Cyber Essentials focuses on five control areas: firewalls and internet gateways, secure configuration, user access control, malware protection and security update management. Prepare by defining the current scope, checking real settings and evidence, resolving gaps and using the current official scheme guidance for the assessment and certification process.

Define what is in scope before answering questions

Start with a current picture of the organisation, the people who work for it, the devices they use and the services that process or provide access to business information. Include office and home-working arrangements, cloud services, internet-facing systems and equipment managed by third parties where it belongs within the proposed scope. An unclear boundary makes later answers harder to support because nobody can tell whether a device, account or service should be included.

Create an inventory that a business owner and technical team can both understand. It should identify the purpose of important systems, operating system and software support status, responsible owner, administrator route and any known exceptions. Treat uncertainty as an action to resolve. The assessment is more dependable when it is based on visible configuration and ownership rather than general confidence that the organisation ‘usually’ follows a particular practice.

  • Organisation, users, devices, networks and cloud services in scope.
  • Home working, mobile access and third-party-managed dependencies.
  • Internet-facing systems and the people responsible for them.
  • Known exceptions, unsupported software and missing inventory details.

Understand the five Cyber Essentials control areas

The scheme’s control areas provide a practical structure for reducing common technical risks. Firewalls and internet gateways concern the boundary between networks and the internet. Secure configuration concerns the way devices and services are set up. User access control covers accounts and privileges. Malware protection addresses appropriate protection against malicious software. Security update management concerns keeping supported systems and software up to date.

Use the control names as prompts for evidence, not as a reason to make unsupported statements. For each area, identify the systems concerned, the relevant settings, the person responsible and the records that show the setting is maintained. The NCSC overview and IASME’s current Cyber Essentials information are the appropriate starting points for scheme information; the official current questionnaire and assessment guidance govern the exact questions and requirements.

  • Firewalls and internet gateways at relevant network boundaries.
  • Secure configuration of devices, applications and cloud services.
  • User accounts, administrator privileges and access control.
  • Malware protection and timely security update management.

Gather evidence from the environment, not from memory

Evidence gathering is a chance to discover practical gaps before submission. Use current device and software records, configuration screens, management reports, account and role lists, update information and documented processes where they exist. Check a representative range of systems and then investigate exceptions. The aim is to reach a reliable answer for the scope, not to produce unnecessary paperwork or copy a generic policy that does not reflect the actual environment.

Set aside time for the people who administer identity, networks, devices and cloud services to check the evidence together. A business owner may need to resolve scope questions or approve remediation work. Record what has been verified, what is missing and which assumptions remain. This makes it easier to revisit the work for renewal or when the organisation changes, and avoids treating the assessment as an isolated technical task.

  • Current device, software, account and administrator-role information.
  • Configuration and management records relevant to each control area.
  • Named owners for evidence, gaps and proposed remediation.
  • A record of scope decisions and exceptions that need follow-up.

Remediate gaps in a controlled order

Common issues can include accounts without appropriate multi-factor protection, unsupported software, unmanaged devices, broad administrator access, uncertain firewall responsibility or missing update information. Do not respond by changing everything at once. First identify whether the gap affects an in-scope service, who depends on it, what safer change is needed and how the result will be checked. Schedule changes to reduce disruption and document the outcome.

Some remediation work may reveal a wider technical or commercial decision: a device may need replacing, a supplier boundary may need clarifying or a legacy application may need a separate risk decision. Capture these dependencies rather than hiding them in a simple pass-or-fail list. Where a control cannot immediately be changed, obtain appropriate advice and use the current scheme rules to understand how that situation should be treated.

  • Prioritise issues that affect in-scope services and users.
  • Plan changes with owners, business impact and validation steps.
  • Record unresolved dependencies and the decision needed to address them.
  • Recheck settings and evidence after remediation work is complete.

Keep certification boundaries clear

Preparation support can help an organisation understand the technical work, collect evidence and address identified gaps. It is not the same as issuing a certification decision. Certification, assessment route, eligibility, assurance level and current scheme requirements are determined through the official scheme and relevant certification bodies. Do not describe a business as certified until it holds the appropriate current certification and the claim can be supported.

Treat Cyber Essentials as part of ongoing security management rather than a one-time document exercise. Changes in devices, staff, suppliers and cloud services can affect the scope and the evidence you rely on. Assign owners for routine access, configuration and update work, keep the inventory current and revisit the documented decisions when material changes occur. That produces a more useful security baseline whether or not a business proceeds to assessment immediately.

  • Use current official sources for scheme and assessment requirements.
  • Separate preparation activity from certification or assessment decisions.
  • Make certification claims only when current supporting evidence exists.
  • Maintain the inventory and control ownership after the assessment work.

Make the preparation work repeatable

Build a small evidence and action record that can be maintained by the people responsible for the environment. It should show the scope, systems checked, source of evidence, gaps, actions and decisions. This avoids starting from scratch when the organisation changes or prepares for a future assessment. It also gives management a clearer view of the work being requested and why a particular technical change matters.

Keep evidence current and proportionate. A record that nobody can maintain is less useful than concise, reliable information connected to real administration processes. When a supplier manages a control, record the supplier, service boundary and the evidence or confirmation required. When the organisation retains a responsibility, name the owner and make the supporting task part of the normal operating routine.

  • Scope, evidence, actions and decisions in one maintained record.
  • Real configuration and ownership information rather than generic claims.
  • Supplier boundaries and confirmations recorded clearly.
  • Named internal owners for the controls they retain.

Certification requires the current official process

This guide is a preparation overview, not a substitute for the current Cyber Essentials questionnaire, scheme rules, assessor instructions or certification advice. The exact requirements and assessment route can change, so use the current NCSC and IASME information before making decisions or claims.

A practical readiness conversation

Before beginning preparation work, make sure the people responsible for the environment can answer these scope and ownership questions.

  • Which people, devices, services and networks are included?
  • Where is the evidence for each control area and who owns it?
  • Which gaps need technical work, a supplier answer or a business decision?
  • Which current official guidance governs the intended assessment route?