Cyber Essentials Self-Assessment Checklist: A Practical Pre-Assessment Guide
Cyber Essentials covers five technical controls. This checklist walks you through each one before you fill in the official questionnaire, so you find the gaps yourself instead of failing the assessment. Work through firewalls, secure settings, updates, user accounts and malware protection, gather your evidence, and you will apply with confidence rather than guesswork.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
Why do a dry run before the real thing
Cyber Essentials is the UK government-backed scheme, run under the National Cyber Security Centre (NCSC), that shows your business has the basic technical protections in place. Plenty of contracts — especially public-sector work — now ask for it. If you want the background on what the certification is and why it matters, our companion piece Cyber Essentials explained for UK small business covers the ground.
This playbook is the practical bit: a checklist to work through before you fill in the official questionnaire. The self-assessment is pass or fail, so the cheapest time to find a problem is before you submit — not after an assessor sends the questionnaire back. Treat the list below as your own private practice run.
Grab a notepad or a spreadsheet. For each item, write down what you found and where the evidence lives. That record is exactly what you will lean on when you answer the real questions.
Step 0: Decide what is in scope
Before the five controls, settle one thing: what are you actually certifying? Scope covers the devices, users and cloud services that touch your business data.
- List every device used for work: office computers, laptops, servers, and staff mobiles or tablets that access email or business apps.
- Include home and personal devices if they are used for work — these are usually in scope.
- List your main cloud services: Microsoft 365 or Google Workspace, accounting software, your website host, file storage.
- Note who owns and manages each device. “Nobody is quite sure” is a red flag to fix now.
A clear scope makes every later step easier, because you know precisely what you are checking.
Control 1: Firewalls
A firewall sits between your devices and the internet and blocks traffic that has no business reaching you. You have more of these than you think — your broadband router has one, and so does every laptop.
- Confirm your internet router or firewall is not still using the default admin password. Change it to a strong, unique one.
- Make sure the software firewall is switched on for every in-scope computer (it is built into Windows and macOS).
- Check that no unnecessary services are exposed to the internet — if you are not sure, that is a conversation to have with your IT support.
- For staff working from home or on public Wi-Fi, confirm they are protected — a firewall on the device, and ideally a VPN for anything sensitive.
Control 2: Secure configuration
Devices and software often ship with settings chosen for convenience, not safety. Secure configuration means removing what you do not need and locking down what you keep.
- Remove or disable software and apps you do not use — every extra program is another thing that can go wrong.
- Change all default passwords on devices and accounts to strong, unique ones.
- Turn off features you do not need, such as guest accounts or auto-run for external drives.
- Make sure devices lock automatically after a short period of inactivity and require a password, PIN or biometric to wake.
- Where a service offers it, enable multi-factor authentication. This is central to the next controls too — our guide to multi-factor authentication explained shows how to set it up.
Control 3: Security update management (patching)
Most breaches exploit known weaknesses that already have a fix available. Keeping software up to date is one of the highest-value, lowest-cost things you can do.
- Turn on automatic updates for operating systems (Windows, macOS, iOS, Android) wherever possible.
- Turn on automatic updates for applications, especially web browsers and email software.
- Confirm all your software is still supported by its maker. Cyber Essentials will not pass software that is past its end-of-life and no longer receiving security updates.
- Flag any old operating system — Windows versions that are out of support are a common reason for failure. Replace or upgrade before you apply.
- Aim to apply high-risk or critical updates within 14 days of release, which is the scheme’s expectation.
If you have any device that cannot be updated, deal with it now. An unsupported machine on your network can sink the whole application.
Control 4: User access control
The idea here is simple: people should have access to what they need for their job, and no more. If an account is compromised, you want the damage to be limited.
- Give each person their own account — no shared logins.
- Remove accounts for people who have left, and review the list of who has access.
- Make sure everyday work is done on a standard user account, not an administrator account.
- Keep administrator accounts separate and use them only for admin tasks.
- Enforce strong, unique passwords and protect important accounts with multi-factor authentication.
- Have a proper way for staff to store passwords. A shared spreadsheet or sticky notes will not do — a password manager such as Proton Pass gives each person a secure vault, and our roundup of the best password manager for small business compares the options.
Control 5: Malware protection
The final control is about stopping malicious software from running on your devices — whether that is a virus in an email attachment or a dodgy download.
- Make sure anti-malware protection is active on every in-scope computer. On Windows, the built-in Microsoft Defender is acceptable when it is switched on and kept current.
- Confirm it is set to update automatically and to scan files when they are opened.
- For mobile devices, rely on the official app stores (Apple App Store, Google Play) and keep unknown-source installs switched off.
- Consider how you handle email attachments and links — most malware still arrives by email, so staff awareness matters as much as the software.
Pulling it together
Once you have worked through all five controls, review your notes. Every box ticked with evidence noted means you can answer the official questionnaire honestly and quickly. Every box you could not tick is a job to do before you submit — and finding it now, on your own terms, is exactly the point.
A few final tips:
- Keep your evidence in one place, such as a simple shared document, so you can find it again next year when you renew.
- Get whoever manages your devices involved early, rather than answering questions on their behalf.
- Be honest with yourself. The scheme protects you, not the assessor — a certificate that papers over a real gap helps no one.
If you would rather not do the technical tidying yourself, or you want to be certain you will pass first time, this is bread-and-butter work for a good IT partner. Our cyber-security services include running this pre-assessment, fixing what needs fixing, and guiding you through certification. If that sounds useful, get in touch and we will talk it through in plain English.
Frequently asked questions
Do I need to fix everything before I apply for Cyber Essentials?
Yes. Cyber Essentials (the self-assessed level) is pass or fail against the five controls, so it is far cheaper and less stressful to close the gaps first. This checklist is designed to surface those gaps before you pay for and submit the official questionnaire.
How long does the self-assessment take to prepare for?
For a small business with a handful of devices, a focused day or two is usually enough to work through the checklist and tidy up settings. Older kit, unsupported software or unclear ownership of devices can add time, which is exactly why doing a dry run first is worth it.
Does Cyber Essentials cover mobile phones and home laptops?
It can. Any device that connects to your business data or services — including staff mobiles and home computers used for work — is usually in scope. Decide what is in scope early, because it changes which settings and updates you need to check.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment you complete yourself and have verified. Cyber Essentials Plus adds a hands-on technical audit by an assessor. The five controls are the same, so this checklist prepares you for both — Plus simply checks that you have actually done what you said.
Can we do the self-assessment ourselves or do we need help?
Many small firms complete it themselves, especially with a checklist like this. If you have no in-house IT, unsupported systems, or you simply want it done right first time, an IT partner can run the pre-assessment and fix issues for you before submission.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.