Resources

Cyber Essentials readiness checklist

Work through the requirements before you apply, and see exactly where the gaps are.

By Jason Kelly, Certified ISO/IEC 27001 Lead Implementer. Last reviewed October 2026.

Written against the current version: NCSC Requirements for IT Infrastructure v3.3 and the IASME Danzell question set, which apply to assessments started from 27 April 2026.

This is a preparation aid, not the official questionnaire, and it does not guarantee certification. It is general guidance, not legal or professional advice. Always check your answers against the NCSC requirements and the IASME question set.

0 of 37 checks complete

Your ticks are saved in this browser only. Nothing is sent to us.

Scope

Decide what the certificate covers before you check anything else.

1. Firewalls

Only the network services you need should be reachable from the internet.

2. Secure configuration

Remove what you don’t need and lock down what you keep.

3. Security update management

Known vulnerabilities must be fixed quickly.

4. User access control

The right people, with the right access, and strong sign-in.

5. Malware protection

Stop malicious software arriving and running.

Recommended, but not required

Backups are not a Cyber Essentials requirement, but version 3.3 puts much more emphasis on them. They are your recovery plan if ransomware gets through.

  • Automatic backups are switched on for important data.
  • At least one backup copy is kept separate from your network, for example disconnected storage or a separate cloud account.
  • You have test-restored a backup in the last six months.

What changed in April 2026

  • Cloud services are formally defined and can no longer be excluded from scope.
  • MFA on cloud services is now strictly enforced.
  • Passkeys and FIDO2 security keys are recognised as passwordless sign-in and count as MFA.
  • Any part of your organisation you leave out of scope must be justified to the assessor.
  • Backups are given more prominence, though they remain a recommendation.
Book a readiness review

Important

This checklist is provided free as general information. It is a preparation aid based on the NCSC Cyber Essentials Requirements for IT Infrastructure v3.3. It is not the official question set, it does not guarantee certification, and it is not legal or professional advice. Requirements change each year; always check the current official documents before you apply. To the extent permitted by law, Cyber Ascent Consultancy Limited accepts no liability for any loss arising from use of this checklist. See our terms of use.