cyber-essentials-checklist

Cyber Essentials Checklist: Step-by-Step Guide

  • Cybersecurity
  • Cyber Essentials
  • Gabriel Few-Wiegratz
  • Published: 7th Jun 2026

Share this

Download the Checklist

This is the fastest route through certification: one document, every control, every submission step, laid out as a tick-list you can work through with your team. Print it, assign owners against each line, and use it to track your position before you open the questionnaire. Everything below is the same route in on-page form, so you can scan it, link out from it, and come back to the PDF when you need the working copy.

 Download your Cyber Essentials checklist.

Expert View

Matt Davies

Chief Product Officer, SureCloud

LinkedIn

 

 

What our experts say about first-time CE preparation

"Scope definition trips up more first-time applicants than any of the five controls. Organisations underestimate how much of their estate is genuinely in scope, particularly cloud services and home-working devices, and then face remediation they weren't expecting. Get scope agreed with your ASP before you open the questionnaire."

 
Before You Start: Scoping Your Certification

Scope is the first and most consequential decision in the Cyber Essentials process. Your certification only covers what sits inside the boundary you define, so an incomplete boundary means gaps that surface later as remediation, not as a scope discussion. This is where most delays start.

Two areas cause the most confusion: the network boundary (what counts as “your” network when staff work remotely or use personal devices) and cloud services (which SaaS and cloud platforms fall in scope, and how much of that scope depends on who controls the configuration).

Scope Checklist:

  1. Document all devices that can access internet-facing services.

  2. Identify all cloud services where your organisation controls configuration.

  3. Identify any devices or services explicitly excluded from scope, and document the rationale.

  4. Confirm the scope boundary covers your full set of core operational systems.

  5. Review IASME’s scope guidance for BYOD and home-working devices.

The 5 Control Areas: What You Need in Place

Cyber Essentials tests five control areas. Below is what to confirm for each, as a working tick-list. For the reasoning behind each requirement, see The 5 Cyber Essentials Controls Explained.

Firewalls and Internet Gateways - Confirm firewall rules block unnecessary inbound traffic by default. - Change default admin passwords on all firewalls and routers before deployment. - Disable any unused or unapproved services and ports. - Restrict firewall administration to authorised users only, ideally over a secure internal connection. - Review firewall rule sets and remove any that are no longer justified.

Secure Configuration - Remove or disable unnecessary user accounts, applications, and software on all in-scope devices. - Change all default passwords on hardware and software before use. - Disable auto-run features that could execute untrusted code. - Configure devices to require authentication before granting access. - Confirm device and account configuration is reviewed periodically, not just at setup.

User Access Control - Enforce MFA on every account that can reach an internet-facing service. - Issue user accounts only after an approval process, with unique logins per person. - Restrict administrative privileges to those who need them, and use separate admin accounts. - Remove or disable accounts promptly when someone leaves or changes role. - Review user access rights on a set schedule, not only when prompted.

Malware Protection - Confirm anti-malware software or application allowlisting is active on all in-scope devices. - Keep anti-malware signatures and definitions updated automatically. - Configure anti-malware tools to scan files on download or access. - Restrict installation of new software to an approved list where allowlisting is in use. - Confirm malware protection is applied consistently across all device types, including mobile.

Security Update (Patch) Management - Apply critical and high-severity patches within 14 days of release. - Remove any end-of-life or unsupported software from your scope entirely. - Maintain an inventory of software and firmware versions in scope, so you know what needs patching. - Confirm licensing is current for all software that requires it to receive updates. - Apply the same 14-day patch discipline to firmware, not just operating systems and applications.

Selecting an Assured Service Provider

Cyber Essentials assessments must be conducted through an IASME-approved Assured Service Provider (ASP). You cannot submit directly to IASME.

  1. Search the IASME-published ASP directory.
  2. Confirm the ASP is accredited for CE, and for CE+ if you’ll need it.
  3. Confirm the ASP’s pricing and what’s included in it.
  4. Confirm how the ASP manages your submission through the IASME portal.
Completing the Cyber Essentials Questionnaire

The self-assessment questionnaire is completed through the IASME portal, via your ASP. In outline, you’ll need to:

  1. Create or log in to your account on the IASME portal.
  2. Complete the scope declaration.
  3. Work through each of the five control sections.
  4. Review your answers for internal consistency before submitting.
  5. Respond promptly to any ASP clarification requests.

For the full walkthrough, including how the questionnaire is scored and what happens if an answer is flagged, see How to Complete the Cyber Essentials Questionnaire.

Annual Renewal

Cyber Essentials certification is valid for 12 months.

  1. Diarise renewal at least four weeks before expiry.
  2. Check the current NCSC/IASME scheme version for updates before resubmitting. See Cyber Essentials Requirements 2026 for what’s changed under Danzell.
  3. Conduct an internal review of your control state ahead of resubmission.
  4. Update scope documentation if your IT environment has changed since last certification.
CE+ Track: If You Need the Higher Tier

The process above is the first stage for CE+. If CE+ is required, it must be initiated within three months of standard CE certification. Miss that window and you have to restart the standard CE process before you can attempt CE+ again. CE+ adds an external technical audit on top of the self-assessment, so build in time for evidence gathering once you’ve certified for standard CE.

Key Facts
  1. All five controls must be met. There’s no partial pass.
  2. Patch management is the most common cause of failure.
  3. MFA is a requirement enforced through the IASME portal submission.
  4. CE+ must be initiated within three months of standard CE certification.
  5. Certification is valid for 12 months.
  6. Your choice of ASP affects cost, turnaround, and support through remediation.
Work Through It With the PDF

The tick-lists above cover what to check. The downloadable checklist turns that into a working document: assign an owner to each line, track status control by control, and use it as your internal sign-off record before you submit through your ASP.

Gracie AI Agents with Personas and Skills identify control gaps against all five CE requirements before your ASP sees a single response, cutting evidence collection time by 50-65% and removing the rework cycle from your certification process. Request a demo.Related reading: CE+ Guide | CE Questionnaire Guide
Recommended Cyber Resources
  • Cyber Essentials

Cyber Essentials Renewal: Annual Guide

  • Cybersecurity

Enterprise Cyber Risk Quantification: A Practical Guide for CISOs

FAQ’s

How long does it take to work through this checklist?

That depends on how much remediation you need, not on the checklist itself. Organisations with controls already in good shape can tick through it in a few hours; those with patching gaps, missing MFA, or undocumented scope should budget two to eight weeks to close those gaps before submitting. Once you’re ready to submit, our Cyber Essentials Requirements 2026 guide sets out the full two-to-four week certification timeline from that point. 

Do I need an Assured Service Provider?

Yes. You cannot submit an assessment directly to IASME. All submissions go through an accredited ASP. 

What’s the difference between Cyber Essentials and Cyber Essentials Plus?

 Standard CE is a self-assessment; CE+ adds an independent technical audit of the same five controls. See our full CE vs CE+ comparison for cost, process, and which one your organisation needs. 

How often do I need to recertify?

Certification is valid for 12 months. Renewal requires a fresh assessment against the current scheme version. 

What happens if I fail a control?

You’ll receive details of what needs remediation. Once addressed, you resubmit that element for review. A full restart isn’t usually required unless the certification lapses.