes cover the cloud-only profile, BYOD decisions, and Cyber Essentials without an IT team. For the broader startup-stage business angle, see the netsecgroup.io Cyber Essentials for Startups reference.

What "microbusiness" means for Cyber Essentials

The IASME scheme does not define "microbusiness" as a separate certification class; the same five controls apply at every size. What changes at the 1 to 9 person band is the shape of the assessment: fewer users, fewer devices, simpler scope, and consequently a faster engagement and a lower fee. Net Sec Group's published pricing reflects this through its pricing page.

The IASME requirement is to certify the "whole organisation" by default. For a microbusiness this is rarely a difficult call; if the firm has 5 employees, all 5 are in scope, all 5 use the cloud platforms, all 5 have laptops. The scope statement reads "the whole company" and the assessor accepts it.

Where microbusiness scope decisions become non-trivial is at the edges: the founder using their personal laptop, the home-office router being treated as a firewall, the contractor on a 4-week engagement, the dormant cloud account in the founder's name from a previous venture. This article walks through each.

Scope question 1, who counts as a user

The rule: every person who accesses organisational data using credentials in your identity provider is in scope as a user, regardless of whether they are an employee, a director, or a contractor.

Microbusiness translation: at 1 to 9 employees, this almost always means everyone. The 1-person sole trader has 1 user (themselves). The 3-person agency has 3 users. The 5-person consultancy with 2 contractors on a current engagement has 7 users.

Edge case: a non-executive director who has a Microsoft 365 mailbox to receive board papers but does no operational work. They are still a user; the mailbox is in-scope. The fix is either to leave them in scope (small overhead) or to remove the mailbox and route board papers a different way (also small overhead). The choice is a scope-cost decision the founder makes.

Worked example: a 4-person agency with 2 employees, 2 freelancers on retainer, 1 non-executive director with mailbox access, 1 dormant founder account from when the founder used their own Microsoft 365 personal subscription before incorporating. Scope is 4 employees plus 2 freelancers plus 1 NED = 7 in-scope users. The dormant founder account is excluded by closing the account before the engagement.

Scope question 2, which devices are in scope

The rule: every device that accesses organisational data is in scope. Laptops, desktops, tablets, phones, and any virtual machine or cloud PC the firm uses for in-scope work.

Microbusiness translation: company-issued laptops are clearly in scope. The decisions sit at the BYOD edges, especially the founder's personal hardware. See the BYOD decisions article for the full BYOD scoping treatment; the short version is that personal devices accessing organisational data are in scope, and the path the device takes (native app, browser, MDM enrolment, app-protection policy) determines the evidence requirements.

Edge case 1, founder's personal laptop: if the founder uses a personal MacBook for both personal and company work, the MacBook is in scope. The fix is either to issue a company laptop (cleanest) or to apply MDM and a Conditional Access policy to bring the personal MacBook into scope as a managed device. Either path passes; the company-laptop path is faster to evidence.

Edge case 2, founder's personal phone: same reasoning. A personal phone with the corporate Microsoft 365 mailbox is in scope. Browser-only access through Conditional Access can scope the phone out of the device sample (the conditional-access controls become the in-scope evidence). Native-app access requires an app-protection policy.

Edge case 3, contractor laptops on a short engagement: contractor laptops are in scope if they handle in-scope data. For a 4-week contractor engagement, the contractor laptop is in scope for those 4 weeks. The evidence formats are the BYOD formats; the engagement window is what changes.

Scope question 3, the home-office boundary firewall

The rule at CE Basic: a boundary control between the in-scope estate and the wider internet, evidenced by the firewall configuration.

Microbusiness translation: a microbusiness with no office and no on-premises infrastructure does not have a single boundary appliance to evidence. The home-office router on the founder's BT or Virgin Media broadband is not the boundary the assessor expects to see; the boundary the assessor accepts is the host-based firewall on each in-scope laptop (Windows Defender Firewall, macOS Application Firewall, Linux UFW). The cloud-only spoke covers this in detail; see the cloud-only business scope article for the per-control evidence formats.

Edge case, shared workspace: a microbusiness using a coworking space (WeWork, Regus, a local hub) treats the coworking-provided wireless as a transit network only. The in-scope boundary is still the device-level firewall on each laptop, not the coworking router. The coworking provider is not in scope.

Scope question 4, cloud accounts and admin separation

The rule at CE Basic: every administrative account on every in-scope cloud service has MFA enforced; admin actions are attributable to a named human; the leaver process is documented and run.

Microbusiness translation: a microbusiness running Microsoft 365 typically has 1 or 2 administrators (founder plus a deputy or external IT support). The full evidence pack is small: an admin list of 1 or 2 accounts, an MFA report covering both, a worked-example leaver record (or a written statement that no leavers have occurred since the firm was founded, with the leaver-process documentation ready to use when one does).

