Cyber Essentials Requirements: A Practical Checklist
Cyber Essentials is organised around five technical controls. Before applying, define what your organisation is responsible for, understand what is in scope, and prepare the systems, accounts, and services that support your work.
The five controls
Define scope first, then use this practical guide to work through firewalls, secure configuration, updates, access, and malware protection.
Based on Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026). For assessment accounts registered from 27 April 2026.
Start here
Understand Your Scope
Start by drawing a clear boundary around the business unit, locations, networks, hardware, software, and cloud services covered by your application. Your scope may be the whole IT infrastructure or a well-defined, separately managed sub-set agreed with your Certification Body.
- Computers and laptops
- Servers and networks
- Mobile phones, tablets, and other end-user devices
- Routers, firewalls, and VPNs
- Operating systems, applications, software, and firmware
- Cloud services and organisational services
- Home workers, remote workers, and their work devices
Cloud services: If a cloud service holds or processes your organisational data or provides an organisational service, include it in scope. Cloud services cannot simply be ignored or excluded because another provider hosts them.
Cloud providers handle parts of the underlying service, but that shared-responsibility model does not remove your responsibility for the accounts, access, configuration, data, devices, and services covered by your assessment.
Cyber Essentials five controls
Work through each control in plain English.
These sections are a preparation route for the technical requirements. Use the official requirements and your Certification Body’s current question set when you complete an application.
- 01
Firewalls
Control the traffic that can reach your devices and services, and keep the management interface protected.
- Change default administrative passwords to strong, unique passwords, or disable remote administrative access altogether.
- Block unauthenticated inbound connections by default and keep firewall administration off the public internet unless there is a documented business need with suitable protection.
- Approve and document inbound rules, including the business need, and regularly review them.
- Remove or disable unnecessary firewall rules when they are no longer needed; use a software firewall on devices connecting to untrusted networks such as public Wi-Fi.
Treat firewall rules and credentials as a maintained control, not a one-time setup task.
- 02
Secure Configuration
Reduce avoidable weaknesses by controlling how devices, applications, services, and cloud platforms are configured.
- Change default passwords and settings, and control and regularly review configurations against an agreed baseline.
- Remove or disable unnecessary user accounts, software, services, and functionality, including features that are not needed for the role.
- Use supported security settings for operating systems, applications, routers, firewalls, mobile devices, and cloud services.
- Record meaningful configuration changes so that an unexpected setting can be investigated and corrected.
A configuration review should cover the systems and services in scope, not only the office network.
- 03
Security Update Management
Keep software and firmware licensed, supported, and updated, with a clear route for urgent vulnerability fixes.
- Keep operating systems, applications, routers, firewalls, and firmware licensed and supported by a vendor that provides vulnerability fixes.
- Remove end-of-life or unsupported software from devices, or place it in a defined, isolated sub-set that prevents all traffic to or from the internet.
- Enable automatic updates where possible and apply vulnerability fixes within 14 days of release when the vendor calls them critical or high risk, the CVSS v3 base score is 7 or above, or the vendor gives no severity details.
- Track exceptions and update evidence so that urgent fixes are not missed when an update covers several issues.
The official 14-day requirement applies to those update classes. Applying every update within 14 days is strongly recommended for optimum security, but is not the blanket mandatory rule. An unmet mandatory requirement should be treated as a certification blocker; confirm the current assessment question and outcome with your Certification Body rather than inventing an automatic-fail rule.
- 04
User Access Control
Make access personal, approved, proportionate to each role, and removed promptly when it is no longer needed.
- Create and approve individual user accounts, authenticate users with unique credentials, and remove or disable accounts when someone leaves or an account is no longer required.
- Review access when someone changes role and give users only the applications, devices, and services needed for their work.
- Use least privilege, keep administrator controls limited, and use separate administrator accounts for administrative activity where appropriate.
- Implement MFA where it is available; authentication to cloud services must always use MFA. Passwordless options such as passkeys and FIDO2 authenticators can provide a passwordless authentication method, with FIDO2 treated as MFA in the v3.3 guidance.
Include third-party support accounts in the review and keep an auditable joiner, mover, and leaver process.
- 05
Malware Protection
Use an active, current mechanism that helps prevent malicious code from running and malicious web connections from succeeding.
- Keep a malware protection mechanism active on every device in scope and keep it up to date in line with the vendor instructions.
- Use anti-malware protection configured to prevent malware from running, prevent malicious code execution, and prevent connections to malicious websites where supported.
- Alternatively, use application allowlisting with code-signing controls, active approval, and a current list of approved applications.
- Review whether protection applies across servers, desktops, laptops, tablets, mobile phones, and relevant cloud service models in scope.
Antivirus alone does not guarantee compliance: the mechanism must be active, current, and configured to meet the applicable protection requirements.
A working list
Quick checklist
Use these prompts to turn the Cyber Essentials requirements into a practical preparation list. Checking a box is a reminder to verify the evidence, not a certification decision.
Review prompts
Common Things to Check
Use these as prompts for a review of your own environment, not as assumptions about what another organisation has missed.
- Can you name every device, router, firewall, cloud service, and remote-working route that belongs inside your chosen scope?
- Do former users, shared accounts, third-party accounts, and old administrator accounts still have access?
- Can you show which updates are urgent, who owns them, and when the 14-day clock starts?
- Are old applications, firmware, firewall rules, services, and default credentials still present because nobody owns their removal?
- Would a configuration change or access decision leave a useful record for the person answering the assessment?
- Is protection active and current on every in-scope device, including devices used away from the office?
Cloud-service preparation
Microsoft 365
Microsoft 365 is a cloud service and should be considered within scope when it stores or processes organisational data or provides an organisational service. Check MFA for cloud authentication, individual user accounts, admin roles and separate administrative access, and the tenant security settings that support your controls. Microsoft 365 does not automatically equal Cyber Essentials compliance: your organisation remains responsible for the relevant configuration, devices, access, and scope.
- MFA for every cloud-service sign-in, with a practical passwordless option considered where appropriate.
- Individual user accounts, joiner/mover/leaver processes, and least-privilege access.
- Tightly controlled admin roles and separate admin accounts for administrative work where appropriate.
- Tenant security settings, device coverage, update ownership, and evidence that match your chosen scope.
Prepare with a clear next step
Turn the checklist into a readiness conversation.
Use the readiness check to organise what you know, then decide whether you need focused Cyber Essentials support or a wider security assessment and remediation route.
This is a plain-English preparation guide. It does not replace the official Cyber Essentials requirements or your Certification Body’s assessment guidance, and it does not guarantee certification.