This is for you if

  • You're bidding for a government, NHS or supply-chain contract that requires certification
  • Your cyber insurance renewal now asks for it, or your premium jumps without it
  • You think your controls are solid but haven't tested them against the actual assessment criteria

A failed submission doesn't just cost the re-assessment fee. It can cost the contract, the renewal deadline, or weeks chasing gaps you didn't know existed. Most of that is avoidable with an honest look at where you stand first.

Cyber Essentials is the UK government-backed scheme that certifies a business has basic technical controls in place against the most common internet-based attacks. This checklist mirrors the five control themes assessors check against, so you can run an honest self-assessment and see exactly where the gaps are before you submit an application.

Work through each section with whoever manages your IT, whether that's an internal team or an outsourced provider. If you can't confidently tick a box, that's a gap to close before you apply. Systech holds Cyber Essentials and helps clients prepare; it is not a certification body.

1. Firewalls

  • Boundary firewall enabled and configured on every internet connection
  • Default admin passwords changed on all firewalls and routers
  • Unnecessary open ports and services closed at the boundary
  • Firewall rules reviewed, documented and justified by business need
  • Personal or device-level firewalls enabled on all laptops and desktops
  • Remote administration of firewalls restricted and protected by MFA

2. Secure configuration

  • Default passwords changed on all devices, software and services
  • Unnecessary user accounts removed or disabled
  • Unnecessary software, apps and services uninstalled from devices
  • Auto-run for removable media (USB drives etc.) disabled
  • Device lock screens configured to activate after a period of inactivity
  • Unused or legacy accounts on cloud services identified and removed

3. Security update management

  • All operating systems and software patched within 14 days of a security update being released
  • Automatic updates enabled wherever available
  • All software in use is licensed and still supported by its vendor
  • Unsupported or end-of-life software identified, with a replacement date scheduled
  • An up-to-date inventory of all software and firmware in use is maintained
  • Mobile devices included in the same patching regime as desktops and servers
Security updates: 14 days from releaseA four-week timeline. A security update is released on day 0; high-risk and critical updates must be applied by day 14. An authenticated scan at a Plus audit finds a device that is three months behind regardless of what the patching policy says on paper.ReleaseDay 7Day 14Day 21Day 28Security update releasedDay 14: high-risk and critical updates applied,on every operating system and application inscopeAutomatic updates wherever available, and third-party applications, browsers, PDF readers andline-of-business software in the same regime as Windows. An authenticated scan finds a device three monthsbehind, whatever the policy says on paper.
High-risk and critical security updates applied within 14 days of release, on every operating system and application in scope. Unsupported software in scope is a hard fail rather than an observation.

4. User access control

  • Every individual has their own unique user account; no shared logins
  • Administrator rights limited to those who genuinely need them to do their job
  • A formal process exists for approving and provisioning new user accounts
  • Leavers' access is revoked promptly as part of an offboarding process
  • Strong password policy in place, or MFA enabled wherever it's available
  • Admin accounts are separate from everyday user accounts, and not used for email or browsing

5. Malware protection

  • Anti-malware software installed and enabled on all devices
  • Anti-malware signatures and definitions kept up to date automatically
  • Application allow-listing or sandboxing considered for higher-risk devices
  • Users prevented from installing unauthorised software
  • Malware scanning applied to files from removable media and email attachments
  • Web filtering or browser protections in place against known malicious sites
Cyber Essentials and Cyber Essentials Plus compared on how the five controls are proved
Cyber EssentialsCyber Essentials Plus
Assessment methodSelf-assessment questionnaire: you answer for your own estate and a director signs it offSelf-assessment plus a hands-on technical audit by an assessor from a certification body
Who verifies the answersThe certification body reviews the submission. No external party logs into your systemsAn independent assessor tests real devices
Technical testingNoneAuthenticated vulnerability scans of sampled devices, malware protection tested, email and web filtering checked, MFA tested from an untrusted device for user and administrator accounts
Device samplingNot applicableThe assessor chooses the sample, so a handful of unmanaged machines cannot hide behind the well-managed ones
SequencingCan be held on its ownNeeds a valid Cyber Essentials certificate awarded within the previous three months
The controlsThe same five control themesThe same five control themes; the difference is entirely in how they are proved
Cyber Essentials and Cyber Essentials Plus prove the same five controls differently: a self-assessment questionnaire verified by a certification body, or that plus a hands-on technical audit by an assessor. Plus must follow a Cyber Essentials certificate awarded within the previous three months.

If you need Plus

Plus must follow Cyber Essentials within three monthsA six-month timeline. The Cyber Essentials certificate is awarded at month 0; the Plus audit must take place within the following three months, while the estate still matches the submission.CertificateMonth 1Month 2Month 3Month 4Month 5Month 6Cyber Essentials certificate awardedThree months: the window for the Plusaudit closesPlan both stages inside the window, so the audit lands while the estate still matches the submission. Abusiness that expects to need Plus should not treat the base certificate as a separate, earlier project.
Plus must follow a Cyber Essentials certificate awarded within the previous three months. Plan both stages inside the window, so the audit lands while the estate still matches the submission.

Where this leaves you

Ticking every box above doesn't guarantee certification on its own, an assessor will still verify the detail, but it puts a business in a strong position to apply with confidence rather than uncertainty. If any of these controls are missing, patchy, or you're simply not sure how your current setup measures up, Systech can help you close the gaps and prepare for certification, end to end: see our Cyber Essentials certification support for how that works.

  • Every box ticked, honestly

    Apply with confidence rather than uncertainty. Ticking every box does not guarantee certification on its own: an assessor will still verify the detail.

  • Unsupported or end-of-life software still in scope

    A hard fail rather than an observation. Replace it, move the application forward onto a supported platform, or ask whether the machines can be segregated out of scope.

  • Not sure whether the basic certificate is enough

    Read the contract wording. Where it specifies Cyber Essentials, base-level certification satisfies it; Plus adds a hands-on technical audit and must follow a Cyber Essentials certificate awarded within the previous three months.

  • Controls missing, patchy, or you are not sure how you measure up

    Request a call. Systech holds Cyber Essentials and helps clients prepare, end to end: we close the gaps and support you through the application. The certification body assesses and issues the certificate.

Basic or Plus?

Not sure whether the basic certificate is enough, or whether an assessor needs to test your controls hands-on? Cyber Essentials vs Cyber Essentials Plus sets out the difference, the cost gap and who each level is for.