Cyber Essentials checklist

The Cyber Essentials checklist, in full.

This Cyber Essentials checklist covers the five technical controls the scheme assesses, what evidence each one needs, and the scope decisions that determine how much work you are taking on. It is the complete list, not a preview — work through it before you pay, because the assessment fee buys you six months to submit and two working days to fix anything you get wrong.

Last reviewed

Download it

This checklist is available as a PDF. The full content is on this page — the download is the same thing in a form you can print, circulate or work through offline. Get it from the resource library, filed under Checklists.

Decide scope first

Scope determines everything else on this list, and getting it wrong is the most expensive mistake available.

Cyber Essentials is assessed against a defined scope. That can be the whole organisation, or a clearly separated sub-network — but the boundary has to be real and defensible, not drawn to exclude whatever is inconvenient.

Work through these before anything else:

  • What is in scope? All end-user devices, servers, cloud services and networks used to access organisational data or services — including staff home working devices and personally owned devices used for work.
  • Are you certifying the whole organisation? Whole-organisation scope is simplest to explain to customers. A sub-scope needs genuine segmentation, and you will be asked to describe it.
  • Which cloud services are included? Effectively all of them — anything holding organisational data or providing a service. This is the question that most often uncovers tools nobody knew were in use.
  • Is anything running unsupported software? Answer this now. Unsupported software within scope is an automatic fail, not a finding.

Note that the size band you pay in is based on the whole organisation’s headcount, not the scoped portion. Narrowing scope reduces work, not fee.

1. Firewalls

Every device in scope sits behind a correctly configured firewall.

  • A firewall protects every in-scope device
    A boundary firewall at the network edge, or a host-based firewall on devices used on untrusted networks — which includes home and public Wi-Fi.
  • Default administrative passwords changed
    On every firewall and internet gateway, to something not guessable.
  • Administrative interfaces not exposed to the internet
    Or, where genuinely necessary, protected by multi-factor authentication or an IP allow-list, and documented.
  • Inbound rules documented and business-justified
    Every permitted inbound service has an owner and a reason. Rules that no longer have either are removed.
  • Host-based firewalls enabled on laptops
    Enabled and configured, not simply present and switched off.

2. Secure configuration

Devices and services are set up to reduce inherent vulnerability.

  • Unnecessary user accounts removed or disabled
    Including guest, test and shared accounts nobody has used in months.
  • Default passwords changed everywhere
    Devices, applications and services, not just the obvious network kit.
  • Unnecessary software removed or disabled
    If it is not needed for a business purpose, it is attack surface.
  • Auto-run disabled
    So removable media cannot execute automatically on connection.
  • Device unlocking is controlled
    A password, PIN or biometric is required, with brute-force protection — either a lockout after a limited number of attempts or a throttle between attempts.
  • No unnecessary services reachable from the internet
    Confirmed by looking from the outside, not by reading a configuration file.

3. Security update management

The control that fails the most assessments, because it applies to everything rather than to servers.

  • All software is supported by its vendor
    Operating systems, applications, browsers, plugins, firmware. Anything unsupported in scope is an automatic fail — remove it, upgrade it, or take it out of scope properly.
  • High-risk and critical updates applied within 14 days
    Measured from vendor release. This is the specific, testable requirement — not “promptly”.
  • Automatic updates enabled where available
    The most reliable way to meet the 14-day requirement without tracking it manually.
  • Licensing is current
    Software must be licensed and supported, which are two separate conditions.
  • Someone owns the exceptions
    Anything that cannot be patched on time has a named owner, a documented reason and a compensating control.

4. User access control

Accounts are individual, justified, and removed when they should be.

  • Every user has their own account
    No shared logins for access to organisational data or services.
  • Account creation follows an approval process
    Documented, with a record of who approved what.
  • Accounts are removed when people leave
    Promptly, and demonstrably — this is a favourite evidence request.
  • Administrative accounts are separate from everyday accounts
    An administrator does not browse the web and read email from an account with administrative privilege.
  • Administrative privilege is reviewed
    Periodically, with privilege removed when a role no longer needs it.
  • Multi-factor authentication on cloud services
    Required. The usual gap is not the main identity provider but a standalone SaaS tool bought outside IT.
  • Passwords meet the scheme’s requirements
    Protection against brute force, plus a policy on length and quality — the scheme accepts several approaches, so pick one and apply it consistently.

5. Malware protection

Active, current, and actually tested at Plus.

  • Anti-malware is installed and active on in-scope devices
    Including laptops used off the corporate network.
  • Signatures and engine are kept up to date
    Automatically, and verifiably.
  • Or an equivalent approach is in place
    Application allow-listing is an accepted alternative where anti-malware is not appropriate. Sandboxing is the third route. Pick one and be able to evidence it.
  • Web and file protections are enabled
    Blocking known malicious sites and scanning files on access.

Before you submit

The process facts worth knowing, because they change how you sequence the work.

  1. Download the question set and answer it on paper first
    It is free from IASME. If you have prepared your answers, filling in the self-assessment takes about an hour — the preparation is the real work.
  2. Fix the automatic-fail items before paying
    Unsupported software and missing MFA on cloud services are the two that most reliably cost people a second assessment fee.
  3. Get board sign-off ready
    A board member must sign a declaration that the answers are true. That is what gives a self-assessment its weight, and it takes calendar time to arrange.
  4. Know the clocks
    Six months from application to submit, or the account may be closed with no refund. Most assessors aim to return results within three days. If you fail, you get two working days to correct and resubmit at no extra charge.
  5. If you need Plus, plan it as one project
    Certify to Plus within three months of the self-assessment and you do not repeat the question set. See Cyber Essentials Plus for what the audit actually tests.

The checklist, answered.

What are the five Cyber Essentials controls?
Firewalls, secure configuration, security update management, user access control and malware protection. They are identical for Cyber Essentials and Cyber Essentials Plus — what differs is that Plus verifies them by technical audit rather than by marking your answers.
What is in scope for Cyber Essentials?
All end-user devices, servers, cloud services and networks used to access organisational data or services — including home working and personally owned devices used for work. You may certify a clearly segmented sub-network instead of the whole organisation, but the boundary must be genuine.
What automatically fails Cyber Essentials?
Unsupported software anywhere within the scope of the assessment. IASME treats it as an outright fail rather than a finding, so a single end-of-life operating system in scope is enough.
How long do I have to complete the assessment?
Six months from the date of application. After that your account may be closed and you would have to apply and pay again, with no refund.
Is there a vulnerability scan at the basic level?
No. The verified self-assessment includes no test or vulnerability scan — instead a board member signs a declaration that the answers are true. Scanning comes in at Cyber Essentials Plus.

Your suppliers hold certificates too. Check them.

Book a 30-minute call and we will assess one of your certified suppliers from the outside — scope, currency and what has changed since the audit.