- Controls
- Five technical areas
- New in 2026
- MFA & 14-day patching
- Auto-fail
- Missing cloud MFA
- Delivered by
- A certified IASME assessor
The five controls, in plain terms
Cyber Essentials covers five technical controls. Here’s what each means in practice:
- Firewalls. Every device is protected from the internet by a properly configured firewall, with no unnecessary services exposed and no default admin passwords.
- Secure configuration. Devices and software are set up securely — default passwords changed, unnecessary accounts and software removed, no needless features left on.
- Security update management. Everything is supported (nothing past end-of-life in scope) and updates are applied promptly.
- User access control. People have only the access they need, admin accounts are separate and used only for admin, and leavers are removed promptly.
- Malware protection. Anti-malware is in place and kept current, or approved-application controls are used.
The 2026 rules that catch people out
The current requirements are stricter, with genuine automatic fails. Get these right before you submit:
- MFA on all cloud services. Multi-factor authentication must be enabled wherever it’s available, and it’s mandatory on cloud services — a gap here is an automatic fail.
- Patch within 14 days. Critical and high-risk updates — operating systems, applications, and router/firewall firmware — must be applied within 14 days.
- Nothing unsupported in scope. End-of-life software still in use will fail you.
- All cloud services are in scope. You can’t quietly exclude them; the definition is clearer and stricter.
- No default credentials or insecure defaults left in place.
Our April 2026 changes page explains these in full.
Before you submit
Work through the list above, fix the gaps, and be honest about scope — guessing at scope is a common reason for a fail. If you’d rather not do it alone, a certified IASME assessor will check your setup against how it’s actually marked, tell you plainly what to change, and get you through — usually in days. See what Cyber Essentials involves and what it costs.
Common questions
What’s the most common reason for failing Cyber Essentials?
Missing MFA on a cloud service and slow patching are the big two under the 2026 rules — both are automatic fails. Vague scope and unsupported software are close behind. Sorting those clears most of the risk.
Can we do Cyber Essentials ourselves with this checklist?
Many organisations do. This checklist covers what’s assessed; the value of an assessor is translating the requirements to your exact setup, catching the things that would fail you, and getting you through first time.
How long does it take to get ready?
If your controls are in reasonable shape, days. If there’s remediation — rolling out MFA, fixing patching — a little longer. We tell you what’s needed and roughly how long before you commit.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day