Cyber Essentials checklist for UK SMEs
By Muhammad Sohaib Roomi, founder and reviewer at BrightCertPublished Reviewed
Part of our plain-English Cyber Essentials guide
Short answer
A checklist is a preparation aid, not the certification application. The application itself is the Danzell self-assessment, submitted through an IASME-licensed Certification Body. What a checklist does is get you to the point where answering those questions is a matter of record rather than recall. Work through scope first, because every other answer depends on it.
Most Cyber Essentials preparation does not fail on a missing control. It fails because nobody can show the control is in place, and the person who would know is on leave.
What a checklist is for, and what it is not
A checklist does not certify anything and it is not the application. Its job is narrower and more useful than that: it converts a set of things you believe about your organisation into a set of things you can show, each with a name against it and a date.
That is why the checklist below has an owner column and an evidence column rather than a single tick box. A tick records that somebody felt confident. An owner and a piece of evidence record something that survives that person being unavailable, and it is the difference between a renewal that takes an afternoon next year and one that starts from nothing again.
Start with scope, because everything else inherits from it
Scope decides which devices, people, locations and cloud services the other five sections apply to. Settle it first and the rest is bounded work. Leave it until later and you will find yourself redoing sections because a service or a device type turned out to be inside the boundary after all.
Two things reliably get missed. Cloud services are one: the list held by whoever manages IT and the list of services actually in use are rarely the same, because teams sign up for things directly. Personally owned devices are the other, since scope covers remote workers and personal devices that can access organisational data or services, not only the equipment the company bought.
Both are covered in more detail in the guide to what changed in requirements v3.3.
The checklist
27items across seven stages. Print it, or copy it into whatever you already use to track work — the columns matter more than the format. Use your browser’s print option (Ctrl / Cmd + P) and everything except the checklist itself drops away.
Cyber Essentials preparation checklist
Organisation: ____________________ · Completed by: ____________________ · Date: ____________________ · Source: brightcert.co.uk/blog/cyber-essentials-checklist
1. Scope
Everything below inherits from this. Getting it wrong makes the rest of the work the wrong work.
| Task | Evidence to record | Owner | Status |
|---|---|---|---|
| List every location people work from, including homes | Written list of sites and home-working arrangements | To be completed | To be completed |
| List every device that can reach organisational data, including personally owned ones | Device inventory with owner and type | To be completed | To be completed |
| List every cloud service in use, including services adopted by one team | Cloud service inventory | To be completed | To be completed |
| Write down what is in scope, what is excluded, and the reason for each exclusion | Signed scope statement | To be completed | To be completed |
2. Boundary firewalls and internet gateways
What sits between your systems and the internet, and who decided each gap in it.
| Task | Evidence to record | Owner | Status |
|---|---|---|---|
| Identify every internet-facing device and cloud boundary | Network diagram or device list | To be completed | To be completed |
| Confirm default administrative passwords have been changed | Written confirmation per device, dated | To be completed | To be completed |
| Record the business reason for each inbound rule | Firewall rule list with justification and approver | To be completed | To be completed |
| Confirm a firewall is active on devices used outside the office | Device setting confirmation | To be completed | To be completed |
3. Secure configuration
Devices and software set up deliberately rather than left at whatever the vendor shipped.
| Task | Evidence to record | Owner | Status |
|---|---|---|---|
| Remove or disable user accounts that are no longer needed | Before and after account list | To be completed | To be completed |
| Remove or disable software that is not needed | Installed software list per device type | To be completed | To be completed |
| Confirm no default credentials remain anywhere in scope | Written confirmation, dated | To be completed | To be completed |
| Confirm devices lock automatically when unattended | Screen-lock setting per device type | To be completed | To be completed |
4. User access control
Who can reach what, who approved it, and what happens when someone leaves.
| Task | Evidence to record | Owner | Status |
|---|---|---|---|
| Produce a user list showing role and whether the account is administrative | User access list | To be completed | To be completed |
| Confirm administrative accounts are approved and used only for administrative tasks | Approval record; separate day-to-day accounts | To be completed | To be completed |
| Confirm the leaver process removes access, with a recent example | Leaver process document and one completed instance | To be completed | To be completed |
| Per cloud service, record whether MFA is available and whether it is on for all users | Service-by-service MFA table with date and who checked | To be completed | To be completed |
5. Malware protection
One of three approaches per device type, and proof it is actually running.
