Cyber Essentials is the UK government’s baseline cybersecurity certification, run by the National Cyber Security Centre (NCSC) and delivered through IASME and its licensed certification bodies. It is deliberately narrow: five technical controls that stop the majority of commodity attacks, assessed either by self-assessment (Cyber Essentials) or by an independent technical audit (Cyber Essentials Plus). US companies encounter it when a UK public-sector contract, a Ministry of Defence supply-chain requirement, or a UK enterprise customer puts it on the list.
This checklist walks through the five controls the way an assessor checks them, the scope decisions that trip most applicants up, the Plus audit itself, and what is different for a company outside the UK.
Cyber Essentials vs Cyber Essentials Plus
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Method | Self-assessment questionnaire, verified by a certification body | Hands-on technical audit of your systems by the certification body |
| Evidence | Your answers, signed off by a board member or equivalent | Vulnerability scans, device sample checks, and control tests performed on your estate |
| Timing | Certificate valid for 12 months | Must be completed within three months of passing the self-assessment |
| Typical effort | Days | Weeks, including remediation |
| Who asks for it | UK public-sector contracts as a minimum | Government, defense, and enterprise buyers who want independent verification |
Plus builds on the self-assessment: you cannot take the audit without first passing the questionnaire, and the audit checks that what you declared is true on a sample of your devices.
Scope: decide this first
Most failed applications go wrong before the controls are even considered.
- Whole organization or a defined subset? Whole-organization scope is simpler to defend and what most buyers expect. A subset is permitted where it is a clearly separated business unit or network boundary, and it must be named on the certificate.
- Every device that accesses organizational data is in scope. Laptops, desktops, servers, mobile phones, and tablets, including personal devices under a bring-your-own-device arrangement if they touch company email or data.
- Home workers are in scope. Their devices are assessed; their home routers generally are not, provided a software firewall is active on the device.
- Cloud services are in scope. Microsoft 365, Google Workspace, and any SaaS the organization uses are assessed for the controls the customer is responsible for, above all multi-factor authentication.
- Unsupported operating systems fail the assessment. An end-of-life OS in scope is an automatic fail unless it is removed or genuinely isolated.
Control 1: Firewalls
What the assessor checks:
- A boundary firewall or equivalent protects every internet connection, and a host-based firewall is active on every device, including laptops used away from the office.
- Default administrative passwords on firewalls and routers have been changed to strong, unique ones.
- Administrative interfaces are not reachable from the internet, or are protected by multi-factor authentication or an IP allow list where remote administration is unavoidable.
- Every inbound rule that opens a service to the internet is documented with a business justification and an owner.
- Rules that are no longer needed are removed promptly.
Control 2: Secure configuration
The configuration checks, applied to every in-scope device:
- Unused accounts, especially default and guest accounts, are removed or disabled.
- Default passwords are changed on every device and service.
- Software and services that are not required are removed or disabled.
- Auto-run and auto-play are disabled so removable media cannot execute code automatically.
- Devices lock after a period of inactivity and require a PIN, password, or biometric to unlock. Mobile devices enforce a minimum of six characters or biometric unlock.
- Accounts are protected against brute force: lockout after no more than ten failed attempts, or throttling that keeps guessing impractically slow.
Control 3: Security update management
The patching checks, including the one that fails the most audits:
- All software in scope is licensed and supported by its vendor. Unsupported software is removed.
- Automatic updates are enabled wherever the software supports them.
- Updates that fix vulnerabilities rated critical or high (CVSS version 3 score of 7 or above, or described as critical or high by the vendor) are applied within 14 days of release. This applies to operating systems, applications, firmware, and browser plugins alike.
- There is a process to discover updates for software that does not update itself, and someone owns it.
The 14-day rule is the control most often failed at the Plus audit, because the authenticated scan of sample devices finds the browser, PDF reader, or runtime that nobody realized was out of date.
Control 4: User access control
The account and authentication checks:
- Every user has a unique account; shared accounts are eliminated.
- Accounts are created through an approval process and removed promptly when people leave or change roles.
- Administrative privileges are granted only to those who need them, and administrator accounts are used only for administration, not for email and browsing.
