Cyber Essentials, explained
Cyber Essentials is the UK government-backed baseline certification that more and more contracts — public sector, larger supply chains, insurers — now require. It covers five technical controls. This guide explains each one in plain English, what it means for your trade, and how to tell if you're ready. Current question set: Danzell v3.3.
See where you stand in 5 minutes
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →The five controls
Cyber Essentials is built on these five. Each guide covers what it requires, what a scan can and can't verify, and how to get ready.
- Firewalls & internet gateways →A boundary between your devices and the internet, so only the services you actually need are reachable from outside.
- Secure configuration →Devices and software set up to reduce the ways in — default passwords changed, unused features and accounts removed.
- Security update management →Keeping software supported and patched, so known vulnerabilities are closed before attackers use them.
- User access control →Making sure accounts are only used by the right people, with MFA, unique logins and separate admin accounts.
- Malware protection →Protecting devices from malicious software, via anti-malware and/or only allowing approved applications to run.
Cyber Essentials for your industry
Why it matters and what buying pressure looks like in your line of work.
Every question, explained
The actual self-assessment questions, why assessors ask them, and what “good” looks like.
- Is every device that connects to the internet protected by a firewall — including laptops used by home or remote workers?
- Have the default administrative passwords on your firewalls/routers been changed to strong, unique ones?
- Are inbound services from the internet blocked unless there is a documented business need for them?
- Have you removed or disabled software, user accounts and services that you don't use?
- Have all default or vendor-supplied passwords been changed or removed on your devices and software?
- Where a password is the only thing protecting access, is it suitably strong (and is brute-force protection in place)?
- Is all of your software still supported by its vendor (nothing past its end-of-life date)?
- Are high-risk and critical security updates applied within 14 days of the vendor releasing them?
- Are automatic updates turned on wherever they're available?
- Is multi-factor authentication (MFA) enabled on EVERY user account that supports it — including all cloud services and email, for every user, not just admins?
- Does each person have their own individual account, with no shared logins?
- Are administrator accounts separate from everyday accounts, and are leavers' accounts removed promptly?
- Is anti-malware protection active on all in-scope devices (or do you only allow approved applications to run)?
- Are unapproved applications prevented from running, and downloads/attachments handled safely?
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.