| Task | Evidence to record | Owner | Status |
|---|---|---|---|
| Record which approach applies to each device type: anti-malware, allow-listing or sandboxing | Device type to approach mapping | To be completed | To be completed |
| Confirm protection is active and updating | Console screenshot or management report | To be completed | To be completed |
| Confirm how personally owned devices in scope are covered | BYOD arrangement, or evidence the restriction is enforced | To be completed | To be completed |
6. Security update management
Supported software, patched inside the window. The support half fails quietly.
| Task | Evidence to record | Owner | Status |
|---|---|---|---|
| Produce a software inventory recording vendor support status and end-of-life dates | Software inventory | To be completed | To be completed |
| Confirm nothing in scope is past vendor end of life | Inventory review, dated | To be completed | To be completed |
| Confirm critical and high-risk updates are applied within 14 days of release | Update policy stating the window | To be completed | To be completed |
| Keep one sample patch record showing the window was met | Patch log extract | To be completed | To be completed |
7. Final review before applying
The pass that catches answers describing last year's organisation.
| Task | Evidence to record | Owner | Status |
|---|---|---|---|
| Confirm every answer describes the arrangement as it is today | Reviewer name and date against each control area | To be completed | To be completed |
| Confirm every claim has a named owner and evidence behind it | Completed checklist | To be completed | To be completed |
| Confirm you are working from the current Danzell question set and v3.3 requirements | Note of the question set in use | To be completed | To be completed |
| Choose a Certification Body and confirm the fee band for your headcount | Quote or fee confirmation | To be completed | To be completed |
Collecting the evidence
Evidence for Cyber Essentials does not mean a formal audit file. It means that for each claim there is something more durable than memory: an exported list, a dated note of who confirmed a setting, a policy document that states the rule you say you follow.
Three that are worth building properly, because they answer several questions at once and they keep their value between renewals:
- A cloud service inventory. Which services, who owns each one, whether the provider offers multi-factor authentication, and whether it is enabled for all users rather than administrators.
- A software inventory with support status. Recording the vendor end-of-life date alongside each entry answers the supported-software question and warns you about the next thing due to fall out of support.
- A user access list. Role, whether the account is administrative, and when access was last reviewed. This is also the artefact that makes the leaver process demonstrable rather than described.
The final review is not a formality
The last stage exists to catch a specific and common failure: answers that were true when they were first written and quietly stopped being true. A supplier changed, a new device type arrived, someone left. The answer still reads well and no longer describes the organisation.
It is also where you confirm you are working from the current question set. Applications started from 27 April 2026 use the Danzell questions and v3.3 requirements, so anything drafted against the older Willow set needs re-reading rather than reusing.
Frequently asked questions
Is a Cyber Essentials checklist the same as the application?
No. The application is the Danzell self-assessment, submitted through an IASME-licensed Certification Body. A checklist is preparation: it gets you to the point where answering the real questions is a matter of record rather than recall.
What should we do first?
Scope. Every other answer depends on which locations, devices, people and cloud services are inside the boundary. Working through the controls before scope is settled usually means doing part of it twice.
How long does working through a checklist take?
The checking is rarely the slow part. Gathering evidence is, because it means finding out things nobody has written down before, such as which cloud services are actually in use and whether MFA is enabled for everyone rather than administrators.
Do we need evidence if it is a self-assessment?
The self-assessment is answered on your word, but the answers still have to be true and you may be asked to support them. Recording evidence and an owner against each item is what turns a confident answer into a defensible one, and it makes next year's renewal considerably faster.
Does completing this checklist mean we will pass?
No. It means you will know where you stand before you apply, and you will not be discovering gaps partway through an application. The certification decision belongs to the Certification Body.
Rather than filling this in from memory, answer the questions once and get a scored view of where the gaps are and which to fix first.
Start your assessmentBrightCert helps UK businesses prepare for Cyber Essentials by assessing readiness, identifying gaps, and producing a practical report. BrightCert does not issue the official Cyber Essentials certificate. That comes from an IASME-licensed Certification Body.
Sources: NCSC: Cyber Essentials resources · IASME: Cyber Essentials
