ESSENTIAL GUIDANCE · READINESS · 8 min read

Part of Foundation insights

How to prepare for Cyber Essentials: a practical checklist

A straightforward Cyber Essentials checklist covering scope, software, access, updates, malware protection and assessment evidence.

A straightforward Cyber Essentials checklist covering scope, software, access, updates, malware protection and assessment evidence.

Need an acronym translated?Open the cyber glossary →

Start by agreeing the scope

List the devices, networks, cloud services and remote-working arrangements that connect to your organisation's data or services. Confirm who owns each part and record any boundaries or exclusions. A clear scope prevents late surprises and makes every later answer easier to evidence.

Remove unsupported software and unnecessary exposure

Check that operating systems, applications, network devices and firmware still receive security updates. Remove software that is no longer supported, close services that do not need to be internet-facing and review firewall rules. Forgotten technology is one of the most common sources of avoidable assessment work.

Tighten user and administrator access

Give people only the access they need, keep administrator accounts separate from everyday accounts and remove access promptly when roles change. Check where multi-factor authentication is required and make sure it is consistently enabled rather than assumed.

Check updates, secure settings and malware protection

Confirm that high-risk security updates are applied within the scheme's required timescales. Review default passwords, unnecessary accounts and insecure settings. Make sure in-scope devices have suitable malware protection or an approved application-control approach and that coverage can be demonstrated.

Collect evidence as you work

Keep an accurate asset list, screenshots or configuration records, policy evidence and named owners for remedial actions. Do not wait until submission week to reconstruct what changed. For Cyber Essentials Plus, prepare representative devices for the independent technical checks and make sure staff know when testing will happen.

Use a readiness review before submitting

A readiness review tests the answers and evidence before they become part of the formal assessment. It gives teams time to fix gaps, clarify the scope and avoid unnecessary delay. Pentesys Foundation provides that preparation and remediation support; certification itself is completed through an authorised certification body.

TALK TO PENTESYS

Apply this guidance to your environment.

Tell us what you need to understand, test or prove. We'll help you choose a proportionate next step—without forcing the conversation into a predefined package.

Apply this to my environment Explore Foundation

Keep reading

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.