Skip to content
Practical preparation

Cyber Essentials check and checklist for 2026.

Use this as a preparation checklist, not as a substitute for the official assessment. Start with scope, then work through the five Cyber Essentials technical controls under the current v3.3 requirements.

Reviewed September 2026Current requirements effective 27 April 2026
01

Scope

Identify which organisation, devices, networks, cloud services and internet-facing systems are included. Scope mistakes can undermine the rest of the assessment.

02

Firewalls

Restrict unnecessary inbound access and make sure internet boundaries are securely configured.

03

Secure configuration

Remove unnecessary software/services, address default settings and reduce avoidable attack surface.

04

Security update management

Use supported software and apply qualifying security fixes within the required timeframe.

05

User access control

Limit access to what people need, control privileged accounts and use MFA where the requirements call for it.

06

Malware protection

Use appropriate malware protection, application allow-listing or equivalent controls for in-scope devices.