Skip to content

Checklist

Cyber Essentials checklist

Work through scope and the five controls before you apply. Each item follows the NCSC's Requirements for IT Infrastructure v3.3.

Reviewed October 2026. Applies to: Cyber Essentials requirements for IT infrastructure v3.3 (NCSC, April 2026), the Danzell question set.

How to use this checklist

This is a preparation aid, not the official assessment. The questions you answer for certification are the Danzell question set, which IASME publishes and you can download free. That download is for preparation too: answers count only when given on the assessment platform. Use this checklist to find gaps before you open the question set.

Each item is something to do or confirm, with a line on what counts as done. A free tool is linked only where it checks part of an item from outside. Most items can be confirmed only by looking at your own devices, accounts and settings.

Start with scope

Every answer depends on the scope, so settle it first, list what is inside it, and agree it with your Certification Body. The scope rules explain personally owned devices, home working, cloud services and third parties.

The checklist

0 of 53 done

Your ticks are kept in this browser only.

Scope

Decide what the assessment covers before you check any control.

  • Free tool: Subdomain finder

Firewalls

Only secure and necessary services can be reached from the internet.

  • Free tool: Exposed services checker

Secure configuration

Devices and services run only what their role needs, with no defaults left in place.

Security update management

Software in scope is supported, and serious vulnerabilities are fixed within 14 days.

  • Free tool: End-of-life software checker

User access control

Accounts go only to authorised people, with only the access they need.

Malware protection

Every device in scope has an active way to stop malicious code running.

What to do with the gaps

The unticked items are your gap list. Work on them in this order:

  1. The automatic fails: MFA on every cloud service that offers it, and critical and high-risk updates within 14 days for operating systems, firmware and applications. Either one alone fails the assessment.
  2. Unsupported software: replace it, remove it, or move it into a sub-set with no internet traffic. Virtual patching is not accepted for unsupported operating systems.
  3. The rest, control by control, recording what you changed and when, so the evidence is ready when you answer.

Some gaps are a scope decision rather than a fix. A network you cannot bring up to standard can be left out only as a separately managed, segregated sub-set, and you will need to justify it to the assessor. End-user devices and cloud services cannot be left out.

When the list is clear, gather the evidence and follow the route to certification. For practical help, the NCSC points small and medium-sized organisations to Cyber Advisors.

For the internet-facing items, the External Security Check rechecks a verified domain on a schedule and tells you when exposed services or advertised software change. It covers the edge only: it does not see devices, accounts or cloud settings, and it is not part of the assessment.

Sources

Checked on the review date above. Standards and schemes change; the source is the authority.