Cybersec Essentials

Cyber Essentials Requirements: The 5 Controls (2026)

juan@preyhq.com
Juan O.
Aug 7, 2026
0 minute read
Cyber Essentials Requirements: The 5 Controls (2026)
TL;DR

Cyber Essentials requirements at a glance

  • Five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. The UK government says they block around 80% of common cyber attacks.
  • Two levels: Cyber Essentials (a verified self-assessment, from £320+VAT) and Cyber Essentials Plus (adds a hands-on technical audit). Both are valid for 12 months.
  • Scope is the hard part: every device that accesses your organisation's data is in scope, including home working and BYOD. Incomplete asset discovery is the most common reason organisations fail.
  • 2026 changes: mandatory MFA on cloud admin accounts, firmware counted as software for patching, passwordless recognised, and asset inventory formalised.
  • Start here: build one accurate list of every device before you open the questionnaire. You can't certify controls on devices you can't see.

You won the contract. Somewhere in the tender documents was a line requiring Cyber Essentials, so you opened the self-assessment questionnaire expecting a checklist. Firewalls, patching, access control: nothing you haven't dealt with before. Then you hit the section that asks you to list every device in scope, and you realise you don't have that list. Half the fleet is remote. A couple of laptops belong to people who left. Two are personal devices someone uses to check email on Fridays.

That's the Cyber Essentials experience for most small and mid-sized organisations. The five controls are learnable in an afternoon. The real work is proving they apply to every device you own, including the ones that aren't in the office. The scheme assumes you already have a complete, current view of your estate. That assumption is where certifications stall.

The stakes are concrete. An incomplete scope isn't a paperwork issue; it's an assessment failure, and for Cyber Essentials Plus a hands-on auditor finds it in the first hour. If you're doing this as, in one IT manager's words, "a 1 man shop for a company that's WFA across several countries," the gap between what the questionnaire assumes and what you can actually see is the whole job.

This guide covers the Cyber Essentials requirements for 2026: the five technical controls, the difference between the two certification levels, how to define your scope, and the device blind spot that sinks more assessments than any single control.

What Cyber Essentials is, and who actually needs it

Cyber Essentials is a UK government-backed certification scheme built on five technical security controls, administered by IASME for the National Cyber Security Centre (NCSC). It comes in two levels: a verified self-assessment, and Cyber Essentials Plus, which adds an independent technical audit. The UK government says the controls block around 80% of common cyber attacks.

Worth clearing up one point of confusion first: this is the UK NCSC scheme, not the US CISA programme that shares the name. If a UK contract, insurer, or head office asked you for "Cyber Essentials," this is the one they mean.

Most organisations pursue it for a concrete reason rather than general good hygiene. Central government contracts that handle certain data require it. A growing number of private-sector buyers ask suppliers for it as a condition of doing business, which pushes the requirement down the supply chain, much as PCI DSS does for anyone handling card data. And UK organisations with turnover under £20m that certify their whole organisation get free cyber liability insurance, arranged through IASME.

The framing that helps here is separating the certificate from the security. Cyber Essentials is evidence that you run a set of basic controls; it isn't the controls themselves, and passing it doesn't make you secure on its own. If you want the fuller picture of how a certificate relates to actual operational posture, our breakdown of IT security versus IT compliance is a useful companion. The reader who treats the certificate as the finish line is the one who's surprised twelve months later at recertification.

The five technical controls, requirement by requirement

Everyone worries about the five controls, and they're the part you'll spend the least time on. The Cyber Essentials requirements are built on five control areas: firewalls, secure configuration, security update management, user access control, and malware protection. Each has specific requirements you attest to in the questionnaire, and each has a common way organisations trip up. Here's what each asks for in 2026.

Firewalls. Every device and network boundary needs a correctly configured firewall. Change default administrative passwords on boundary firewalls and routers, block unauthenticated inbound connections, and enable host-based firewalls on devices that leave the office. A laptop on a home or café network doesn't have your corporate boundary protecting it.