- Multi-factor authentication is enabled on all cloud services in scope, for all users, with administrators as the minimum where a service cannot support everyone.
- Password policy meets the scheme’s requirements: at least 8 characters where MFA is in place, at least 12 characters where it is not, with no maximum length, plus a deny list of common passwords or a technical control against guessing. Passwordless authentication is accepted under the current requirements.
- Users are told how to choose passwords and what to do if they suspect a compromise.
Control 5: Malware protection
The malware protection checks:
- Anti-malware software is installed, active, and kept updated on every in-scope device, or application allow-listing is used so only approved software can run.
- Anti-malware protection scans files on access and blocks known malicious websites.
- Mobile devices only install applications from approved stores, and application allow-listing is used where the platform supports it.
Sandboxing is no longer accepted as a standalone malware protection option under the current requirements; the choice is anti-malware software or allow-listing.
The annual question set
NCSC and IASME revise the requirements roughly once a year, and each version is named and dated (the April 2025 revision was called Willow). Recent versions have expanded the definition of vulnerability fixes beyond CVSS scores to include vendor-defined critical and high fixes, added passwordless authentication as an acceptable method, and clarified cloud-service and remote-working scope. Always confirm which version your certification body will assess against before you start, because an application submitted under an old version is assessed against the new one once it is current.
What the Plus audit actually does
The certification body’s assessor, usually working remotely, performs four kinds of checks within three months of your self-assessment pass:
- An external vulnerability scan of your internet-facing addresses, looking for exposed services and known vulnerabilities rated high or critical.
- An authenticated vulnerability scan of a sample of devices, sized to your estate and operating-system mix, checking patch status and configuration against the 14-day rule and the secure configuration control.
- Malware protection tests on the sampled devices: test files delivered by email and by download, and access to a known-malicious test URL, to confirm the controls block them.
- Account and MFA checks, confirming that MFA is enforced on cloud services and that administrator separation is real.
Failures are reported, and a limited window is usually allowed for remediation and re-check before the application is marked as failed.
Where applicants fail, and how readiness testing prevents it
The failures we see are consistent: an unsupported OS on one forgotten machine, a browser or runtime past its 14-day patch window, a cloud service with MFA enforced for administrators but not users, a device with the built-in firewall disabled, and default credentials on a network device nobody logs into. All of them are found by running the same checks the assessor runs, before the assessor runs them. That is what our Cyber Essentials Plus readiness testing does: an external test of the boundary, authenticated checks across the same kind of device sample, and an evidence pack formatted for your certification body, with a free retest of anything that failed.
For US companies
Certification is open to organizations anywhere, and IASME-licensed certification bodies audit overseas applicants remotely. US companies typically pursue it because a UK central government contract involving personal data or ICT services requires it, because a UK prime contractor flows a Ministry of Defence requirement down, or because a UK enterprise customer treats it as a minimum bar alongside SOC 2 and ISO 27001.
Three practical notes. The scope can be limited to the business unit that serves the UK, provided the boundary is real. The question set uses UK terminology, but the controls are universal, and the evidence a US company already holds for SOC 2 (MFA enforcement, patch management, endpoint protection) covers most of it. The certification body fee is set by IASME according to organization size and paid to the certifier; readiness testing and any remediation are separate.
Frequently asked questions
How long does Cyber Essentials take? The self-assessment can be completed in days if the controls are already in place. Plus takes a few weeks including the audit and any remediation, and must be finished within three months of the self-assessment pass.
Is Cyber Essentials the same as ISO 27001? No. Cyber Essentials verifies five technical controls; ISO 27001 certifies an entire information security management system. Many organizations hold both, with Cyber Essentials as the technical baseline and ISO 27001 as the governance framework.
Does it cover phishing? Not directly. The controls reduce what a successful phishing attack can achieve (MFA, least privilege, malware protection), but user awareness is outside the scheme. A social engineering assessment covers that separately.
What happens if we fail the Plus audit? The certification body reports the failures, and most allow a short remediation and re-check period. Readiness testing beforehand is far cheaper than a second audit.
Certifying for a UK contract from the US? Scope a readiness assessment and we will run the assessor’s checks first, so the audit confirms what you already fixed.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →