Back to articles

Cyber Essentials checklist for UK SMEs

By , founder and reviewer at BrightCertPublished Reviewed

Part of our plain-English Cyber Essentials guide

Short answer

A checklist is a preparation aid, not the certification application. The application itself is the Danzell self-assessment, submitted through an IASME-licensed Certification Body. What a checklist does is get you to the point where answering those questions is a matter of record rather than recall. Work through scope first, because every other answer depends on it.

Most Cyber Essentials preparation does not fail on a missing control. It fails because nobody can show the control is in place, and the person who would know is on leave.

What a checklist is for, and what it is not

A checklist does not certify anything and it is not the application. Its job is narrower and more useful than that: it converts a set of things you believe about your organisation into a set of things you can show, each with a name against it and a date.

That is why the checklist below has an owner column and an evidence column rather than a single tick box. A tick records that somebody felt confident. An owner and a piece of evidence record something that survives that person being unavailable, and it is the difference between a renewal that takes an afternoon next year and one that starts from nothing again.

Start with scope, because everything else inherits from it

Scope decides which devices, people, locations and cloud services the other five sections apply to. Settle it first and the rest is bounded work. Leave it until later and you will find yourself redoing sections because a service or a device type turned out to be inside the boundary after all.

Two things reliably get missed. Cloud services are one: the list held by whoever manages IT and the list of services actually in use are rarely the same, because teams sign up for things directly. Personally owned devices are the other, since scope covers remote workers and personal devices that can access organisational data or services, not only the equipment the company bought.

Both are covered in more detail in the guide to what changed in requirements v3.3.

The checklist

27items across seven stages. Print it, or copy it into whatever you already use to track work — the columns matter more than the format. Use your browser’s print option (Ctrl / Cmd + P) and everything except the checklist itself drops away.

Download the checklist as a Word documentAll 27 items with owner and status columns you can fill in and keep. Opens in a new tab.

Cyber Essentials preparation checklist

1. Scope

Everything below inherits from this. Getting it wrong makes the rest of the work the wrong work.

1. Scope: tasks, evidence, owner and status
TaskEvidence to recordOwnerStatus
List every location people work from, including homesWritten list of sites and home-working arrangementsTo be completedTo be completed
List every device that can reach organisational data, including personally owned onesDevice inventory with owner and typeTo be completedTo be completed
List every cloud service in use, including services adopted by one teamCloud service inventoryTo be completedTo be completed
Write down what is in scope, what is excluded, and the reason for each exclusionSigned scope statementTo be completedTo be completed

2. Boundary firewalls and internet gateways

What sits between your systems and the internet, and who decided each gap in it.

2. Boundary firewalls and internet gateways: tasks, evidence, owner and status
TaskEvidence to recordOwnerStatus
Identify every internet-facing device and cloud boundaryNetwork diagram or device listTo be completedTo be completed
Confirm default administrative passwords have been changedWritten confirmation per device, datedTo be completedTo be completed
Record the business reason for each inbound ruleFirewall rule list with justification and approverTo be completedTo be completed
Confirm a firewall is active on devices used outside the officeDevice setting confirmationTo be completedTo be completed

3. Secure configuration

Devices and software set up deliberately rather than left at whatever the vendor shipped.

3. Secure configuration: tasks, evidence, owner and status
TaskEvidence to recordOwnerStatus
Remove or disable user accounts that are no longer neededBefore and after account listTo be completedTo be completed
Remove or disable software that is not neededInstalled software list per device typeTo be completedTo be completed
Confirm no default credentials remain anywhere in scopeWritten confirmation, datedTo be completedTo be completed
Confirm devices lock automatically when unattendedScreen-lock setting per device typeTo be completedTo be completed

4. User access control

Who can reach what, who approved it, and what happens when someone leaves.

4. User access control: tasks, evidence, owner and status
TaskEvidence to recordOwnerStatus
Produce a user list showing role and whether the account is administrativeUser access listTo be completedTo be completed
Confirm administrative accounts are approved and used only for administrative tasksApproval record; separate day-to-day accountsTo be completedTo be completed
Confirm the leaver process removes access, with a recent exampleLeaver process document and one completed instanceTo be completedTo be completed
Per cloud service, record whether MFA is available and whether it is on for all usersService-by-service MFA table with date and who checkedTo be completedTo be completed

5. Malware protection

One of three approaches per device type, and proof it is actually running.

5. Malware protection: tasks, evidence, owner and status
TaskEvidence to recordOwnerStatus
Record which approach applies to each device type: anti-malware, allow-listing or sandboxingDevice type to approach mappingTo be completedTo be completed
Confirm protection is active and updatingConsole screenshot or management reportTo be completedTo be completed
Confirm how personally owned devices in scope are coveredBYOD arrangement, or evidence the restriction is enforcedTo be completedTo be completed

6. Security update management

Supported software, patched inside the window. The support half fails quietly.

6. Security update management: tasks, evidence, owner and status
TaskEvidence to recordOwnerStatus
Produce a software inventory recording vendor support status and end-of-life datesSoftware inventoryTo be completedTo be completed
Confirm nothing in scope is past vendor end of lifeInventory review, datedTo be completedTo be completed
Confirm critical and high-risk updates are applied within 14 days of releaseUpdate policy stating the windowTo be completedTo be completed
Keep one sample patch record showing the window was metPatch log extractTo be completedTo be completed

7. Final review before applying

The pass that catches answers describing last year's organisation.

7. Final review before applying: tasks, evidence, owner and status
TaskEvidence to recordOwnerStatus
Confirm every answer describes the arrangement as it is todayReviewer name and date against each control areaTo be completedTo be completed
Confirm every claim has a named owner and evidence behind itCompleted checklistTo be completedTo be completed
Confirm you are working from the current Danzell question set and v3.3 requirementsNote of the question set in useTo be completedTo be completed
Choose a Certification Body and confirm the fee band for your headcountQuote or fee confirmationTo be completedTo be completed

Collecting the evidence

Evidence for Cyber Essentials does not mean a formal audit file. It means that for each claim there is something more durable than memory: an exported list, a dated note of who confirmed a setting, a policy document that states the rule you say you follow.

Three that are worth building properly, because they answer several questions at once and they keep their value between renewals:

  • A cloud service inventory. Which services, who owns each one, whether the provider offers multi-factor authentication, and whether it is enabled for all users rather than administrators.
  • A software inventory with support status. Recording the vendor end-of-life date alongside each entry answers the supported-software question and warns you about the next thing due to fall out of support.
  • A user access list. Role, whether the account is administrative, and when access was last reviewed. This is also the artefact that makes the leaver process demonstrable rather than described.

The final review is not a formality

The last stage exists to catch a specific and common failure: answers that were true when they were first written and quietly stopped being true. A supplier changed, a new device type arrived, someone left. The answer still reads well and no longer describes the organisation.

It is also where you confirm you are working from the current question set. Applications started from 27 April 2026 use the Danzell questions and v3.3 requirements, so anything drafted against the older Willow set needs re-reading rather than reusing.

Frequently asked questions

Is a Cyber Essentials checklist the same as the application?

No. The application is the Danzell self-assessment, submitted through an IASME-licensed Certification Body. A checklist is preparation: it gets you to the point where answering the real questions is a matter of record rather than recall.

What should we do first?

Scope. Every other answer depends on which locations, devices, people and cloud services are inside the boundary. Working through the controls before scope is settled usually means doing part of it twice.

How long does working through a checklist take?

The checking is rarely the slow part. Gathering evidence is, because it means finding out things nobody has written down before, such as which cloud services are actually in use and whether MFA is enabled for everyone rather than administrators.

Do we need evidence if it is a self-assessment?

The self-assessment is answered on your word, but the answers still have to be true and you may be asked to support them. Recording evidence and an owner against each item is what turns a confident answer into a defensible one, and it makes next year's renewal considerably faster.

Does completing this checklist mean we will pass?

No. It means you will know where you stand before you apply, and you will not be discovering gaps partway through an application. The certification decision belongs to the Certification Body.

Rather than filling this in from memory, answer the questions once and get a scored view of where the gaps are and which to fix first.

Start your assessment

BrightCert helps UK businesses prepare for Cyber Essentials by assessing readiness, identifying gaps, and producing a practical report. BrightCert does not issue the official Cyber Essentials certificate. That comes from an IASME-licensed Certification Body.

Sources: NCSC: Cyber Essentials resources · IASME: Cyber Essentials