Secure configuration. Devices and software should be set up to reduce their attack surface out of the box. Remove or disable unused accounts and software, change default passwords, and enforce a minimum password strength (at least a 12-character minimum where you rely on passwords alone). Multi-factor authentication is required on cloud service admin accounts.

Security update management. You can only run software that's still supported by its vendor. High and critical vulnerabilities must be patched within 14 days of a fix being released, and that now explicitly includes firmware, not just operating systems and applications. Anything end-of-life and no longer receiving security updates has to be removed from scope or replaced.

User access control. Access to data and services should follow least privilege. That means a documented process for approving accounts, separate administrator and standard user accounts (admins don't read email from the account that can change everything), MFA on cloud user accounts, and a regular review that removes access people no longer need.

Malware protection. Every in-scope device needs one of three approaches: anti-malware software kept up to date, application allow-listing, or sandboxing. On mobile devices, restricting installation to official app stores counts. No device should be left with nothing standing between it and a malicious download.

Control Core requirement (2026) Common failure point
FirewallsBoundary and host firewalls on; default admin passwords changed; unauthenticated inbound blocked.Host firewalls left off on remote laptops.
Secure configurationRemove unused accounts and software; change defaults; 12-char minimum passwords; MFA on cloud admins.Leftover default accounts and no MFA on admin consoles.
Security update managementSupported software only; high/critical patches within 14 days; firmware included; no end-of-life systems.An unsupported OS or unpatched device nobody was tracking.
User access controlDocumented account approval; separate admin/standard accounts; MFA for cloud users; regular access reviews.Admin rights on everyday accounts; ex-staff access never removed.
Malware protectionAnti-malware, allow-listing, or sandboxing on every device; mobile apps from official stores only.A device in scope with no protection configured at all.

Notice how many of those failure points are about a device, not a control. The controls themselves are well understood. What breaks assessments is a device that slipped through: the laptop still running an unsupported OS, the admin account nobody remembered, the machine with no anti-malware because it was set up in a hurry. For the wider set of controls that sit beyond the certification baseline, our guide to security controls in cybersecurity goes deeper than the scheme requires.

Quick win: Pick the three highest-risk controls to check today: change any default admin passwords on your firewall and routers, confirm nothing in your estate runs an end-of-life operating system, and turn on MFA for every cloud admin account. Those three account for a large share of first-attempt failures.

Where do most Cyber Essentials assessments actually fail?

Most assessments fail on scope, not controls. Your scope is every device that accesses your organisation's data: office and remote laptops, mobiles, and cloud services. Home routers are out unless you supplied them; corporate laptops on home networks are in. The usual failure is incomplete asset discovery, the scope wrong before a single control is checked.

This is the part the questionnaire quietly assumes you've solved. It asks you to describe your scope and count your devices, as if you have a definitive list in a drawer. Plenty of organisations don't. They have a spreadsheet that was accurate the last time someone updated it and a general sense of how many laptops are out there that turns out to be off by a dozen once you actually count. That spreadsheet is precisely why asset discovery fails: it drifts the moment a device is bought, lost, or handed to a new starter, and nobody notices until an assessor asks.

Consider a common situation. An organisation wins a public-sector contract that requires Cyber Essentials and starts the self-assessment. When it comes to listing in-scope devices, the picture falls apart: half the fleet is remote, several machines are BYOD, and two laptops belong to employees who left months ago and were never collected. The controls aren't the blocker. The inability to produce a definitive device list is. Every hour after that goes into reconstructing the estate before the real work can even start.

Bring-your-own and home working make this worse, because those devices are in scope but rarely in anyone's inventory. A UK IT lead running 300 devices put the problem plainly: their management tool "fails to provide the visibility for tracking lost or stolen MacBooks." If you can't see a device reliably, you can't attest that it meets five controls, and you certainly can't prove it to an assessor. Our overview of essential cybersecurity controls for SMBs makes the same point from the other direction: visibility comes before control.

