Guide · Readiness check

Cyber Essentials checklist for SMEs

Use this Cyber Essentials checklist as a readiness check before you apply. It walks through scope and all five technical controls — firewalls, secure configuration, user access control, malware protection and security update management — with the specific evidence an assessor looks for and the gaps that most often cause SMEs to fail.

Step 1 — Get your scope right

Scope is where a Cyber Essentials application most often unravels. Certification covers everything your business uses to do its work, not just the kit in the office. Confirm each of the following before you look at a single control.

  • Every laptop, desktop, tablet, phone and server used for business work is listed — including personally owned devices used for email.
  • All cloud services holding company data are listed, including Microsoft 365, accounting, CRM and file sharing.
  • Home and remote working setups are accounted for, not just the office.
  • The legal entity name and headcount used on the application match your Companies House record.
  • Any part of the business you plan to exclude is genuinely separated by a firewall or a separate network — partial scopes are rarely worth the complexity for an SME.

Step 2 — Work through the five technical controls

Each control below lists what you must be able to evidence across everything in scope. If you cannot tick an item today, that is a gap to close before you submit — not something to describe optimistically on the questionnaire.

Control 1

Firewalls

Every device that connects to the internet must sit behind a correctly configured firewall — including laptops used at home, in coffee shops and on client sites.

  • A boundary firewall or internet router protects every office network, and its default administrative password has been changed.
  • The firewall administration interface is not reachable from the internet, or is protected by multi-factor authentication and an IP allow-list.
  • Software firewalls are enabled on all laptops, desktops and servers, including devices used outside the office.
  • Every inbound firewall rule is documented with a business reason, and rules that are no longer needed have been removed.
  • Unauthenticated inbound connections are blocked by default.

Most common failure: home and remote laptops relying on an unmanaged domestic router with the software firewall switched off.

Control 2

Secure configuration

Devices and cloud services must ship into use with only what the business needs enabled — nothing left at vendor defaults.

  • Default passwords on devices, routers, printers and software have been changed to unique, strong passwords.
  • Unused user accounts, applications and services have been removed or disabled on every device.
  • Auto-run and auto-play are disabled so removable media cannot execute code automatically.
  • Devices lock after a period of inactivity and require a password, PIN or biometric to unlock.
  • A documented build or enrolment standard exists so new devices are configured the same way every time.

Most common failure: an inherited server or NAS still running a vendor default account nobody has audited.

Control 3

User access control

Staff should have the access their role requires and no more, and administrative accounts must be tightly controlled.

  • Every user has their own named account — no shared logins.
  • A documented process governs how accounts are created, changed and removed when someone leaves.
  • Administrative accounts are separate from day-to-day accounts and are not used for email or web browsing.
  • Multi-factor authentication is enabled on all cloud services, including Microsoft 365 and Google Workspace, and on every administrator account.
  • Passwords meet the scheme's requirements (a minimum length with either MFA, throttling or a deny-list of common passwords).
  • The list of administrators has been reviewed within the last 12 months.

Most common failure: MFA enabled for staff but skipped on a global admin or a legacy service account.

Control 4

Malware protection

Each in-scope device needs one of the scheme's accepted approaches to stopping malicious code.

  • Anti-malware software is installed and active on all Windows and macOS devices, with signatures updating automatically.
  • Malware protection is centrally monitored so alerts are seen and acted on, not left on the device.
  • Web filtering or browser protection blocks known malicious sites.
  • Mobile devices only install applications from approved stores (App Store, Google Play or a managed enterprise catalogue).
  • Where application allow-listing is used instead of anti-malware, the approved application list is documented and maintained.

Most common failure: anti-malware installed but nobody receiving or reviewing its alerts.

Control 5

Security update management

Unpatched software is the single most exploited route into an SME network, and the scheme sets a hard deadline.

  • All operating systems, browsers, applications and firmware are licensed and still supported by their vendor.
  • Automatic updates are enabled wherever the vendor supports them.
  • Critical and high-severity security updates are installed within 14 days of release.
  • Software that is out of support has been removed, upgraded or fully separated from the rest of the network.
  • An inventory of devices and software exists so nothing is silently missed at patching time.

Most common failure: an end-of-life Windows machine kept alive for one line-of-business application.

