Skip to content

Cyber Essentials

Cyber Essentials requirements

What is in scope and what each of the five controls requires, summarised from the NCSC's Requirements for IT Infrastructure v3.3. The NCSC document is the authority; this page is a reading aid.

Reviewed October 2026. Applies to: Cyber Essentials requirements for IT infrastructure v3.3 (NCSC, April 2026), the Danzell question set.

How the requirements work

The requirements are one NCSC document, Cyber Essentials: Requirements for IT Infrastructure. Version 3.3 is dated April 2026 and applies to applications started on or after 27 April 2026; applications started earlier may continue on version 3.2. The question set you answer for certification, called Danzell, asks about the same requirements.

As the applicant, you are responsible for meeting every requirement within the scope you choose, and your Certification Body may ask for evidence. The NCSC sets the order of work: define the scope, review the five controls, then make sure every requirement is met.

ControlAimApplies to
FirewallsOnly secure and necessary network services can be reached from the internetBoundary firewalls, desktops, laptops, routers, servers, IaaS, PaaS, SaaS
Secure configurationDevices are set up to reduce vulnerabilities and run only the services their role needsServers, desktops, laptops, tablets, phones, thin clients, IaaS, PaaS, SaaS
Security update managementDevices and software are not open to known vulnerabilities that have fixesServers, desktops, laptops, tablets, phones, firewalls, routers, IaaS, PaaS, SaaS
User access controlAccounts go only to authorised people, with only the access their role needsServers, desktops, laptops, tablets, phones, IaaS, PaaS, SaaS
Malware protectionKnown malware and untrusted software cannot run, cause damage or reach dataServers, desktops, laptops, tablets, phones, IaaS, PaaS, SaaS

Some words carry set meanings. Software includes operating systems, off-the-shelf applications, extensions, interpreters, scripts, libraries, network software, and router and firewall firmware. A device is any host, piece of network equipment or end-user device, physical or virtual. Backups are not a requirement, although the NCSC highly recommends them.

Scope

Scope is the networks, hardware, software and cloud services the assessment covers. It can be the whole IT infrastructure the organisation uses for its business, which the NCSC says gives the best protection, or a well-defined, separately managed sub-set, segregated from the rest by a firewall or VLAN. Either way, you define the boundary by the business unit that manages it, the network boundary and the physical location, and you agree it with your Certification Body before the assessment starts.

Within the boundary, the requirements apply to every device and piece of software that can accept incoming connections from internet-connected devices, can make outbound connections over the internet, or controls the flow of data between those devices and the internet. Two rules are fixed: a scope without end-user devices is not acceptable, and cloud services that host your data or services cannot be excluded. If you leave anything out, you justify the exclusion to the assessor and explain how the excluded part is separated.

Bring your own device

Personally owned devices that access organisational data or services are in scope, alongside the organisation's own mobile and remote devices. A device used only for native voice calls, native text messages or a multi-factor authentication app is out of scope.

Home and remote working

Corporate and personally owned devices used for work at home or elsewhere are in scope. A router the organisation gives a home worker is in scope; any other home router is not, so the firewall control has to be met on the device itself, usually with its software firewall. If the worker connects through a corporate VPN, the internet boundary is the company's firewall or cloud firewall.

Wireless devices

Wireless access points and other wireless devices are in scope if they can communicate with other devices over the internet. They are out of scope if an attacker could reach them only from within signal range, or if they are part of an internet provider's router at a home or remote location.

Cloud services

For Cyber Essentials, a cloud service is an on-demand, scalable service on shared infrastructure, reached over the internet through an account (issued by you, or a business email address), that stores or processes your data. Every such service is in scope. You remain responsible for every control, but the provider may implement some of them, depending on the type of service.

Who typically implements each control, after Table 1 of the requirements. The real split depends on how each service is built.
ControlIaaSPaaSSaaS
FirewallsYou and the providerThe provider, sometimes you as wellThe provider
Secure configurationYou and the providerYou and the providerYou and the provider
Security update managementYou and the providerYou and the providerThe provider
User access controlYouYouYou
Malware protectionYou and the providerThe provider, sometimes you as wellThe provider

Where the provider implements a control for you, you need its commitment in the contract or in documents the contract references, such as a security or privacy statement. Providers often describe this as a shared responsibility model.

Third parties

Accounts your organisation owns are in scope even when a supplier, contractor or managed service provider uses them to manage or support your systems. If someone else administers your infrastructure, you must be able to confirm that the controls are met. Devices you own and lend to a third party are in scope.

Of devices you do not own, only the personal devices of employees, volunteers, trustees and university research assistants are in scope. Students' own devices, and devices belonging to managed service providers, contractors and customers, are out of scope, but you are still responsible for making sure devices that use your services and data are configured correctly.