Quick win: Before you open the questionnaire, build one authoritative device list and reconcile it against three sources: your identity provider (who has accounts), your finance or purchasing records (what you bought), and whatever management tooling you run (what's actually checking in). Devices that appear in one source but not the others are your scope gaps. Flag every BYOD and every ex-employee device explicitly.

Cyber Essentials or Cyber Essentials Plus: which do you need?

Most teams don't choose their level; the contract chooses it for them. The difference is verification. Cyber Essentials is a self-assessment questionnaire, independently reviewed before you're certified. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit by a licensed assessor, including vulnerability scans on a sample of your devices.

Standard certification starts at £320+VAT, banded by size; Plus costs more and scales with your estate. Both last 12 months. The practical difference is that Plus is much harder to pass on optimistic answers, because an assessor actually checks. If your self-assessment says every device has anti-malware and up-to-date patches, Plus is where a machine that quietly disagrees gets found.

The 2026 requirements tightened several things worth knowing before you certify. MFA is now mandatory on cloud service administrator accounts. Passwordless and biometric authentication are formally recognised. Firmware is explicitly treated as software for patching, so out-of-date router or laptop firmware can count against you. And asset inventory has been formalised as an expectation rather than an implied one, the scheme catching up to the reality that scope is where organisations struggle. If you're mapping this against a broader obligation set, our guide to IT compliance puts it alongside the other frameworks you may be juggling.

The honest read for a smaller team: budget for recertification from the start, and if you're likely to need Plus eventually, prepare for it now. It's far easier to keep the controls continuously true than to reconstruct them the week before an auditor arrives.

When an in-scope device goes missing

A device you can't account for is both a scope problem and a data-exposure problem. If a laptop is lost, stolen, or sitting with an ex-employee, it's still in scope, you can't prove its controls, and its data is exposed unless it's encrypted. Encryption is the backstop; visibility and remote action contain the rest.

This is where Cyber Essentials meets an operational reality the questionnaire doesn't dwell on. Devices disappear. A technical college library once described a machine that had "been missing for over a year with no way to track or retrieve it." That device is a hole in the scope, a possible data breach, and an awkward line in next year's assessment, all at once. Offboarding creates the same problem more quietly: a departing employee's laptop that never came back is an in-scope device you can neither secure nor verify.

How endpoint visibility platforms close the device gap

Endpoint visibility and management tools address the part of Cyber Essentials that lives outside the five controls: knowing your estate and being able to act on it. The workflow is straightforward. A lightweight agent maintains a live hardware and software inventory, so your scope list reflects what's actually checking in rather than what a spreadsheet claimed months ago. It reports each device's encryption status, giving you configuration evidence auditors can see. And when a device goes missing, you can lock it, wipe it remotely, and see its last known location, which turns "we lost a laptop" into "we contained it and have a record."

Prey is one platform IT teams use for exactly this in mixed Windows, macOS, Linux, Android, and iOS fleets, where the appeal is operational simplicity for a lean team rather than another heavy console. One customer described it as "set it and forget it device security... [that] lets me sleep at night." The recovery side is concrete too: teams have used location history to retrieve devices weeks after they went missing, including cases where a former employee claimed a laptop was returned and the record showed otherwise. For the encryption and remote-wipe fundamentals behind this, our guide to data security controls covers what evidence actually holds up.

Quick win: For every device in your fleet, confirm you can answer two questions right now: is it encrypted, and if it went missing today, could you lock or wipe it and show a record of doing so? Any device where the answer is "not sure" is both a Cyber Essentials gap and a live data risk.

Keeping certification year-round, not as a one-time push

Cyber Essentials is annual, so the organisation that treats it as a one-off scramble does the same scramble every twelve months. The controls that were true on assessment day drift: new devices arrive, patches lapse, someone leaves and their access lingers. The teams that recertify smoothly kept the picture current all year rather than rebuilding it from scratch each renewal.

