← Insights and resources

Cyber Essentials

Cyber Essentials readiness and evidence guide

Cyber Essentials readiness begins with an accurate scope and asset inventory. The organisation must then evidence secure configuration, controlled user and administrator access, malware protection, firewall boundaries and timely security updates across every in-scope device and cloud service.

Practical assessment guideReviewed UK organisations

Control checklist

What to verify first.

Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.

  1. Confirm the certification scope, networks, cloud services, users and remote-working arrangements.

  2. Maintain an inventory of in-scope laptops, mobiles, servers, network devices and cloud services.

  3. Remove unsupported software and record how security updates are monitored and deployed.

  4. Document firewall defaults, exposed services and the approval of any exceptions.

  5. Apply secure configuration standards and remove unnecessary applications and accounts.

  6. Limit administrator privileges and use separate accounts for administrative tasks.

  7. Deploy appropriate malware protection and prevent untrusted application execution.

  8. Collect evidence before assessment and assign every gap to an owner and target date.

Decision flow

Move from uncertainty to evidence.

The sequence keeps discovery, control changes and proof connected.

  1. 01

    Scope

    Define the organisation, networks, people, devices and cloud services included.

  2. 02

    Assess

    Compare actual control evidence with the current question set and requirements.

  3. 03

    Remediate

    Fix exposed, unsupported or weakly controlled assets before submission.

  4. 04

    Maintain

    Keep inventory, ownership and evidence current after certification.

Assessment template

Record control status and evidence.

Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.

Control areaEvidence to locateStatusOwner / action
Scope and inventory Boundary statement and current asset export Gap Partial Evidenced
Firewalls Configuration standard and approved inbound services Gap Partial Evidenced
Secure configuration Build baseline and sample compliance result Gap Partial Evidenced
Access control User, administrator and leaver review Gap Partial Evidenced
Updates and malware Patch status, support state and protection policy Gap Partial Evidenced

Related service

Governance & Compliance

Translate Cyber Essentials requirements into owned controls, clear evidence and a practical remediation plan.

Explore Governance & ComplianceDiscuss this assessment

Official sources

Continue with primary guidance.

Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.

Related analysis

Apply the guide to current risks.

Start with a conversation

Turn the assessment into an owned plan.

Share the scope, evidence and highest-priority gap. We’ll help define a proportionate next step for your environment.

Talk to an expert