The Cyber Essentials checklist every UK SME should run this quarter
Five controls decide most certification outcomes. Here is how to audit each one before you pay for an assessment.
2026-07-28 · 6 min read · Triforce Technology Desk
Cyber Essentials is increasingly a condition of doing business — insurers ask for it, public sector buyers require it, and enterprise clients now bundle it into supplier questionnaires. The good news is that certification rests on five control areas, and most failures happen in the same predictable places.
Start with boundary firewalls. Every internet-facing device needs a firewall with default passwords changed, unused services closed, and any inbound rule documented with a business justification. If nobody can explain why a port is open, close it.
Second, secure configuration. Remove software nobody uses, disable auto-run, and confirm that every account with administrative rights genuinely needs it. Shared admin logins are the single most common reason an assessment comes back with remediation actions.
Third, patch management. Critical and high-severity patches must land within fourteen days. That is only achievable with automated deployment and a monthly exception report for the machines that failed to update — usually laptops that were switched off.
Fourth, user access control. Starters, movers and leavers should be processed the same day. Multi-factor authentication belongs on every cloud service, not just email.
Finally, malware protection on every endpoint, centrally reported rather than left to individual users. Run these five audits, fix what surfaces, and certification becomes an administrative step instead of a project.