— Cyber Essentials Checklist 2025

CYBER ESSENTIALS
CHECKLIST
2025

A complete Cyber Essentials checklist covering all five controls, their requirements, and the most common failure points. Use this to assess your readiness before submitting for certification.

— The Five Controls

Complete Cyber Essentials
requirements checklist

Each control must be fully met for certification. Tick off each requirement against your current environment. Common failure points are highlighted for each control.

01

Firewalls

Protect every device with a properly configured firewall.

Requirements
  • A boundary firewall is in place and configured to block unauthorised inbound connections
  • All devices (laptops, desktops, mobile) have a host-based firewall enabled
  • Firewall rules are documented and reviewed regularly
  • Default firewall passwords have been changed
  • Only necessary ports and services are open
  • Remote desktop and admin services are not exposed to the internet without VPN/MFA
Common Failure Points
  • Default passwords not changed
  • RDP (port 3389) open to the internet
  • No host-based firewall on mobile devices
02

Secure Configuration

Remove unnecessary software and disable default settings.

Requirements
  • All unnecessary user accounts (including default accounts) have been removed or disabled
  • Default passwords have been changed on all devices and software
  • Auto-run and auto-play features are disabled
  • Unnecessary software and services have been removed
  • Devices are configured to lock after a period of inactivity
  • Full-disk encryption is enabled on laptops and mobile devices
Common Failure Points
  • Default admin accounts not disabled
  • Auto-run enabled on Windows devices
  • Unnecessary software (e.g., Java, Flash) still installed
03

Access Control

Only authorised users can access systems and data.

Requirements
  • User accounts are created individually — no shared accounts
  • Standard user accounts are used for day-to-day work (not admin accounts)
  • Admin/privileged accounts are separate and used only when needed
  • Multi-factor authentication (MFA) is enabled for all cloud services
  • MFA is enabled for remote access (VPN, RDP, etc.)
  • Unused accounts are disabled or removed promptly
  • Strong password policies are enforced (min 12 characters, no common passwords)
Common Failure Points
  • MFA not enabled on Microsoft 365
  • Shared admin accounts in use
  • Former employees' accounts not disabled
04

Malware Protection

Protect all devices against viruses and malicious software.

Requirements
  • Anti-malware software is installed on all devices
  • Anti-malware is configured to update automatically
  • Anti-malware performs regular scans
  • Web browsing is restricted to prevent access to known malicious sites
  • Users cannot disable anti-malware protection
  • Email filtering is in place to block malicious attachments and phishing
Common Failure Points
  • Anti-malware not installed on all in-scope devices
  • Definitions out of date
  • Users able to disable protection
05

Patch Management

Keep all software and operating systems up to date.

Requirements
  • Operating systems are supported and receive security updates
  • Security patches are applied within 14 days of release
  • Applications are up to date and supported by the vendor
  • Unsupported software (e.g. Windows 7, Office 2010) is not in use
  • Auto-update is enabled where available
  • A process exists to identify and patch vulnerabilities promptly
Common Failure Points
  • Outdated operating systems (Windows 7/8/Server 2012)
  • Patches applied inconsistently or slowly
  • Unsupported third-party software still in use
— FAQ

Cyber Essentials requirements
— common questions

Q.What are the five Cyber Essentials controls?

The five Cyber Essentials controls are: (1) Firewalls — protecting every device with a properly configured boundary and host-based firewall; (2) Secure Configuration — removing unnecessary software and changing default settings; (3) Access Control — ensuring only authorised users can access systems, with MFA on cloud services; (4) Malware Protection — anti-malware on all in-scope devices; and (5) Patch Management — keeping all software and operating systems up to date with security patches within 14 days.

Q.What is the Cyber Essentials requirements checklist for 2026?

The Cyber Essentials requirements checklist for 2026 includes: (1) Firewalls — boundary and host-based firewalls configured to block unauthorised traffic; (2) Secure Configuration — default passwords changed, unnecessary software removed, auto-run disabled; (3) Access Control — individual user accounts, MFA on all cloud services, admin accounts separate; (4) Malware Protection — anti-malware installed and updated on all devices; (5) Patch Management — all software patched within 14 days, no end-of-life systems (Windows 10 is now EOL).

Q.What are the Cyber Essentials Plus technical requirements?

