Free tool

Are you ready for Cyber Essentials?

19 plain-English questions across the five technical controls, updated for the April 2026 requirements. About four minutes, and you’ll see exactly where the gaps are.

Up to date with Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026) and IASME’s Danzell question set, in force since . Questions marked Automatic fail fail the whole assessment if the answer is no. Last checked 8 October 2026.

1 Firewalls

Only secure and necessary services can be reached from the internet.

Is every device protected by a firewall, including a software firewall on laptops used on home, hotel or public wifi?
Have the default admin passwords on your routers and firewalls been changed to strong, unique ones?
Is your router’s or firewall’s admin page blocked from the internet (or, if it has to be reachable, protected by MFA or an IP allow list)?
Are incoming connections blocked by default, with any open ports approved, documented and removed when no longer needed?
2 Secure configuration

Devices and software are set up to reduce weak spots.

Do you remove software and user accounts that aren’t needed (such as guest accounts), and change any default passwords?
Does every device need a password, a PIN of at least six characters, or a fingerprint or face to unlock, with a limit on wrong guesses?
Is auto-run turned off, so files (for example on USB sticks) can’t run without someone’s say-so?
3 Security update management

Devices and software aren’t open to known weaknesses.

Is every operating system and app still supported and getting security updates? (Windows 10 now needs Microsoft’s paid Extended Security Updates.)
Are critical and high-risk security updates for operating systems and for router and firewall firmware installed within 14 days of release?Automatic fail
Are critical and high-risk security updates for applications, including their extensions and plug-ins, installed within 14 days of release?Automatic fail
Are automatic updates switched on wherever they’re available?
4 User access control

Only the right people have access, with only the access they need.

Is multi-factor authentication (MFA) switched on for every user of every cloud service that offers it, such as Microsoft 365 and your social media accounts?Automatic fail
Is MFA switched on for every administrator account on your cloud services?Automatic fail
Are admin accounts (including Microsoft 365 and other cloud admin accounts) separate, and used only for admin work, never for everyday email and browsing?
Does everyone have their own login, with no shared accounts?
Are accounts and special access removed or disabled promptly when someone leaves or no longer needs them?
5 Malware protection

Known malware can’t run on your devices.

Is anti-malware active and kept up to date on every Windows and Mac computer (or are apps limited to an approved list)?
+ Scope

Knowing what Cyber Essentials covers in your company.

Do you know every device that’s used for work, including personal phones that get work email?
Do you have a list of every cloud service the company uses, from Microsoft 365 to accounting software and social media?

0 of 19 answered

Frequently asked questions

Is this an official Cyber Essentials assessment?

No. It’s a quick self-check, based on the NCSC’s Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026) and IASME’s Danzell question set. Certification is done through IASME, the Cyber Essentials delivery partner, via a certification body. See the NCSC’s Cyber Essentials resources.

What changed in April 2026?

Version 3.3 of the requirements and the Danzell question set came into force on 27 April 2026. The controls themselves barely changed, but the marking did. Not using multi-factor authentication on a cloud service that offers it is now an automatic fail, and so is answering “no” to installing critical and high-risk updates within 14 days (for operating systems, router and firewall firmware, and applications). Cloud services can no longer be left out of scope, social media accounts count as cloud services, and passkeys count as MFA. Read IASME’s summary.

What’s the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment questionnaire, checked by a certification body. Cyber Essentials Plus covers the same controls but adds hands-on technical testing of your systems by an assessor.

Can you help us get certified?

Yes. Cyber Essentials Compliance is available as an add-on to any MYLE plan, and we hold Cyber Essentials Plus ourselves. Tell us where you are and we’ll help you close the gaps.

Do you store my answers?

No. The checklist runs entirely in your browser. If you choose to send your results to us, they’re added to the IT Assessment form for you to check before sending.

Get certified with a company that’s done it

We hold Cyber Essentials Plus, ISO 9001 and ISO 27001. Start with a two-minute IT Assessment.