Cyber Essentials readiness checklist

Cyber Essentials asks you to have five basic controls in place. None of them are exotic, and most small businesses are already part of the way there without realising. Work through the questions below to see where you stand before you pay for an assessment.

This is a preparation aid, not the official Cyber Essentials self-assessment. Working through it does not certify your business and does not guarantee you will pass. Certification is awarded by a certification body licensed by IASME, who run the scheme on behalf of the NCSC.

Before you start: Know what you are certifying

Assessments come unstuck on scope more than anything else. Work out what is included before you answer a single technical question.

Control 1: Firewalls

Something has to sit between your devices and the internet, deciding what is allowed through.

Control 2: Secure configuration

Devices and software arrive set up for convenience rather than safety. This control is about tightening them before use.

Control 3: Security update management

Most successful attacks use a flaw that was fixed months ago on machines that never took the fix.

Control 4: User access control

People should have the access their job needs, and no more. Administrator rights are the ones that matter most.

Control 5: Malware protection

Something needs to stop malicious software running, whether that is anti-malware or only permitting approved applications.

Backups are not part of Cyber Essentials, which surprises people. They are still the thing that decides how bad a ransomware morning gets, so keep a copy of your data somewhere separate and test that it restores.

Download the printable checklist (PDF)