Cyber Essentials Checklist: 5 Key Areas
The Cyber Essentials checklist sets out the five technical control areas every UK organisation should have in place to defend against the most common online threats. It is a practical starting point for cyber security essentials and a useful stepping stone toward broader information security management. This guide covers each control area and explains how it links to ISO 27001, supported by ISO 27001 training courses including the Lead Auditor Course, Internal Auditor Course, and Foundation Course.
What is a Cyber Essentials Checklist?
A cyber essential checklist is a structured set of technical controls drawn from the UK government-backed Cyber Essentials scheme, administered by IASME on behalf of the National Cyber Security Centre (NCSC). It distils best-practice cyber security essentials into five areas that organisations of any size can implement to reduce the risk of common attacks such as phishing, malware, password compromise, and unpatched vulnerabilities. Working through this checklist before applying for certification helps an organisation evidence each control consistently and identify gaps early.
Cyber Essentials Checklist Overview
The checklist is built around the following five control areas. Each area has its own set of requirements that must be in place across the in-scope environment.
- Firewalls Checklist: Confirm that boundary firewalls and software firewalls are configured on all in-scope devices, default administrative passwords have been changed, and inbound services are blocked unless documented and approved. Remote management of firewalls should be disabled or protected by multi-factor authentication.
- Secure Configuration Checklist: Remove or disable unnecessary user accounts, default passwords, and unused software. Auto-run features should be disabled and devices configured to lock after a short period of inactivity. Each system should have only the services it needs.
- User Access Control Checklist: Verify user accounts are assigned only to authorised individuals, administrative accounts are used solely for admin tasks, and multi-factor authentication is enforced on cloud services. Account creation, change, and removal should follow a documented process.
- Malware Protection Checklist: Ensure malware protection is active on all in-scope devices, signatures are kept up to date, and only approved applications can run. For cloud-delivered services, application allow-listing or sandboxing may be used in place of traditional anti-virus.
- Security Update Management Checklist: Confirm operating systems, applications, and firmware are licensed and supported, with high-risk or critical security updates applied within 14 days of release. Unsupported software must be removed from the in-scope environment.
How Cyber Essentials Supports ISMS Frameworks
Cyber Essentials addresses the technical foundations that any Information Security Management System (ISMS) relies on. The five control areas map directly to several Annex A controls in ISO 27001, including access control, configuration management, malware protection, and technical vulnerability management. Organisations that complete this baseline often find they have already implemented a meaningful portion of the technical controls expected by an ISMS, leaving them better placed to focus on governance, risk treatment, and continual improvement under a wider framework.
Cyber Essentials vs ISO 27001
Both schemes improve cyber security but they differ in scope, depth, and how they are assessed. The table below summarises the main differences.
Preparing for Cyber Essentials Certification
Preparation usually starts with defining the scope of the assessment, including all devices, networks, and cloud services that handle organisational data. The next step is a gap assessment against the checklist, identifying any control area where evidence is incomplete. Common preparation actions include enabling multi-factor authentication on cloud accounts, decommissioning unsupported software, tightening firewall rules, and documenting the joiners, movers, and leavers process. A short internal review before submitting the self-assessment helps reduce the risk of failed questions and rework.
Considering a Wider Security Framework like ISO 27001?
If your organisation handles sensitive customer data, contracts with regulated industries, or wants to differentiate on security posture, ISO 27001 provides a more comprehensive framework. It builds on the technical baseline that Cyber Essentials covers and adds risk assessment, governance, supplier management, and continual improvement. SEQM Training delivers CQI and IRCA certified ISO 27001 courses at lead auditor, internal auditor, and foundation level, supporting the standard BS EN ISO/IEC 27001:2023+A1:2024 and the tracked changes edition.
Frequently Asked Questions
A cyber essentials checklist covers five control areas: firewalls, secure configuration, user access control, malware protection, and security update management.
For a prepared organisation, the self-assessment can typically be completed and certified within a few weeks. Cyber Essentials Plus involves an additional technical audit and usually takes longer.
It is not mandatory for all organisations, but many UK government contracts and supply chain agreements require Cyber Essentials or Cyber Essentials Plus certification.
You need defined scope, evidence that all five control areas are implemented, and a completed self-assessment questionnaire submitted through a certification body.


