Guide

Cyber Essentials requirements: the five controls explained

Updated

Cyber Essentials assesses five technical control themes, set by the NCSC. None of them is exotic; the work is applying them consistently across every in-scope device, including phones and home-working kit.

The five controls

1. Firewalls
Every device in scope sits behind a correctly configured boundary firewall or uses a software firewall; default administrative passwords on routers and firewalls are changed, and management interfaces are not exposed to the internet without good reason and protection.
2. Secure configuration
Devices and software are configured to reduce vulnerabilities: unused accounts and software removed, auto-run disabled, and device unlocking controlled (PINs, passwords or biometrics meeting the scheme's rules).
3. Security update management
All in-scope software is licensed and supported, and updates fixing vulnerabilities the scheme classes as high-risk are applied within 14 days of release. Unsupported operating systems and applications must be removed or taken out of scope: this is one of the most common failure points.
4. User access control
Each user has their own account; administrator rights are separated from day-to-day accounts and reviewed; accounts are removed when people leave; and multi-factor authentication is applied to accounts on cloud services.
5. Malware protection
Every in-scope device is protected by anti-malware software or by an approved alternative approach such as application allow-listing.

Scope: what the assessment covers

  • The default and strongest option is whole organisation: every device that accesses organisational data or services. Contracts often require whole-organisation scope, and the included insurance depends on it.
  • Bring-your-own devices are in scope when staff use them to access organisational data or services, one of the most commonly misunderstood rules.
  • Cloud services your organisation uses are in scope, which is where the MFA requirement bites.
  • The official requirements document and question set are free to download from NCSC and IASME, so you can check every rule against your estate before paying anything.

The question set is versioned and updated periodically (recent versions have been named after trees, such as Willow). Always download the current requirements and question set from NCSC or IASME before preparing, and check which version your assessment will use.

Meeting the controls before you apply

  1. Inventory every device and cloud service that touches organisational data, including personal phones and home machines.
  2. Retire or replace unsupported software; no other single action prevents more failures.
  3. Turn on MFA for cloud services, separate admin accounts, and set device-unlock rules.
  4. Run through the official question set as a dry run, then submit, or use the form to get a certification body to prepare and certify you in one engagement. See also passing first time.

Questions, answered directly

What are the five controls of Cyber Essentials?

Firewalls, secure configuration, security update management, user access control and malware protection. They are defined by the NCSC in the scheme's requirements document, and both certification levels assess the same five; Cyber Essentials Plus additionally tests them through an independent technical audit.

Are employees' own phones in scope for Cyber Essentials?

Yes, when they access organisational data or services, such as work email or documents. They must then meet the controls, including supported operating systems and device unlocking rules. Devices used only for calls, texts or multi-factor authentication codes are treated differently; check the current requirements document for the exact boundary.

Get your actual price, not a range.

Two minutes of questions; Cyber Essentials certification bodies and consultants quote you directly. Free, no obligation.

Get Cyber Essentials quotes