Cyber Essentials Plus technical requirements include everything in Basic, plus: (1) External vulnerability scan of all public IPs — no critical vulnerabilities (CVSSv3 ≥7.0); (2) Credentialed patch audit of sampled devices — no patches older than 14 days; (3) Malware protection testing — EICAR test files must be blocked via email and browser; (4) MFA enforcement verification — live testing on all cloud services; (5) Account separation testing — verified on sampled devices; (6) Email client protection — must block .exe, .bat, .msi attachments; (7) Web browser protection — must block malicious downloads.

Q.How do I prepare for Cyber Essentials Plus assessment?

To prepare for Cyber Essentials Plus assessment: (1) Ensure you have valid CE Basic certificate; (2) Enable MFA on all cloud services for all users (most common failure point); (3) Patch all devices within 14 days — remove any Windows 10/EOL software; (4) Remove local admin rights from standard users; (5) Configure email filtering to block executables; (6) Run internal vulnerability scans; (7) Document all policies (AUP, Patch Policy, Access Control). Coreitech provides full preparation support including pre-assessment testing to identify gaps before the official assessor arrives.

Q.What is not allowed in Cyber Essentials assessment?

Not allowed in Cyber Essentials assessment: (1) End-of-life operating systems — Windows 7, 8, 8.1, Server 2008/2012, and now Windows 10 (EOL Oct 2025) are automatic failures; (2) Unsupported software — any application no longer receiving security updates; (3) Shared admin accounts — all users must have individual accounts; (4) Missing MFA on cloud services — automatic failure if any user can access without MFA; (5) Unpatched critical vulnerabilities — CVSSv3 ≥7.0 with patch available 14+ days; (6) Users running as local administrators for day-to-day work.

Q.How long does Cyber Essentials Plus take to complete?

Cyber Essentials Plus typically takes 4-10 weeks to complete. If you already have CE Basic and good security controls, timeline is 4-6 weeks. Organisations with significant gaps (missing MFA, unpatched systems, EOL software) may need 8-10 weeks for remediation before assessment. Coreitech's pre-assessment preparation reduces delays by identifying and fixing gaps early. The official IASME assessment itself takes 1-3 days depending on organisation size.

Q.What does the Cyber Essentials assessment actually check?

For Cyber Essentials Basic, you complete a self-assessment questionnaire (SAQ) covering all five controls. The certifying body reviews your answers and may ask follow-up questions. For Cyber Essentials Plus, an independent assessor conducts hands-on technical testing — vulnerability scanning, credential testing, and verification that your answers to the SAQ are accurate. The assessor tests all in-scope devices, your network boundary, and your cloud services.

Q.What counts as "in scope" for Cyber Essentials?

Everything that connects to the internet and can access your organisation's data is in scope. This includes laptops, desktops, servers, smartphones, tablets, and cloud services (including Microsoft 365, Google Workspace, and any other SaaS platforms). Home working devices used for business are also in scope. You can reduce your scope by segmenting your network, but all internet-connected user devices must be included.

Q.Is MFA required for Cyber Essentials?

Yes. The updated Cyber Essentials requirements mandate multi-factor authentication (MFA) for all cloud services — including Microsoft 365, Google Workspace, and any other internet-accessible services. MFA must also be enabled for all administrator accounts and remote access (VPN, RDP). This is one of the most common areas where businesses fail or need remediation before certification.

Q.What operating systems are not allowed in a Cyber Essentials assessment?

Any operating system that is no longer supported by the vendor is not permitted in scope for Cyber Essentials. This means Windows 7, Windows 8/8.1, Windows Server 2008/2012 (without extended support), and macOS versions that no longer receive security updates. If you have unsupported operating systems in use, they must either be upgraded or removed from scope before certification.

Q.How do I know if I'll pass Cyber Essentials?

The best way to know is to conduct a gap assessment before submitting. Coreitech offers a free Cyber Essentials readiness review — we assess your current controls against all five requirements and identify exactly where you need to make changes. This prevents failed assessments and delays. Common failure points are: MFA not enabled on cloud services, unsupported operating systems, missing anti-malware on some devices, and default passwords not changed.

— Ready to Certify?

Ready to get Cyber Essentials certified?

Coreitech will assess your controls against this checklist, remediate any gaps, and get you certified — with a high first-time pass rate. Free readiness review available.