Cyber Essentials assesses five technical control themes: firewalls, secure configuration, security update management, user access control and malware protection. The current requirements are version 3.3 for assessments started from 27 April 2026. Use this checklist to organise the work before you open the assessment, then verify every answer against the official question set for your certification route.
1. Decide and document the scope
Describe the organisation, business unit, network boundary and locations being certified. Build an inventory of internet-connected devices, software and cloud services within that boundary, including equipment used by home workers and relevant third parties.
Do not assume cloud services are automatically outside scope. Record who is responsible for configuring each service and whether you rely on the provider’s controls or settings you manage. Keep the scope understandable: unexplained exceptions make both assessment and ongoing security harder.
- Servers, desktops, laptops, tablets and mobiles
- Firewalls, routers and internet-facing network devices
- Home-working and bring-your-own devices that access organisational data or services
- Cloud services such as Microsoft 365 and line-of-business platforms
- Accounts or devices used by contractors and managed service providers
- Operating systems, firmware, browsers, office software and key applications
2. Check firewalls and internet gateways
Confirm that every in-scope device is protected by a correctly configured firewall, whether that is a network boundary device, a host firewall or controls supplied by a cloud service. Remove inbound rules and exposed services that are not required.
Change default or easily guessed administrator passwords. Restrict administrative access from the internet and document any business reason for an exposed service. Review port-forwarding, remote-management interfaces and temporary rules that may have outlived their purpose.
3. Apply secure configuration
- Remove or disable unused accounts, applications, services and features
- Change default passwords before equipment or software enters service
- Prevent routine users from performing administrative work
- Use screen locking and appropriate authentication controls
- Disable automatic execution of downloaded files where applicable
- Review device, browser and cloud-service settings against a maintained baseline
- Record any configuration that must remain less restrictive and the business reason
4. Bring software and devices into support
List operating systems, applications, browser extensions, firmware and network equipment. Anything no longer supported by its manufacturer should be removed, replaced, isolated outside the certified scope where legitimately possible, or covered by an accepted scheme allowance.
Enable automatic updates where practical. Cyber Essentials requires high-risk or critical security updates to be applied within 14 days of release when the relevant conditions in the requirements are met. Your process must cover applications and internet-facing devices as well as Windows or macOS. Record who checks that deployment has succeeded.
5. Tighten user and administrator access
Every user should have their own account and only the access needed for their role. Create a joiner, mover and leaver process that adds, changes and removes access promptly. Review dormant accounts and third-party access before assessment.
Separate administrator accounts from ordinary email and web-browsing accounts. Use multi-factor authentication wherever the Cyber Essentials requirements call for it, particularly for cloud services. Review privileged access regularly and make approval traceable.
- Remove leavers and unused guest accounts
- Review global, domain and local administrators
- Eliminate shared accounts unless there is a documented technical need
- Require strong, protected authentication
- Apply MFA to cloud services and privileged access as required
- Keep an organisation-controlled emergency-access account secure and monitored
6. Confirm malware protection
Use an approved malware-protection approach for every relevant device: anti-malware software, application allow-listing or application sandboxing, as permitted by the requirements. Confirm protection is active, updating and centrally visible where possible.
Control where software can be installed from and prevent users bypassing warnings casually. Test your alert and isolation process so the business knows who acts when a threat is detected.
7. Review backup and recovery
Backup is addressed in the Cyber Essentials requirements as important supporting guidance even though it is not one of the five control themes. Identify critical data, keep appropriate backup copies protected from ordinary user and administrator compromise, and test restoration.
Microsoft 365 retention and availability are not automatically a complete backup strategy. Decide what must be recoverable, for how long and after which scenarios, then keep evidence of a successful test.
8. Gather evidence before answering
Collect the inventory, network information, screenshots or exports, policy decisions and supplier confirmations behind each answer. Ask technical owners to validate statements rather than answering from memory. The application is a declaration about controls that are operating, not merely planned.
Run an internal gap review early enough to fix issues. Recheck the live official requirements and assessment questions because the scheme is updated periodically. Certification lasts 12 months, so note renewal dates and make the controls part of normal IT management.
Pre-submission checklist
- Scope is agreed and written clearly
- In-scope devices, software and cloud services are inventoried
- Unsupported technology has been removed or appropriately addressed
- Firewalls and exposed services have been reviewed
- Default settings and unnecessary services have been removed
- Critical or high-risk security updates follow the required timetable
- User, administrator, leaver and third-party access has been reviewed
- MFA is applied wherever required
- Malware protection is active and monitored
- Backups are protected and a restore has been tested
- Every assessment answer has an owner and supporting evidence
Need help getting assessment-ready?
Merr IT provides Cyber Essentials preparation and remediation support for Wiltshire businesses. We can help define scope, identify technical gaps and turn certification requirements into controls that remain useful throughout the year.