Guide
Cyber Essentials requirements: the five controls explained
Updated
Cyber Essentials assesses five technical control themes, set by the NCSC. None of them is exotic; the work is applying them consistently across every in-scope device, including phones and home-working kit.
The five controls
- 1. Firewalls
- Every device in scope sits behind a correctly configured boundary firewall or uses a software firewall; default administrative passwords on routers and firewalls are changed, and management interfaces are not exposed to the internet without good reason and protection.
- 2. Secure configuration
- Devices and software are configured to reduce vulnerabilities: unused accounts and software removed, auto-run disabled, and device unlocking controlled (PINs, passwords or biometrics meeting the scheme's rules).
- 3. Security update management
- All in-scope software is licensed and supported, and updates fixing vulnerabilities the scheme classes as high-risk are applied within 14 days of release. Unsupported operating systems and applications must be removed or taken out of scope: this is one of the most common failure points.
- 4. User access control
- Each user has their own account; administrator rights are separated from day-to-day accounts and reviewed; accounts are removed when people leave; and multi-factor authentication is applied to accounts on cloud services.
- 5. Malware protection
- Every in-scope device is protected by anti-malware software or by an approved alternative approach such as application allow-listing.
Scope: what the assessment covers
- The default and strongest option is whole organisation: every device that accesses organisational data or services. Contracts often require whole-organisation scope, and the included insurance depends on it.
- Bring-your-own devices are in scope when staff use them to access organisational data or services, one of the most commonly misunderstood rules.
- Cloud services your organisation uses are in scope, which is where the MFA requirement bites.
- The official requirements document and question set are free to download from NCSC and IASME, so you can check every rule against your estate before paying anything.
The question set is versioned and updated periodically (recent versions have been named after trees, such as Willow). Always download the current requirements and question set from NCSC or IASME before preparing, and check which version your assessment will use.
Meeting the controls before you apply
- Inventory every device and cloud service that touches organisational data, including personal phones and home machines.
- Retire or replace unsupported software; no other single action prevents more failures.
- Turn on MFA for cloud services, separate admin accounts, and set device-unlock rules.
- Run through the official question set as a dry run, then submit, or use the form to get a certification body to prepare and certify you in one engagement. See also passing first time.