Cyber Essentials certification stands or falls on five technical controls. Every question in the self-assessment maps back to one of them, and so does every failure. If you can honestly evidence all five across everything in scope, you will pass; if you cannot, no amount of careful wording will get you through, because a board member signs the declaration and the assessor checks the answers.

This checklist explains each control in practical terms: what it requires, what evidence looks like, and where businesses actually fail. It reflects the current question set (Danzell, in force since 28 April 2026), which tightened several requirements, so if you last looked at Cyber Essentials more than a year ago, read the MFA and patching sections especially carefully. When you are ready to certify, our Cyber Essentials certification support takes it from checklist to certificate.

First: get your scope right

Before the five controls, the question that decides how hard this will be: what is in scope? The assessment covers every device that accesses organisational data or services: office desktops and laptops, servers, phones and tablets, home workers’ machines, and personal devices used for work under bring-your-own-device arrangements. It also covers your cloud services: Microsoft 365, Google Workspace, accounting platforms, CRMs and the rest.

The most common scoping mistakes are forgetting BYOD phones that collect company email, and missing cloud services nobody thinks of as “IT”. List everything first; surprises found during the questionnaire are what blow timelines.

Control 1 — Firewalls

The requirement: every internet connection is protected by a correctly configured firewall (or equivalent network device), and every device has its software firewall enabled.

Evidence checklist:

Where businesses fail: the office firewall is fine, but a forgotten port-forward from a long-dead CCTV system is still open, or the broadband router still answers to `admin`/`admin`. Attackers scan for exactly these.

Control 2 — Secure configuration

The requirement: devices and software are configured to reduce vulnerabilities: no default passwords, no unnecessary software or accounts, no auto-run, and device locking on every machine.

Evidence checklist:

Where businesses fail: machines set up over the years by different people, no two alike, several still carrying software nobody remembers installing. Uniformity is the practical fix, and it is why managed estates pass this control almost by default.

Control 3 — User access control

The requirement: accounts exist only for people who need them, admin rights are separated and minimised, and multi-factor authentication protects cloud services.

Evidence checklist:

Where businesses fail: MFA, overwhelmingly. One legacy shared mailbox without it, one director who “hates the phone prompts”, and the assessment fails. The second most common: everyone quietly being a local admin because it made an old application work in 2019. Our MFA rollout guide covers doing this without a staff revolt.

Control 4 — Malware protection

The requirement: every in-scope device has an active anti-malware mechanism: security software that updates itself and scans, an approved-application allow list, or (for mobile platforms) restricting installs to official stores.

Evidence checklist:

Where businesses fail: rarely on installation, often on coverage: the machine in the warehouse, the director’s home PC that touches company files, the server everyone forgot counts as a device. Coverage means every device, not most. For what monitored protection adds beyond the checkbox, see our managed antivirus and EDR service.

Control 5 — Security update management

The requirement: in-scope software is licensed, supported, and patched promptly: high-severity and critical fixes applied within 14 days of release. Under the current set, that 14-day window covers operating systems, applications, firmware and browser extensions, and includes vendor mitigations that arrive as configuration changes rather than patches.

Evidence checklist:

Where businesses fail: this control fails more certifications than any other. Machines that “do updates eventually”, an old server nobody dares patch, a line-of-business application pinned to an unsupported version. Fourteen days is a discipline, not an intention, and it is the control hardest to fake on the questionnaire.

The declaration

One more requirement that is not a technical control: the questionnaire is signed at board level, confirming the answers are accurate. That signature is why preparation beats optimism. The scheme includes one free resubmission within 48 hours of assessor feedback, but structural failures (missing MFA, unsupported systems) cannot be fixed in 48 hours, which is why gap analysis comes before submission, not after.

Quick self-check

Ten questions that predict most outcomes. If any answer is “no” or “not sure”, that is your remediation list:

  1. Has every router and firewall had its default password changed?
  2. Are any services exposed to the internet without MFA or IP restriction?
  3. Do all devices, including phones, lock and require authentication?
  4. Has every departed employee’s account been disabled?
  5. Does anyone use an admin account for email or browsing?
  6. Is MFA on for every user on every cloud service, no exceptions?
  7. Does every device, including home and BYOD machines, run active anti-malware?
  8. Is any in-scope operating system or application out of support?
  9. Do high-severity patches land within 14 days, provably?
  10. Could a board member sign all of the above with a straight face?

Frequently asked questions

Are the five controls the same for Cyber Essentials Plus?

Yes: identical controls. Plus adds an independent technical audit that tests them: vulnerability scans of sample devices and tests of email and browser defences, rather than taking the questionnaire’s word for it. See our Essentials vs Plus comparison.

What changed in the April 2026 question set?

The Danzell set (in force from 28 April 2026) hardened two areas in particular: MFA on cloud services became strictly enforced with auto-fail for gaps, and the 14-day remediation window was extended to cover configuration-change mitigations and browser extensions as well as conventional patches. Passwordless authentication was also formally recognised as compliant.

Do home workers’ personal computers really count?

If they access organisational data or services, yes: they are in scope and every control applies to them. This surprises more businesses than any other scoping rule, and it is checked.

How long does it take to get compliant with all five controls?

A managed, modern estate: days, mostly documentation. A typical unmanaged SME: two to six weeks of remediation, with MFA rollout and replacing unsupported machines the usual long poles.

Can we fail on something small?

Yes. Coverage rules are absolute: one machine without anti-malware, one cloud account without MFA, one unsupported OS in scope. The scheme’s logic is that attackers only need the one gap too.

From checklist to certificate

If the ten-question self-check produced a list, that list is the work, and it is exactly what we fix. Our certification support runs the gap analysis against all five controls, remediates the failures at a fixed price, and handles the questionnaire and assessor. Get in touch and tell us your deadline.