Cyber Essentials checklist
A practical, scannable checklist of the five Cyber Essentials controls UK businesses must meet before certification.
Built by SimpleCyber, an IASME-certified Cyber Essentials assessment body based in Wigan.
Firewalls
A firewall provides technical protection between your network devices and the internet. Your organisation will have physical, virtual or software firewalls at your internet boundaries.
- Every in-scope device sits behind a correctly configured firewall or network device with firewall functionality.
- Software firewalls are enabled on all computers, laptops and servers, even behind a boundary firewall.
- Default passwords are changed on all routers, boundary firewalls and host devices.
- Firewall admin access uses MFA, a 12-character minimum password, or an 8-character minimum with common-password blocking.
- There is a documented process to change firewall passwords when they are compromised.
- Firewall rules are reviewed at least every 12 months and unnecessary services or ports are removed.
- Unauthenticated inbound connections are blocked by default; any exposed services have a documented business case.
- Remote access to firewall configuration is protected by MFA or limited to trusted IP addresses.
Secure Configuration
Devices and cloud services are often insecure by default: standard admin passwords, unnecessary accounts, and unneeded pre-installed software all present risk.
- Unused software, services and accounts are removed or disabled on all devices and cloud services.
- Default passwords are changed for all user and administrator accounts on every device.
- External-facing services use MFA, 12-character passwords, or 8-character passwords with common-password blocking.
- Password-only external services are protected against brute-force attacks by throttling or account lockout.
- Auto-run features for downloaded or imported files are disabled or require user authorisation.
- Devices lock when unattended using a PIN or password of at least six characters, or biometric authentication.
Security Update Management
All software must remain in vendor support and receive security updates. Critical/high-risk fixes must be applied within 14 days - there are no exceptions to this rule.
- All operating systems, firmware and software are still supported by the vendor and licensed.
- High-risk and critical security updates for operating systems and firmware are installed within 14 days of release.
- High-risk and critical security updates for applications are installed within 14 days of release.
- Unsupported software is removed from in-scope devices, or the devices are moved out of scope.
User Access Control
Users should only have access to what their role needs, using unique credentials, with administrator access tightly controlled and MFA enforced on cloud services.
- New user accounts are only created after a documented approval process.
- Every user and administrator has unique credentials; no shared or permanently logged-in accounts.
- Accounts for staff who leave are disabled or deleted promptly.
- Staff only have access privileges needed for their current role; reviewed when roles change.
- A formal process governs who can hold an administrator account and why.
- Administrative tasks are performed with separate admin accounts, not day-to-day accounts.
- Administrator accounts are not used for browsing the web or email.
- Administrative access is tracked and reviewed regularly.
- MFA is enabled for all administrators and users of cloud services.
Malware Protection
Every device must be protected from malware, using anti-malware software and/or application allow listing.
- Every device is protected by anti-malware software, application allow listing, or both.
- Anti-malware software updates automatically and blocks malware when detected.
- Anti-malware web scanning warns users before visiting malicious sites.
- Application allow listing prevents users from installing unsigned or unapproved applications.
Planning a budget? See how much Cyber Essentials certification costs.
This checklist summarises the published Cyber Essentials controls. It is not an official IASME/NCSC assessment and completing it does not guarantee certification.