Cyber Essentials Checklist (2026)

What you actually need to have in place to pass Cyber Essentials — in plain English, updated for the stricter 2026 rules. Work through this before you submit.

Controls
Five technical areas
New in 2026
MFA & 14-day patching
Auto-fail
Missing cloud MFA
Delivered by
A certified IASME assessor

The five controls, in plain terms

Cyber Essentials covers five technical controls. Here’s what each means in practice:

  • Firewalls. Every device is protected from the internet by a properly configured firewall, with no unnecessary services exposed and no default admin passwords.
  • Secure configuration. Devices and software are set up securely — default passwords changed, unnecessary accounts and software removed, no needless features left on.
  • Security update management. Everything is supported (nothing past end-of-life in scope) and updates are applied promptly.
  • User access control. People have only the access they need, admin accounts are separate and used only for admin, and leavers are removed promptly.
  • Malware protection. Anti-malware is in place and kept current, or approved-application controls are used.

The 2026 rules that catch people out

The current requirements are stricter, with genuine automatic fails. Get these right before you submit:

  • MFA on all cloud services. Multi-factor authentication must be enabled wherever it’s available, and it’s mandatory on cloud services — a gap here is an automatic fail.
  • Patch within 14 days. Critical and high-risk updates — operating systems, applications, and router/firewall firmware — must be applied within 14 days.
  • Nothing unsupported in scope. End-of-life software still in use will fail you.
  • All cloud services are in scope. You can’t quietly exclude them; the definition is clearer and stricter.
  • No default credentials or insecure defaults left in place.

Our April 2026 changes page explains these in full.

Before you submit

Work through the list above, fix the gaps, and be honest about scope — guessing at scope is a common reason for a fail. If you’d rather not do it alone, a certified IASME assessor will check your setup against how it’s actually marked, tell you plainly what to change, and get you through — usually in days. See what Cyber Essentials involves and what it costs.

Common questions

What’s the most common reason for failing Cyber Essentials?

Missing MFA on a cloud service and slow patching are the big two under the 2026 rules — both are automatic fails. Vague scope and unsupported software are close behind. Sorting those clears most of the risk.

Can we do Cyber Essentials ourselves with this checklist?

Many organisations do. This checklist covers what’s assessed; the value of an assessor is translating the requirements to your exact setup, catching the things that would fail you, and getting you through first time.

How long does it take to get ready?

If your controls are in reasonable shape, days. If there’s remediation — rolling out MFA, fixing patching — a little longer. We tell you what’s needed and roughly how long before you commit.

Related

Get through Cyber Essentials first time

Tell us your setup and we’ll check it against how it’s actually marked — then get you certified, often in days.