Edge case 1, founder is the only administrator: this is fine for CE Basic. The IASME requirement is that admin actions are attributable to a named human; one human is one named human. The risk is a single point of failure (the founder loses access), which the IASME requirement addresses by suggesting a break-glass admin procedure. Document the procedure even if you do not exercise it.

Edge case 2, external IT support has admin access: the external provider's admin account is in scope. Their MFA configuration must be evidenced; their leaver process (if they cycle staff) must be documented in the contract. This is straightforward to evidence; capture a screenshot of the provider's admin account in your tenant with MFA enforced.

Edge case 3, Google Workspace plus separate cloud subscriptions: a microbusiness on Google Workspace with a Stripe account, an AWS account, and a Heroku account has 4 cloud platforms in scope. Each platform's admin accounts need MFA evidenced. The fix is to enable MFA on each platform's admin and capture per-platform screenshots; this is a 30-minute task at this scale.

Scope question 5, contractors and short engagements

The rule: contractors handling in-scope data are in scope as users; their devices are in scope by the BYOD rules.

Microbusiness translation: a 5-person agency with 2 freelance designers on a 6-month engagement has 7 users in scope. A 3-person consultancy with a freelance accountant filing returns has the accountant in scope as a user only if the accountant has a Microsoft 365 mailbox or other identity-provider account in your tenant. If the accountant works entirely on their own systems and exchanges files via email, they are not a user in your tenant and are out of scope.

Edge case, contractor with their own laptop on a 4-week engagement: the contractor's laptop is in scope for those 4 weeks. The evidence formats are the BYOD formats; the engagement window does not change the rule. After the engagement ends, the contractor's account is processed through the leaver process and the laptop is out of scope.

What microbusiness pass quickly looks like

A 4-person agency on Microsoft 365 with 4 company-issued laptops, MFA already enforced on the founder and deputy admin accounts, Microsoft Defender on every laptop, Microsoft Intune managing patch policy, and a written 5-line leaver process passes Cyber Essentials Basic in under a week of preparation followed by the 12-hour fast-track engagement. The total time from "we should look at this" to certificate is typically 8 to 9 working days; the cost is the published Net Sec Group fast-track tier price plus whatever new tooling the firm decides to buy in week 1 (typically nothing, since Microsoft 365 Business Premium provides MFA via Entra ID P1, anti-malware via Defender for Business, MDM and patch policy via Intune, and Conditional Access for cloud-admin enforcement; four of the five control areas in one Microsoft 365 SKU, leaving only the boundary-firewall evidence to assemble per device).

The patterns that take longer are the patterns that fail the pre-checks in the why-cyber-essentials-fails-first-try article: MFA gaps on cloud admin, an end-of-life operating system in scope, an asset list that does not reconcile against MDM and identity provider. Run the 8-item pre-check first; if all 8 return yes, the microbusiness 7-day path works.

Common questions

Does Cyber Essentials apply to a 1-person business or to any small business under 10 employees?

Yes. The five controls apply to a sole trader with 1 laptop, 1 cloud subscription, and no employees, the same as they apply to a 9-person agency or any small business in the 1 to 9 person band. The evidence pack is correspondingly smaller; the engagement runs in the same time bands.

Is there a separate microbusiness Cyber Essentials certificate?

No. The certificate is the same Cyber Essentials certificate at every size. The IASME scheme has one CE Basic certificate and one CE Plus certificate; the microbusiness band sits inside the same scheme.

My company is 8 people and growing. Should I certify now or wait?

Certify now. The microbusiness scope is simpler and cheaper to evidence than the 15 to 30 person scope you will be in 6 to 12 months. The certificate carries 12-month validity; you renew at the larger size when the time comes, and the renewal is straightforward because the scope grows incrementally rather than starting from cold. See the Cyber Essentials Scope Changes (Danzell) reference for the IASME scope-update rules between renewals.

My founder uses a personal MacBook for everything. Is that a problem?

It is in scope, not a problem. The cleanest fix is to issue a company MacBook so the personal device is out of scope. The next-cleanest fix is MDM enrolment and a Conditional Access policy on the personal MacBook. Both pass; the company-issued path is faster.

Do I need to certify before I can apply for government tenders?

UK government tenders frequently require Cyber Essentials. PPN 09/14 introduced the requirement in 2014; the current reference is PPN 03/23 (May 2023), which continues to require Cyber Essentials for relevant contracts handling personal data and certain ICT services. If you are bidding on a tender that requires CE, certification is the path; the 12-hour fast-track engagement is built for tender-deadline timing.

Where do we book?

Book a Cyber Essentials assessment with Net Sec Group. The booking form lets you describe the microbusiness profile in scope; the assessor returns a confirmed scope statement and engagement timeline.

Reference material

Where this fits on this site

This article is the microbusiness spoke under the scope-decisions hub. The other scope-decision spokes are the cloud-only business scope, BYOD decisions, and Cyber Essentials without an IT team. Once the scope is settled, the timelines hub indexes the three engagement-speed paths, with the 12-hour fast-track engagement the natural choice for a microbusiness that arrives ready.