Buyer guide
Cyber Essentials v3.3 Checklist: Interactive UK Readiness Guide
Cyber Essentials v3.3 readiness checklist
Use this as a preparation aid against the current public requirements. It is not the official assessment, and it deliberately does not reproduce the Danzell questionnaire question-by-question.
Can you identify the devices, servers, networks and cloud services included in the assessment?
Evidence to gather: Document in-scope asset list and cloud services.Have relevant cloud services been included rather than excluded merely because a supplier hosts them?
Evidence to gather: Record services, tenancy and responsibility boundaries.Can every exclusion be justified and its segregation from in-scope systems explained?
Evidence to gather: Document exclusion rationale and segregation.Are critical backups identified and can restore arrangements be demonstrated?
Evidence to gather: Backup scope, retention and restore evidence.Are boundary firewalls/routers configured to allow only necessary services?
Evidence to gather: Firewall/router rules and administration evidence.Is administrative access to firewall/router configuration protected?
Evidence to gather: Admin account and authentication settings.Are unnecessary accounts, services and default credentials removed or changed?
Evidence to gather: Build standard or screenshots.Are user devices configured to lock appropriately when unattended?
Evidence to gather: Policy/configuration evidence.Is all in-scope software licensed and supported?
Evidence to gather: Software inventory and support status.Can high-risk/critical fixes and qualifying CVSS 7+ fixes be applied within the required window?
Evidence to gather: Patch reports / MDM / RMM evidence.Are administrator privileges limited and separated from routine use where appropriate?
Evidence to gather: Admin account list and approval process.Can access be removed promptly when people leave or change role?
Evidence to gather: Joiner-mover-leaver records.Is MFA enabled where the current requirements call for it, including relevant administrator and internet-accessible accounts?
Evidence to gather: Identity-provider MFA policies and screenshots.Do authentication settings meet the current access-control requirements and use stronger methods where practical?
Evidence to gather: Authentication policy and platform settings.Do in-scope devices use an accepted malware-protection approach appropriate to the platform?
Evidence to gather: Endpoint/security configuration evidence.Where application allow-listing/sandboxing is used, is it configured and maintained across the scope?
Evidence to gather: Policy and enforcement evidence.Is a named person responsible for closing each unresolved readiness gap?
Evidence to gather: Action owner and due date.Can the organisation retrieve the supporting screenshots, reports and configuration evidence without rebuilding it on audit day?
Evidence to gather: Evidence folder with dates and owners.NCSC Cyber Essentials resources ↗ · IASME question-set preview ↗
Current NCSC requirements: v3.3, effective 27 April 2026. Always check the official documents before submitting an assessment.