Step 3 — Close the gaps, then submit

Sort the items you could not tick into quick wins and real projects. Enabling multi-factor authentication, turning on software firewalls, removing unused admin accounts and changing default passwords are typically same-week fixes. Retiring unsupported software and introducing a reliable 14-day patching routine take longer and should start first. When every control holds across your full scope, complete the self-assessment questionnaire and submit it to an accredited certifying body.

If you want a second opinion before you apply, our free cyber security review takes 30 minutes and tells you plainly which of these items would fail today and what it would take to fix them — no obligation. As an IASME certified Cyber Essentials assessor we can also run the whole process for you through our Cyber Essentials certification support service.

New to the scheme? Start with what Cyber Essentials is and who needs it. Certification is a baseline rather than a finish line — once certified, most SMEs add managed EDR and MDR and Cyber Shield awareness training to cover the human and detection gaps the five controls do not address.

FAQ

Frequently asked questions

What is on the Cyber Essentials checklist?

+

The Cyber Essentials checklist covers five technical controls: firewalls, secure configuration, user access control, malware protection and security update management. For each control you must be able to show it applies to every in-scope device, network and cloud service — including laptops used at home. Before working through the controls you also need an accurate scope: a list of every device, user and cloud service used for business work. The self-assessment questionnaire asks direct, factual questions against each control, so the practical checklist is really an evidence-gathering exercise: confirm the control is in place, confirm it covers everything in scope, and be ready to describe how.

How do I prepare for Cyber Essentials certification?

+

Start by defining scope — list every device, user and cloud service used for business work, including remote and personally owned devices used for email. Then run a gap analysis against the five controls, recording where each one is already met and where it is not. Fix the gaps in order of effort: enabling multi-factor authentication, removing unused admin accounts, turning on software firewalls and retiring unsupported software usually account for the bulk of the work. Once the gaps are closed, complete the self-assessment questionnaire honestly and submit it to an accredited certifying body. Most SMEs need between two and eight weeks.

What are the most common reasons SMEs fail Cyber Essentials?

+

The most frequent failures are unsupported software still in use (an old Windows machine or an end-of-life server), missing multi-factor authentication on cloud administrator accounts, security updates not applied within the required 14 days, shared or unnamed user accounts, and default passwords left in place on routers, firewalls and network storage. A fifth common failure is scope: an application that describes only the office network while staff work from unmanaged home devices. None of these are difficult to fix, but they are difficult to fix quickly, which is why a gap analysis before you apply saves both time and a resubmission.

How long does it take to work through the Cyber Essentials checklist?

+

A well-run SME with modern devices, Microsoft 365 and consistent patching can work through the checklist in a few days and certify within two to three weeks. A business with legacy hardware, no central device management or inconsistent patching should plan for six to eight weeks, because remediation — not the questionnaire — is where the time goes. Retiring unsupported software and rolling out multi-factor authentication across everyone are usually the two longest tasks. The assessment itself is typically reviewed by the certifying body within a few working days of submission.

Do I need to buy new software to pass Cyber Essentials?

+

Usually not. Most UK SMEs already own everything they need: Windows and macOS include built-in firewalls and anti-malware, and Microsoft 365 and Google Workspace both include multi-factor authentication at no extra cost. The spend, where there is any, tends to go on replacing devices that can no longer receive security updates, or on a management tool that lets you prove patching and configuration across a fleet rather than device by device. Buy after the gap analysis, not before it — otherwise you risk paying for tooling that addresses a control you already meet.

Does this checklist cover Cyber Essentials Plus as well?

+

The same five controls apply to both levels, so this checklist is the right starting point for either. The difference is verification: Cyber Essentials is a self-assessment reviewed by a certifying body, while Cyber Essentials Plus adds an independent technical audit with vulnerability scans and hands-on checks on a sample of your devices. Anything that is described inaccurately on a self-assessment will be found during a Plus audit, so if Plus is your goal, treat every item on this checklist as something an assessor will test rather than something you can simply assert.

Can I do Cyber Essentials myself or do I need help?

+

A confident SME with in-house IT can self-certify — the scheme was deliberately designed to be achievable without a security team. Help is worth it when you have mixed or unmanaged devices, no clear picture of your patching status, staff working from personal equipment, or a contract deadline that makes a failed submission expensive. As an IASME certified Cyber Essentials assessor, we run the gap analysis, tell you plainly what would fail today, handle remediation and submit the assessment. Either way, do the gap analysis before you apply.

Get a free Cyber Essentials readiness review

Reference pages on the certification and its controls

Short, factual definitions of the terms used in this checklist, each with its own FAQ.

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way