The recurring trap is the inventory. A device list assembled the week before assessment is out of date within a month, which means next year you're not maintaining evidence, you're regenerating it. A live inventory that updates as devices check in beats a spreadsheet you rebuild annually, because the evidence is a by-product of normal operations instead of a project. The same logic applies to patch status and encryption: if you can pull a current report on demand, recertification is a review; if you can't, it's an investigation.

There's a wider benefit to running it this way. Continuous control evidence is what more demanding frameworks expect, so the discipline you build for the Cyber Essentials requirements transfers upward. If you're heading toward ISO 27001, NIST, or a formal risk programme, our guide to IT risk management frameworks shows how the same evidence base supports both.

Quick win: Put a recurring quarterly review in the calendar with three checks: diff your device inventory against last quarter (what appeared, what vanished), confirm patch status on high-risk machines, and remove access for anyone who left. Four short reviews a year turn recertification from a fire drill into a formality.

What the Cyber Essentials requirements really test

The five controls are the part everyone worries about and the part that's actually straightforward. Firewalls, configuration, patching, access control, malware protection: none of it is beyond a competent IT generalist. What sinks assessments is the assumption underneath the questionnaire, that you already know exactly which devices you own and can prove each one meets the bar. That's the real lesson of the Cyber Essentials requirements. The control you'll fail isn't a control. It's the device you forgot you had.

So the practical starting point isn't the questionnaire. It's the list. Build one accurate, current view of every device that touches your data, including the remote ones, the BYOD ones, and the ones belonging to people who left. Confirm you can show its encryption and patch status on demand. Get that right and the five controls become paperwork. Get it wrong and no amount of firewall configuration will save the assessment.

Frequently asked questions

What are the five controls of Cyber Essentials?

The five technical controls are firewalls, secure configuration, security update management, user access control, and malware protection. Together they cover network boundaries, device setup, patching, access permissions, and defence against malicious software. The UK government states these controls help protect against around 80% of common cyber attacks.

How much does Cyber Essentials cost?

Standard Cyber Essentials certification starts at £320+VAT, banded by organisation size. Cyber Essentials Plus costs more and varies with the size and complexity of your device estate, because it involves a hands-on technical audit. UK organisations with turnover under £20m that certify their whole organisation also receive free cyber liability insurance.

How long does Cyber Essentials certification last?

Both Cyber Essentials and Cyber Essentials Plus are valid for 12 months. After that you need to recertify. Because the controls drift over a year as devices and access change, keeping an accurate inventory and current patch and encryption evidence throughout the year makes recertification far easier than reconstructing everything before the deadline.

What's the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment questionnaire covering the five controls. Cyber Essentials Plus assesses the same controls but adds an independent, hands-on technical audit by a licensed assessor, including vulnerability scans and testing on a sample of devices. Plus provides stronger assurance and is harder to pass on optimistic self-reported answers.

Do I need Cyber Essentials if I already have ISO 27001?

Not necessarily, but they serve different purposes. ISO 27001 is a broad information security management standard; Cyber Essentials is a focused baseline of five technical controls. Some contracts specifically require Cyber Essentials regardless of other certifications, so check the exact wording of the requirement rather than assuming ISO 27001 covers it.

Does Cyber Essentials cover BYOD and remote devices?

Yes. Any device that accesses your organisation's data or services is in scope, including remote laptops, home-working machines, and bring-your-own devices used for work. Home routers are generally excluded unless the organisation supplied them, but the corporate or personal devices connecting through them are in scope and must meet the controls.

See every device before you certify. Cyber Essentials starts with a complete, current picture of your fleet: what you own, where it is, and whether it's encrypted. Prey gives IT teams that visibility across Windows, macOS, Linux, Android, and iOS in one place. Start a free trial and build the device list your assessment depends on.