The Cyber Essentials checklist, in full.
This Cyber Essentials checklist covers the five technical controls the scheme assesses, what evidence each one needs, and the scope decisions that determine how much work you are taking on. It is the complete list, not a preview — work through it before you pay, because the assessment fee buys you six months to submit and two working days to fix anything you get wrong.
Last reviewed
Download it
Decide scope first
Scope determines everything else on this list, and getting it wrong is the most expensive mistake available.
Cyber Essentials is assessed against a defined scope. That can be the whole organisation, or a clearly separated sub-network — but the boundary has to be real and defensible, not drawn to exclude whatever is inconvenient.
Work through these before anything else:
- What is in scope? All end-user devices, servers, cloud services and networks used to access organisational data or services — including staff home working devices and personally owned devices used for work.
- Are you certifying the whole organisation? Whole-organisation scope is simplest to explain to customers. A sub-scope needs genuine segmentation, and you will be asked to describe it.
- Which cloud services are included? Effectively all of them — anything holding organisational data or providing a service. This is the question that most often uncovers tools nobody knew were in use.
- Is anything running unsupported software? Answer this now. Unsupported software within scope is an automatic fail, not a finding.
Note that the size band you pay in is based on the whole organisation’s headcount, not the scoped portion. Narrowing scope reduces work, not fee.
1. Firewalls
Every device in scope sits behind a correctly configured firewall.
- A firewall protects every in-scope deviceA boundary firewall at the network edge, or a host-based firewall on devices used on untrusted networks — which includes home and public Wi-Fi.
- Default administrative passwords changedOn every firewall and internet gateway, to something not guessable.
- Administrative interfaces not exposed to the internetOr, where genuinely necessary, protected by multi-factor authentication or an IP allow-list, and documented.
- Inbound rules documented and business-justifiedEvery permitted inbound service has an owner and a reason. Rules that no longer have either are removed.
- Host-based firewalls enabled on laptopsEnabled and configured, not simply present and switched off.
2. Secure configuration
Devices and services are set up to reduce inherent vulnerability.
- Unnecessary user accounts removed or disabledIncluding guest, test and shared accounts nobody has used in months.
- Default passwords changed everywhereDevices, applications and services, not just the obvious network kit.
- Unnecessary software removed or disabledIf it is not needed for a business purpose, it is attack surface.
- Auto-run disabledSo removable media cannot execute automatically on connection.
- Device unlocking is controlledA password, PIN or biometric is required, with brute-force protection — either a lockout after a limited number of attempts or a throttle between attempts.
- No unnecessary services reachable from the internetConfirmed by looking from the outside, not by reading a configuration file.
3. Security update management
The control that fails the most assessments, because it applies to everything rather than to servers.
- All software is supported by its vendorOperating systems, applications, browsers, plugins, firmware. Anything unsupported in scope is an automatic fail — remove it, upgrade it, or take it out of scope properly.
- High-risk and critical updates applied within 14 daysMeasured from vendor release. This is the specific, testable requirement — not “promptly”.
- Automatic updates enabled where availableThe most reliable way to meet the 14-day requirement without tracking it manually.
- Licensing is currentSoftware must be licensed and supported, which are two separate conditions.
- Someone owns the exceptionsAnything that cannot be patched on time has a named owner, a documented reason and a compensating control.
4. User access control
Accounts are individual, justified, and removed when they should be.
- Every user has their own accountNo shared logins for access to organisational data or services.
- Account creation follows an approval processDocumented, with a record of who approved what.
- Accounts are removed when people leavePromptly, and demonstrably — this is a favourite evidence request.
- Administrative accounts are separate from everyday accountsAn administrator does not browse the web and read email from an account with administrative privilege.
- Administrative privilege is reviewedPeriodically, with privilege removed when a role no longer needs it.
- Multi-factor authentication on cloud servicesRequired. The usual gap is not the main identity provider but a standalone SaaS tool bought outside IT.
- Passwords meet the scheme’s requirementsProtection against brute force, plus a policy on length and quality — the scheme accepts several approaches, so pick one and apply it consistently.
5. Malware protection
Active, current, and actually tested at Plus.
- Anti-malware is installed and active on in-scope devicesIncluding laptops used off the corporate network.
- Signatures and engine are kept up to dateAutomatically, and verifiably.
- Or an equivalent approach is in placeApplication allow-listing is an accepted alternative where anti-malware is not appropriate. Sandboxing is the third route. Pick one and be able to evidence it.
- Web and file protections are enabledBlocking known malicious sites and scanning files on access.
Before you submit
The process facts worth knowing, because they change how you sequence the work.
- Download the question set and answer it on paper firstIt is free from IASME. If you have prepared your answers, filling in the self-assessment takes about an hour — the preparation is the real work.
- Fix the automatic-fail items before payingUnsupported software and missing MFA on cloud services are the two that most reliably cost people a second assessment fee.
- Get board sign-off readyA board member must sign a declaration that the answers are true. That is what gives a self-assessment its weight, and it takes calendar time to arrange.
- Know the clocksSix months from application to submit, or the account may be closed with no refund. Most assessors aim to return results within three days. If you fail, you get two working days to correct and resubmit at no extra charge.
- If you need Plus, plan it as one projectCertify to Plus within three months of the self-assessment and you do not repeat the question set. See Cyber Essentials Plus for what the audit actually tests.
The checklist, answered.
What are the five Cyber Essentials controls?
What is in scope for Cyber Essentials?
What automatically fails Cyber Essentials?
How long do I have to complete the assessment?
Is there a vulnerability scan at the basic level?
Related reading.
Your suppliers hold certificates too. Check them.
Book a 30-minute call and we will assess one of your certified suppliers from the outside — scope, currency and what has changed since the audit.