The Cyber Essentials checklist - the five controls in plain English.
Cyber Essentials is built on five technical controls, and the official documentation manages to make all of them sound harder than they are. Here's each control in plain English: what it actually means, what the assessor checks, and the specific mistakes that fail first submissions. Work through this honestly and you'll know exactly where you stand before you spend a penny.
Before you start: scope decides everything
One thing before the controls, because getting it wrong invalidates everything after it: scope. Cyber Essentials applies to every device and service that touches your organisation's data or the internet on its behalf - company laptops, phones with work email on them, servers, cloud tenants like Microsoft 365 or Google Workspace, and yes, the director's home PC if it's used for work.
The most common scoping mistake we see is quietly ignoring BYOD. If staff read work email on personal phones, those phones are in scope. You don't need to control the whole device, but the parts touching company data need to meet the standard. Decide your scope first, write it down, and every checklist item below applies to everything inside it.
Control 1: Firewalls & boundary protection
Plain English: there should be a barrier between your devices and the open internet, and it shouldn't be running on factory settings.
Every network you control needs a properly configured boundary firewall - usually your router - and every laptop and desktop needs its own software firewall switched on. The default admin password on the router has to go. Any rule that lets the internet reach into your network needs a documented business reason, and remote management of the router from the internet should be off unless it's protected properly.
- Router/firewall admin password changed from the default
- Software firewall enabled on every laptop, desktop and server
- No inbound services open to the internet without a documented reason
- Remote router administration disabled, or protected by MFA/IP allow-list
- Home workers' routers considered where staff work remotely by default
What fails people: the router nobody has logged into since the ISP installed it. If you don't know the admin password, that's your first job - and if the answer turns out to be "admin", you've found why this control exists.
Control 2: Secure configuration
Plain English: computers and cloud services should only run what you actually use, and nothing should still be on a default password.
Out of the box, devices and services are configured for convenience, not security. This control is about stripping that back: remove software you don't use, disable accounts nobody owns, kill auto-run features, and make sure every account that exists has a reason to exist. It covers your cloud services too - your Microsoft 365 or Google Workspace tenant is as much "configuration" as any laptop.
- Unused software and services removed from devices
- Default and guest accounts disabled or renamed with strong passwords
- Auto-run/auto-play disabled on all devices
- Device lock enabled: PIN, password or biometric on every device
- Cloud tenant reviewed: legacy authentication off, sharing defaults sane
- Passwords at least 8 characters with technical controls against guessing (or 12+ without)
What fails people: legacy authentication left enabled in Microsoft 365. It bypasses MFA entirely, IASME knows it, and the question is on the form. Turn it off.
Control 3: User access control
Plain English: people should only have the access they need to do their job, admin rights should be rare and separate, and leavers should be gone the day they leave.
Two things matter most here. First, separate admin accounts: the account you read email with should never be the account that can install software or administer your tenant. Second, multi-factor authentication - on every cloud service account, and non-negotiably on every admin account. This is also where joiners-and-leavers discipline gets checked: a spreadsheet of who has access to what, reviewed when people join, change role or leave.
- MFA enabled on all cloud accounts - admin accounts first, no exceptions
- Admin accounts separate from day-to-day user accounts
- Unique accounts per person - no shared logins
- Documented process for creating and removing accounts
- Leavers' access removed promptly, with a record that it happened
- Admin access reviewed regularly - who has it, and do they still need it
What fails people: the director who insists on being a global admin from the same account they use for email, with MFA "coming soon". The assessor has seen the excuse before. It doesn't pass.
Want your score on all five controls in three minutes?
Our free readiness check asks 13 plain-English questions and shows you exactly where you stand - no email required to see the score.
Control 4: Malware protection
Plain English: every device needs something actively stopping malicious software, and it needs to keep itself up to date without a human remembering.
For Windows machines, the built-in Defender is genuinely acceptable when configured properly - you don't need to buy anything. Macs need anti-malware too, whatever the popular myth says. For phones and tablets, the standard is different: you rely on app-store-only installation and keeping the operating system current, ideally enforced through mobile device management rather than trust.
- Anti-malware active on every laptop, desktop and server
- Definitions updating automatically - and someone would notice if they stopped
- On-access scanning enabled, not just scheduled scans
- Mobile devices restricted to official app stores
- Users can't disable protection on their own machines
What fails people: the one machine everyone forgot - the warehouse PC, the meeting-room laptop, the server in the cupboard. The standard says every device in scope, and "we forgot about that one" is the most expensive sentence in a technical audit.
Control 5: Security update management
Plain English: high-risk security patches must be applied within 14 days, and nothing in scope can be running software the vendor no longer supports.
This is the control that fails more first submissions than any other, for one reason: end-of-life software. Windows 10 stopped receiving security updates in October 2025. If there's a Windows 10 machine in your scope in 2026, you will not pass - and the assessor will find it, because unsupported operating systems are the first thing the scan looks for. The same applies to old macOS versions, aged phone operating systems and that ancient line-of-business app the supplier abandoned.
- All operating systems in scope currently supported by their vendor
- No Windows 10, no abandoned macOS, no out-of-support phones
- Automatic updates on for operating systems and applications
- High and critical patches applied within 14 days of release
- Unsupported applications removed or formally isolated from scope
- Firmware on routers and firewalls kept current too
What fails people: honestly answering the asset-list question. Every machine gets listed with its operating system version, and the maths does the rest. Replace or retire end-of-life kit before you submit, not after the assessor bounces it.
Most UK SMBs already meet 60% of this standard without knowing it. The remaining 40% is almost always configuration, not spend.
Scored yourself honestly? Here's what the result means
Mostly ticks: you're closer than most. The gap between "nearly there" and "certified" is evidence: IASME wants your answers documented and defensible, and the question wording trips up confident people. A dry-run review before submission is worth far more than it costs.
Ticks with a few gaps: the classic profile. MFA partly rolled out, a couple of end-of-life machines, no separate admin accounts. This is a two-to-three-week remediation job for most SMBs - very fixable inside a 30-day certification window.
More gaps than ticks: don't panic, and don't buy anything yet. Almost everything above is configuration of what you already own. What you need is sequence - which gaps unblock submission fastest - and that's exactly what a structured 30-day engagement is for.
And if you're weighing up what certification actually costs, we've written an honest breakdown of what drives the price - no "from £X" games.
Know where you stand by this afternoon.
Run the free 3-minute readiness check, or book a 15-minute call and get a fixed-price quote for the whole job within 48 hours.