Software development

Publicly available commercial web applications are in scope by default. Bespoke and custom components of web applications are out of scope; for those, the NCSC points to secure development and testing and the government's Software Security Code of Practice.

Scope

Ironfang can check

  • Hostnames under your domain in certificate transparency logs, which can reveal services missing from your asset list
  • Technologies your websites reveal, which point to hosting and cloud services to include
  • DNS records that point at resources that no longer exist

The organisation must establish

  • The boundary: business unit, network boundary, physical locations and legal entities
  • Lists of end-user devices, including personally owned ones, servers, network equipment and cloud services
  • Which controls each cloud provider implements, and where that is written down
  • Any exclusion, with its reason and how it is segregated

Firewalls

The aim is that only secure and necessary network services can be reached from the internet. Every device in scope must be protected by a correctly configured firewall, or a network device with firewall functions. That can be a boundary firewall in front of a network, or a software firewall on the device itself. Where you do not control the network a device connects to, the device needs its own software firewall. For cloud services, data flow policies do the same job.

For every firewall, the organisation must:

  • change the default administrator password to a strong, unique password, or switch off remote administration entirely
  • keep the administration interface off the internet, unless there is a clear, documented business need and the interface is protected by MFA, or by an IP allow list of a few trusted addresses combined with properly managed passwords
  • block unauthenticated inbound connections by default
  • have every inbound rule approved and documented by an authorised person, with the business need recorded
  • remove or disable rules that are no longer needed

Devices used on untrusted networks, such as public wifi, must have a software firewall on. The NCSC advises using the firewall built into most desktop and laptop operating systems rather than a separate product.

In Cyber Essentials Plus, the assessor scans every public IP address in scope and reviews each service that answers. The check reference explains how to close exposed remote desktop and database ports.

Firewalls

Ironfang can check

  • Which of 21 fixed ports (databases, remote desktop, SSH, SMB, Telnet, FTP, the Docker API and alternate web ports) accept a connection on a verified domain's hosts
  • Web services on ports other than 80 and 443, such as administration panels or development servers
  • Whether any of this changes between scheduled checks

The organisation must establish

  • Every boundary firewall, router and software firewall in scope, and how each is configured
  • Approval and a recorded business need for each inbound rule
  • Default passwords changed, and administration interfaces kept off the internet or protected
  • Software firewalls on for devices used outside your network
  • Coverage of every public IP address and port, not only the hosts your domain names point to
  • Exposed services checker Check your domain for databases, remote desktop and other services open to the internet, once it is verified.

Secure configuration

The aim is that computers and network devices are configured to reduce vulnerabilities and provide only the services their role needs. Default set-ups often include an administrator account with a known default password or no MFA, accounts nobody needs, and software or services nobody uses.

The organisation must manage its computers and network devices actively, and regularly:

  • remove or disable user accounts that are not needed, such as guest accounts and administrator accounts that will not be used
  • change default or guessable passwords
  • remove or disable software that is not needed, including applications, system utilities and network services
  • disable auto-run features that execute files without the user's authorisation
  • authenticate users before they reach organisational data or services
  • apply suitable device locking for users who are physically present

Device locking

Where using a device requires being physically present, such as signing in to a laptop or unlocking a phone, a biometric, password or PIN must be in place first, and it must be protected against guessing. Where the setting exists, either throttle attempts so the wait grows after each failure, allowing no more than 10 guesses in 5 minutes, or lock the device after no more than 10 failed attempts. Where the vendor offers no such setting, its default applies.

A password or PIN used only for device unlocking must be at least 6 characters long, enforced by a technical control. If the same credential also signs in to services, the full password rules under user access control apply.

Cloud services are included: for SaaS the provider runs the service, but you must still configure it securely.

Secure configuration

Ironfang can check

  • Network services that answer from the internet on a verified domain's hosts, such as Telnet, FTP or a database, which may be software nobody needs
  • Little else: accounts, auto-run and device locking are not visible from outside

The organisation must establish

  • Account lists for each device and service, with guest and unused accounts removed
  • Default passwords changed on every device and service
  • Unneeded software removed and auto-run disabled
  • Device locking settings: the credential, throttling or lockout, and minimum length
  • Secure settings on each cloud service

Security update management

The aim is that devices and software are not exposed to known vulnerabilities for which fixes exist. All software on in-scope devices must:

  • be licensed and supported: you have the legal right to use it, and a vendor provides regular vulnerability fixes and states the date they will stop
  • be removed when it stops being supported, or moved into a sub-set that blocks all traffic to and from the internet
  • have automatic updates switched on where possible
  • be updated within 14 days of release when the update fixes vulnerabilities the vendor calls critical or high risk, or with a CVSS v3 base score of 7 or more, or when the vendor gives no severity at all

If one update fixes several issues and any of them is critical or high risk, the whole update falls under the 14-day rule. The NCSC strongly recommends, but does not require, installing every update within 14 days.

