All assessments

Cyber Essentials readiness

Cyber Essentials is five technical controls and an honest questionnaire. Most failed applications aren't caused by weak security - they're caused by unknowns. These questions surface the unknowns first.

Compliance9 questionsUpdated 30 July 2026

Who this is for

Organisations pursuing Cyber Essentials because a contract, funder or insurer expects it.

Time needed: About 5 minutes

0 of 9 answered
  1. 01

    Can you define the scope - every device and cloud service in it?

    Whole organisation is simpler to defend than a carved-out scope.

  2. 02

    Are firewalls in place with default passwords changed?

    Office boundary and the software firewall on each device.

  3. 03

    Have unnecessary accounts, software and default settings been removed?

    Including shared logins and software nobody uses any more.

  4. 04

    Is admin access limited to people who need it, with MFA on cloud services?

    MFA is now expected across cloud services, not just email.

  5. 05

    Is malware protection in place on every in-scope device?

    Built-in protection counts if it's enabled and updating.

  6. 06

    Is everything patched within 14 days of a critical update?

    Operating systems, browsers, plugins and firmware.

  7. 07

    Are you free of unsupported operating systems and software?

    One out-of-support machine can fail the whole application.

  8. 08

    Do you know how personal phones and laptops are handled?

    Devices with work email in scope need the same controls.

  9. 09

    Is someone accountable for the application and the evidence?

    Certification stalls when it's nobody's job.

Answer the remaining 9 questions to see your result.

Want a second opinion on your result?

Get an IT health check that reviews your support, security and Microsoft setup, then gives you a short, prioritised list of what's worth doing.