Blog › Article
Cyber Essentials checklist for 2026
Most checklists list the five controls in order and treat every item as equal. They aren't. The current question set has four automatic-fail questions, covering MFA and patching, so they come first here.
Before the questionnaire: the automatic-fail requirements
Get these right before anything else. There are four automatic-fail questions, in two groups. A single honest "no" on any of them fails the assessment, however good the rest of the answers are.
- MFA on every cloud service that offers it — Microsoft 365, Google Workspace, accounting, CRM, file sharing. Two questions: one for administrator accounts, one for users. List every service first; the one people forget is the one that fails.
- High-risk and critical updates within fourteen days of release. Two questions: one for operating systems, routers and firewalls, one for applications. Fourteen days from the vendor's release, not from when your patching tool approved it.
1. Scope
Every other answer depends on this one, and it's where most first attempts go wrong.
- Every device that accesses organisational data or services: desktops, laptops, servers, tablets and phones.
- Devices used by home workers that access organisational data or services.
- Personally owned devices that access work email or files.
- Cloud services that hold or process organisational data, which can't be excluded.
- Anything you exclude must be genuinely separated from what's in scope, not just left off the list.
2. Firewalls
- A firewall between every in-scope device and the internet — the office router or boundary firewall, and the software firewall on laptops that leave the office.
- Default administrator passwords changed on every firewall and router.
- The firewall's admin interface not reachable from the internet, unless there's a clear need and it's protected.
- Inbound rules that are documented, needed, and removed when they no longer are.
3. Secure configuration
- Software and accounts that aren't needed removed or disabled.
- Default passwords changed everywhere, not just on network kit.
- Autorun disabled, so inserted media doesn't run anything by itself.
- Devices lock when unattended and need a PIN, password or biometric to unlock.
- Password-only logins protected against guessing, by lockout or throttling, and meeting the question set's rules on length.
4. Security update management
- Every operating system and application in scope is licensed and still supported by its vendor. Unsupported software must be removed, or moved into a separate subset with no internet access at all.
- Automatic updates switched on wherever that's possible.
- High-risk and critical updates applied within fourteen days — including browsers, PDF readers and remote-access tools.
- Nothing paused indefinitely, and no deferral policy that adds up to more than fourteen days from release to installed.
5. User access control
- A process for creating and removing accounts, so leavers lose access the day they go.
- Administrator accounts used only for administration — not for email or browsing.
- Only the people who need administrator rights have them.
- MFA on cloud services, as above, for every user.
- Accounts that aren't used any more disabled or removed.
6. Malware protection
- Anti-malware running on every device that supports it, kept up to date, with real-time protection on.
- Or, where that isn't the approach, application allow-listing so only approved software can run.
Before you submit the questionnaire
- Answer for the whole estate, not the best machine. "Yes" means yes on every in-scope device.
- Check the machines that are usually off. The laptop in a drawer is still in scope and is usually the one furthest behind.
- Keep the evidence behind each answer. An assessor, or a Cyber Essentials Plus audit, may ask how you know.
- Note the date. The certificate says what was true when you answered. Whether it's still true in six months depends on what happens next.
The checklist is the easy part. Most organisations can make every item true for one day. The fourteen-day rule means it has to stay true every day, on every machine — which is a monitoring problem, not a questionnaire problem.
Quick answers
How many questions are in the Cyber Essentials questionnaire?
Several dozen, grouped under scope and the five controls. The exact wording changes with each question set, so work from the one your certification body gives you.
Can one "no" fail the whole assessment?
Some can. The four automatic-fail questions cover MFA on cloud services, for administrators and for users, and high-risk updates within fourteen days, for operating systems and network devices and for applications. Others may be treated as findings to fix.
Does this checklist cover Cyber Essentials Plus?
The controls are the same. Plus adds an assessor testing a sample of your devices to confirm the answers are true, so the evidence matters more.