Certification guide | 5 min read

What a Cyber Essentials Audit Checks and Why It Matters

The five Cyber Essentials technical controls explained, what an assessor looks for, and how Cyber Essentials Plus and regular IT health checks fit in.

Talk to our team

Blog · Compliance ·

Cyber Essentials audit checklist covering firewalls, secure configuration, access control, malware protection and updates

Cyber Essentials is the UK government backed scheme that shows your business has the basic security controls in place to stop the most common cyber attacks. More and more customers, public sector buyers and insurers ask for it, so it is worth understanding what the assessment involves before you start.

The five controls

Cyber Essentials is built around five technical areas. An assessment checks that each one is in place across all the devices and services in scope.

1. Firewalls

Every device that connects to the internet should be protected by a correctly configured firewall. That includes your office router and the software firewall on each laptop. Default admin passwords must be changed, and any open ports should have a clear business reason.

2. Secure configuration

Computers, phones and cloud services should be set up securely rather than left on default settings. That means removing unused software and accounts, turning off features you do not need and requiring a PIN, password or biometric to unlock devices.

3. User access control

People should only have access to what they need for their job. Admin accounts should be separate from everyday accounts and used only for admin tasks. Multi-factor authentication is expected for cloud services wherever it is available.

4. Malware protection

Every device in scope needs protection against malicious software, such as up to date anti-malware or application controls that only allow approved software to run.

5. Security update management

Operating systems and applications must be supported by the manufacturer and kept updated. Critical and high risk security updates need to be applied within 14 days of release. Software that no longer receives updates must be removed or isolated.

Cyber Essentials vs Cyber Essentials Plus

Cyber Essentials is a self assessment questionnaire, reviewed by an independent certification body.

Cyber Essentials Plus covers the same five controls but adds a hands on technical audit. An assessor tests a sample of your devices, checks for missing updates and tests whether malicious emails and downloads would be blocked. It gives customers stronger assurance, and it is often required for larger contracts.

Why it matters beyond the certificate

The controls in Cyber Essentials stop a large share of everyday attacks. Working through them often uncovers old accounts, unsupported software and forgotten devices that would otherwise go unnoticed.

The certificate lasts 12 months, but threats do not wait for your renewal date. Regular IT health checks between assessments keep your controls in place as staff, devices and software change.

Where penetration testing fits

Cyber Essentials checks that the basics are in place. A penetration test goes further, with a specialist actively trying to break in. Many businesses use Cyber Essentials as the baseline and add pen testing for deeper assurance.

Getting certified

We guide businesses across Dartford and north Kent through Cyber Essentials and Cyber Essentials Plus, from the first gap check to fixing issues and submitting the assessment. If you would like to know how close you already are, talk to our team.

Keep reading

More Advice From Our Blog

Get in touch

Want Help Putting This Into Practice?

Our Dartford team can review your setup and explain the next steps in plain English. Call 01322 783 314, email hello@dartforditsupport.co.uk or send us a message and an engineer will get back to you.

Contact us