The rule covers router and firewall firmware as well as operating systems and applications. Under the Danzell question set, missing the 14 days is an automatic fail: question A6.4 covers operating systems and router and firewall firmware, and A6.5 covers applications and their files and extensions.

In Cyber Essentials Plus, the assessor runs an authenticated vulnerability scan on sampled devices. A critical or high-risk vulnerability with a fix available for more than 14 days is a fail, and virtual patching is not accepted for unsupported operating systems.

Security update management

Ironfang can check

  • Web servers and frameworks that advertise a version past its end of life. The version is inferred from what the server says, so each match needs confirming
  • The technologies your sites reveal, as a starting point for the software list

The organisation must establish

  • A software list for every device and service, with each vendor's end-of-support date
  • Automatic updates on, and records showing critical and high-risk fixes installed within 14 days
  • Router and firewall firmware kept up to date
  • Unsupported software removed, or isolated in a sub-set with no internet traffic

User access control

The aim is that accounts go only to authorised people, and give access only to the applications, computers and networks each person needs. The organisation must control its accounts and their privileges, including accounts used by third parties such as IT support. It must:

  • have a process to create and approve user accounts
  • authenticate users with unique credentials before granting access to applications or devices
  • remove or disable accounts when they are no longer needed, such as when someone leaves or after a set period of inactivity
  • use MFA wherever it is available, and always for cloud services
  • use separate accounts for administration, and use them only for administration, never for email, web browsing or other everyday work
  • remove or disable special access privileges when they are no longer needed, such as when someone changes role

Multi-factor authentication

MFA must be on for every cloud service that offers it. IASME marks missing cloud MFA as an automatic fail, whether the option is free, included or paid. Beyond the cloud, the requirements say MFA should always protect administrator accounts and accounts reachable from the internet.

Where MFA includes a password, it must be at least 8 characters with no maximum length. The additional factor can be a managed device, an app on a trusted device, a physically separate token, or a known or trusted account. SMS is allowed but weaker; the NCSC suggests an alternative where one works.

Passwords

Where users sign in with a password, the requirements set out these measures:

  • Protection against guessing, by at least one of: MFA; throttling, with no more than 10 guesses in 5 minutes; or lockout after no more than 10 failed attempts.
  • A technical control on password quality, by one of: MFA; a minimum length of 12 characters; or a minimum of 8 characters with automatic blocking of common passwords from a deny list. None may set a maximum length.
  • Help for users to choose unique passwords: guidance on avoiding common and reused passwords, encouragement to use at least three random words, and usable secure storage such as a password manager.
  • No enforced regular password expiry and no complexity rules.
  • A process to change passwords promptly when an account is known or suspected to be compromised.

Passwordless sign-in

Version 3.3 puts more weight on passwordless authentication, such as passkeys, biometrics and security keys. FIDO2 authenticators count as passkeys and are treated as MFA.

In Cyber Essentials Plus, the assessor watches users sign in to each cloud service from an untrusted device or private browser session to confirm an MFA prompt, and checks that a standard account cannot run an administrative task without separate administrator credentials.

User access control

Ironfang can check

  • Sign-in services such as remote desktop and SSH that answer from the internet on a verified domain's hosts, where account controls matter most
  • Nothing about accounts, privileges or MFA settings: these are not visible from outside

The organisation must establish

  • The account creation, approval and removal process, with records
  • Separate administrator accounts, and who holds them
  • MFA on every cloud service, for users and administrators
  • Password, throttling and lockout settings
  • Third-party and support accounts held to the same controls

Malware protection

The aim is to stop known malware and untrusted software from running, causing damage or reaching data. Malware protection must be active on every device in scope, using at least one of two options. Protection built into modern operating systems counts; third-party products are an alternative. Either way, it must be active, kept up to date as the vendor instructs, and configured as below.

  • Anti-malware software, an option for Windows and macOS devices, including servers, desktops and laptops. It must update in line with vendor recommendations, stop malware running, stop malicious code executing, and block connections to malicious websites.
  • Application allow listing, an option for any device in scope. Only approved applications, restricted by code signing, may run. You approve each application before deploying it, keep the approved list current, and users cannot install applications that are unsigned or have an invalid signature.

In Cyber Essentials Plus, the assessor sends test files by email and has users download them in a browser, or checks the anti-malware software by hand; for allow listing, the assessor confirms that unsigned code will not run.

Malware protection

Ironfang can check

  • Nothing: malware protection runs on devices, out of sight of any external check

The organisation must establish

  • The method each device uses: anti-malware software or application allow listing
  • Update and blocking settings that stop malicious code and malicious websites
  • For allow listing, the approved application list and code-signing enforcement

Sources

Checked on the review date above. Standards and schemes change; the source is the authority.