ESSENTIAL GUIDANCE · READINESS · 8 min read
Part of Foundation insights →How to prepare for Cyber Essentials: a practical checklist
A straightforward Cyber Essentials checklist covering scope, software, access, updates, malware protection and assessment evidence.
A straightforward Cyber Essentialsi checklist covering scope, software, access, updates, malware protection and assessment evidence.
Need an acronym translated?Open the cyber glossary →Start by agreeing the scope
List the devices, networks, cloud services and remote-working arrangements that connect to your organisation's data or services. Confirm who owns each part and record any boundaries or exclusions. A clear scope prevents late surprises and makes every later answer easier to evidence.
Remove unsupported software and unnecessary exposure
Check that operating systems, applications, network devices and firmware still receive security updates. Remove software that is no longer supported, close services that do not need to be internet-facing and review firewall rules. Forgotten technology is one of the most common sources of avoidable assessment work.
Tighten user and administrator access
Give people only the access they need, keep administrator accounts separate from everyday accounts and remove access promptly when roles change. Check where multi-factor authentication is required and make sure it is consistently enabled rather than assumed.
Check updates, secure settings and malware protection
Confirm that high-risk security updates are applied within the scheme's required timescales. Review default passwords, unnecessary accounts and insecure settings. Make sure in-scope devices have suitable malware protection or an approved application-control approach and that coverage can be demonstrated.
Collect evidence as you work
Keep an accurate asset list, screenshots or configuration records, policy evidence and named owners for remedial actions. Do not wait until submission week to reconstruct what changed. For Cyber Essentials Plusi, prepare representative devices for the independent technical checks and make sure staff know when testing will happen.
Use a readiness review before submitting
A readiness review tests the answers and evidence before they become part of the formal assessment. It gives teams time to fix gaps, clarify the scope and avoid unnecessary delay. Pentesys Foundation provides that preparation and remediation support; certification itself is completed through an authorised certification body.




