Cyber Essentials Checklist UK 2026: Your Step-by-Step Guide

17 August 2026

A practical UK-focused Cyber Essentials checklist for 2026. Covering the 5 controls, firewalls, patch management, and more. Prepare confidently for certification.

Understanding Cyber Essentials and the 5 Controls

The Cyber Essentials scheme, managed by the National Cyber Security Centre (NCSC) and IASME, is the UK's baseline for cyber security. It's designed to protect your business from common cyber threats. The certification is built around five technical controls: boundary firewalls, secure configuration, user access control, malware protection, and patch management. Before you start, make sure you understand these domains fully. Download the official Cyber Essentials requirements document from the NCSC website and map each control to your current IT setup. This checklist will guide you through each one, helping you identify gaps and take actionable steps towards compliance for 2026.

Boundary Firewalls and Internet Gateways

Your first priority is to ensure your network is protected by a boundary firewall or internet gateway. This applies to all devices that connect to the internet, including servers, desktops, and laptops. In the UK, many small businesses use a domestic router, but you need to confirm it has firewall capabilities and that it's properly configured. Disable Universal Plug and Play (UPnP) and any unused ports. If you have cloud services, ensure they are configured correctly too. The key is to allow only necessary inbound and outbound traffic. Review your firewall rules and document them—this is a core part of the Cyber Essentials checklist and a common pain point for UK businesses.

Secure Configuration and Patch Management

Cyber Essentials requires you to remove or disable unnecessary software, accounts, and services. Every device should be configured securely. This means changing default passwords, enabling multi-factor authentication where possible, and setting strict user permissions. Crucially, you must keep all software and operating systems up to date. The UK's NCSC emphasises the importance of patching known vulnerabilities. Enable automatic updates for operating systems, web browsers, and third-party apps. Where automatic patching isn't possible, set a weekly review process. For devices that cannot be updated (e.g., legacy systems), you may need to isolate them or consider whether they should be connected at all.

Access Control and User Accounts

Access control is about managing who can access your data and systems. Only give employees the minimum access they need to do their job. Remove leavers' accounts immediately and disable dormant accounts. Ensure all user accounts have strong, unique passwords. In the UK, the NCSC recommends using three random words or a password manager. Enable multi-factor authentication (MFA) for all remote access services and any administrative accounts. You should also create a separate administrator account for tasks like installing software, and use standard user accounts for day-to-day work. Document your add, change, and remove processes as part of your Cyber Essentials evidence.

Malware Protection and Final Audit Preparation

Malware protection is mandatory for Cyber Essentials. Install an approved antivirus or anti-malware solution on all desktops, laptops, and servers. Many UK businesses use free options like Microsoft Defender, which meets the requirements if kept up to date. Ensure regular malware scans are scheduled and that real-time protection is enabled. You should also restrict access to removable media, network drives, and websites to reduce infection vectors. As you prepare for your Cyber Essentials assessment, collate all your policies, router screenshots, and patch logs. If you're aiming for Cyber Essentials Plus, expect an external vulnerability scan and internal audit. Use a certified assessor to ensure a smooth process in 2026.

FAQ

Cyber Essentials is a UK government-backed certification that verifies your business meets a baseline of cyber security controls. It’s managed by the NCSC and IASME. Certification demonstrates to clients and partners that you protect against common cyber threats, and it’s a requirement for many UK government contracts.

Latest guides