Knowledge Centre
Cyber Security GuidesChecklist

Cyber Essentials Readiness Checklist

15 minutes to completeEvergreen guide — kept up to date

Cyber Essentials is the UK government-backed certification that shows your business has the fundamental security controls in place. Certification is assessed against five control areas. Reviewing them before you apply saves time, avoids failed submissions and — more importantly — closes real gaps whether or not you ever certify.

Cyber Essentials is assessed by self-assessment questionnaire (Cyber Essentials) or with an independent technical audit (Cyber Essentials Plus). Either way, the same five control areas apply. Use this checklist to find and fix the gaps before you pay for an assessment.

Step 1: Define your scope

  • We have listed every laptop, desktop, server and mobile device used for business.
  • We have listed the cloud services the business relies upon (Microsoft 365, accounting, CRM and similar).
  • We know which devices are company-owned and which are personal (BYOD).
  • Personal devices that access business data are included in scope.
  • Devices and operating systems that no longer receive security updates have been identified.

Unsupported operating systems are a common reason for failure. A single Windows machine that no longer receives updates can prevent certification.

Step 2: Firewalls and internet gateways

  • Every internet connection is protected by a firewall.
  • Default administrator passwords on routers and firewalls have been changed.
  • Firewall administration is not exposed to the internet, or is protected by MFA or IP restriction.
  • Unused inbound firewall rules have been removed.
  • Software firewalls are enabled on devices used on untrusted networks (home, public Wi-Fi).

Step 3: Secure configuration

  • Unused software, apps and services have been removed from devices.
  • Unused user accounts have been removed or disabled.
  • Auto-run of files from removable media is disabled.
  • Device locking is enforced (PIN, password or biometric).
  • Default passwords on all devices and services have been changed.

Step 4: User access control

  • Every user has their own account — no shared logins.
  • Accounts are created through an approval process and removed promptly when staff leave.
  • Administrator accounts are separate from everyday accounts.
  • Administrator accounts are not used for email or web browsing.
  • Multi-factor authentication is enabled on all cloud services, and always for administrators.
  • Passwords meet the minimum length requirement (at least 8 characters with MFA, 12 without).

Step 5: Malware protection

  • Anti-malware software is installed and active on every in-scope device.
  • It updates automatically and scans files on access.
  • It scans web pages and blocks known-malicious websites, or an equivalent control is in place.
  • Only approved application stores or approved software lists are used where relevant.

Step 6: Security update management

  • All operating systems and applications are licensed and supported by the vendor.
  • Automatic updates are enabled wherever possible.
  • High and critical security updates are applied within 14 days of release.
  • Unsupported software has been removed or isolated from the internet.

Before you submit

  1. 1Walk through each control area above and record the evidence: settings, screenshots and policies.
  2. 2Fix any gaps — do not certify around them.
  3. 3Decide between Cyber Essentials and Cyber Essentials Plus (audited, and increasingly requested in supply chains).
  4. 4Choose a certification body accredited by IASME.

Why certify at all?

  • Many public-sector contracts require Cyber Essentials.
  • Larger customers increasingly ask suppliers for it.
  • Certification can include cyber insurance for smaller organisations.
  • The controls themselves block the most common attacks.

Plain-English Takeaway

Cyber Essentials is built on five practical control areas: firewalls, secure configuration, access control, malware protection and security updates. Review each one honestly before applying — the review closes real security gaps whether or not you go on to certify.

Downloadable guide

Download the Cyber Essentials Readiness Checklist

A one-page printable checklist covering scope and the five Cyber Essentials control areas.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.