Skip to content

Buyer guide

Cyber Essentials v3.3 Checklist: Interactive UK Readiness Guide

By czitapp · Updated 28 September 2026 · Plain-English UK guidance

Interactive preparation tool

Cyber Essentials v3.3 readiness checklist

Use this as a preparation aid against the current public requirements. It is not the official assessment, and it deliberately does not reproduce the Danzell questionnaire question-by-question.

0 / 18 reviewed
ScopeAsset inventoryBlocker if scope is incomplete

Can you identify the devices, servers, networks and cloud services included in the assessment?

Evidence to gather: Document in-scope asset list and cloud services.
ScopeCloud servicesReview

Have relevant cloud services been included rather than excluded merely because a supplier hosts them?

Evidence to gather: Record services, tenancy and responsibility boundaries.
ScopeExclusionsBlocker if unjustified

Can every exclusion be justified and its segregation from in-scope systems explained?

Evidence to gather: Document exclusion rationale and segregation.
ResilienceBackupsReview

Are critical backups identified and can restore arrangements be demonstrated?

Evidence to gather: Backup scope, retention and restore evidence.
FirewallsInternet boundariesBlocker

Are boundary firewalls/routers configured to allow only necessary services?

Evidence to gather: Firewall/router rules and administration evidence.
FirewallsAdmin accessBlocker

Is administrative access to firewall/router configuration protected?

Evidence to gather: Admin account and authentication settings.
Secure configurationDefaultsBlocker

Are unnecessary accounts, services and default credentials removed or changed?

Evidence to gather: Build standard or screenshots.
Secure configurationScreen lockingReview

Are user devices configured to lock appropriately when unattended?

Evidence to gather: Policy/configuration evidence.
UpdatesSupported softwareBlocker

Is all in-scope software licensed and supported?

Evidence to gather: Software inventory and support status.
Updates14-day windowBlocker

Can high-risk/critical fixes and qualifying CVSS 7+ fixes be applied within the required window?

Evidence to gather: Patch reports / MDM / RMM evidence.
AccessLeast privilegeBlocker

Are administrator privileges limited and separated from routine use where appropriate?

Evidence to gather: Admin account list and approval process.
AccessLeavers / role changesReview

Can access be removed promptly when people leave or change role?

Evidence to gather: Joiner-mover-leaver records.
AccessMFABlocker

Is MFA enabled where the current requirements call for it, including relevant administrator and internet-accessible accounts?

Evidence to gather: Identity-provider MFA policies and screenshots.
AccessPasswords / passwordlessReview

Do authentication settings meet the current access-control requirements and use stronger methods where practical?

Evidence to gather: Authentication policy and platform settings.
MalwareProtection approachBlocker

Do in-scope devices use an accepted malware-protection approach appropriate to the platform?

Evidence to gather: Endpoint/security configuration evidence.
MalwareApplication controlReview

Where application allow-listing/sandboxing is used, is it configured and maintained across the scope?

Evidence to gather: Policy and enforcement evidence.
OperationsOwnershipPreparation

Is a named person responsible for closing each unresolved readiness gap?

Evidence to gather: Action owner and due date.
OperationsEvidence packPreparation

Can the organisation retrieve the supporting screenshots, reports and configuration evidence without rebuilding it on audit day?

Evidence to gather: Evidence folder with dates and owners.
Official sources

NCSC Cyber Essentials resources ↗ · IASME question-set preview ↗

Current NCSC requirements: v3.3, effective 27 April 2026. Always check the official documents before submitting an assessment.

Author
czitapp

Published under the CZITAPP editorial and corrections policies. No additional credentials are claimed here unless they are present in the author profile.

Evidence and change history

Last evidence check
2026-09-28
Change history
  • 2026-09-28 | Initial evidence-led publication.