Cyber Essentials Technical Controls Explained (2026 UK Guide)

17 August 2026

Understand the five Cyber Essentials technical controls for 2026. A clear UK guide to firewalls, access control, patch management and more.

What Are Cyber Essentials Technical Controls?

The Cyber Essentials scheme, developed by the UK government and managed by IASME, is designed to help businesses protect against common cyber attacks. Its technical controls are the specific security measures you must have in place to become certified. These controls focus on five core areas: firewalls, secure configuration, user access control, malware protection, and patch management. In 2026, the scheme remains a baseline requirement for many public sector contracts, and it is also increasingly requested by private-sector supply chains. Understanding these technical controls is not just about passing a checklist; it is about building practical resilience against threats like phishing, ransomware, and unauthorised access, which are still rampant across the UK.

The Five Core Technical Controls Breakdown

Each of the five Cyber Essentials technical controls addresses a vital layer of your cybersecurity. Firewalls ensure only authorised network traffic enters and leaves your systems. Secure configuration means removing default or unneeded settings to reduce vulnerabilities. User access control limits employee permissions to only what they need, with separate accounts for administrators and standard users. Malware protection safeguards against viruses and other malicious software, using antivirus tools and filtering. Finally, patch management keeps software and devices up to date with the latest security fixes. Together, these controls form a robust baseline that is achievable even for small UK businesses and essential for those seeking assurances from suppliers or aiming to win Government contracts.

How to Implement Firewalls and Secure Configuration

For UK businesses, starting with firewalls and secure configuration is the easiest win. When you set up your firewall, ensure it is enabled on all internet-facing devices, including laptops and phones that work remotely. Default passwords must be changed immediately, and any services like remote desktop should be disabled unless strictly necessary. Secure configuration also extends to cloud services; follow NCSC guidance on Office 365 or Google Workspace settings, and make sure your routers and switches are not left with factory settings. Create a simple configuration standard that your IT team or third-party provider can apply, and review it at least annually as part of your Cyber Essentials renewal for 2026.

User Access Control and Malware Protection Essentials

User access control and malware protection are the front line against insider threats and malicious downloads. For Cyber Essentials, you must have a defined procedure for granting and removing access when staff join or leave, and separate admin accounts from everyday user accounts on all devices. Encourage the use of strong, unique passwords and consider adopting multi-factor authentication as best practice, even though it is not yet mandatory for the basic level. For malware protection, install antivirus software on all desktops, laptops, and servers. If you use Microsoft Defender or an equivalent, make sure it is active and receiving updates. Email filtering to block phishing scams is also recommended under NCSC guidance, especially for small UK firms with limited IT budgets.

Patch Management and Certification Tips for UK Businesses

Patch management is often the most challenging technical control for UK organisations, yet it is critical. You must install security updates within 14 days for critical or high-risk vulnerabilities, and remove software that is no longer supported, such as Windows 10 after its end-of-life. Maintain an asset register listing all your devices and software, and set up a routine patch cycle, ideally automated. For certification, you can complete a self-assessment questionnaire or choose an external assessor. In 2026, many UK firms are moving to Cyber Essentials Plus, which involves independent testing. Starting with the basics and remediating issues early will give you the best chance of passing and keeping your certification valid for a full year.

FAQ

The five technical controls are: firewalls, secure configuration, user access control, malware protection, and patch management. Together, they create a baseline security standard that organisations must meet to achieve Cyber Essentials certification. Each control addresses a specific area of risk, from network security to software updates, and they are assessed either via self-assessment or external audit.

Latest guides