Monitor

Blog › Article

17 July 2026 · Article

Cyber Essentials checklist for 2026

Most checklists list the five controls in order and treat every item as equal. They aren't. The current question set has four automatic-fail questions, covering MFA and patching, so they come first here.

Before the questionnaire: the automatic-fail requirements

Get these right before anything else. There are four automatic-fail questions, in two groups. A single honest "no" on any of them fails the assessment, however good the rest of the answers are.

1. Scope

Every other answer depends on this one, and it's where most first attempts go wrong.

2. Firewalls

3. Secure configuration

4. Security update management

5. User access control

6. Malware protection

Before you submit the questionnaire

The checklist is the easy part. Most organisations can make every item true for one day. The fourteen-day rule means it has to stay true every day, on every machine — which is a monitoring problem, not a questionnaire problem.

Quick answers

How many questions are in the Cyber Essentials questionnaire?

Several dozen, grouped under scope and the five controls. The exact wording changes with each question set, so work from the one your certification body gives you.

Can one "no" fail the whole assessment?

Some can. The four automatic-fail questions cover MFA on cloud services, for administrators and for users, and high-risk updates within fourteen days, for operating systems and network devices and for applications. Others may be treated as findings to fix.

Does this checklist cover Cyber Essentials Plus?

The controls are the same. Plus adds an assessor testing a sample of your devices to confirm the answers are true, so the evidence matters more.