Cyber Essentials
Cyber Essentials readiness and evidence guide
Cyber Essentials readiness begins with an accurate scope and asset inventory. The organisation must then evidence secure configuration, controlled user and administrator access, malware protection, firewall boundaries and timely security updates across every in-scope device and cloud service.
Control checklist
What to verify first.
Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.
Confirm the certification scope, networks, cloud services, users and remote-working arrangements.
Maintain an inventory of in-scope laptops, mobiles, servers, network devices and cloud services.
Remove unsupported software and record how security updates are monitored and deployed.
Document firewall defaults, exposed services and the approval of any exceptions.
Apply secure configuration standards and remove unnecessary applications and accounts.
Limit administrator privileges and use separate accounts for administrative tasks.
Deploy appropriate malware protection and prevent untrusted application execution.
Collect evidence before assessment and assign every gap to an owner and target date.
Decision flow
Move from uncertainty to evidence.
The sequence keeps discovery, control changes and proof connected.
- 01
Scope
Define the organisation, networks, people, devices and cloud services included.
- 02
Assess
Compare actual control evidence with the current question set and requirements.
- 03
Remediate
Fix exposed, unsupported or weakly controlled assets before submission.
- 04
Maintain
Keep inventory, ownership and evidence current after certification.
Assessment template
Record control status and evidence.
Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.
Related service
Governance & Compliance
Translate Cyber Essentials requirements into owned controls, clear evidence and a practical remediation plan.
Official sources
Continue with primary guidance.
Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.
Related analysis
Apply the guide to current risks.
July 2026 threat landscape: massive Patch Tuesday and supply chain disruption
Microsoft releases 570+ patches, CISA warns of Langflow vulnerabilities, and Coca-Cola suffers ransomware disruption. Speed of containment is paramount.
Read insight ↗
Healthcare cyber incidents: operational lessons from July 2026
Recent healthcare incidents show how cyber extortion can disrupt medical operations. These are the containment and resilience lessons for care providers.
Read insight ↗