Cyber Essentials Self-Assessment Pack
Self-assessment toolkit for Cyber Essentials readiness covering firewalls, secure config, access control, malware protection, and patching.
UK SMEs, MSP account managers, and internal IT teams preparing for Cyber Essentials or Cyber Essentials Plus.
A practical readiness pack for the UK Cyber Essentials scheme. Walk through the five technical control themes and identify gaps before submitting the questionnaire or engaging a certification body.
Scope
Decide scope early — whole organisation or a specific sub-set. The scope declaration on the questionnaire must match what the assessor will actually look at. In-scope devices include all user endpoints, servers, mobile devices, and any cloud services the organisation administers.
1. Firewalls
- All internet-facing devices have a configured firewall (boundary or software)
- Default admin password on boundary firewalls has been changed
- Inbound firewall rules are documented and approved
- Unused inbound rules are disabled
- Admin interfaces on boundary firewalls are not exposed to the public internet
2. Secure configuration
- Default accounts are removed or renamed where possible
- Auto-run is disabled on removable media
- Unneeded services and software are removed from all devices
- Screen lock is enforced after 10 minutes or less
- Software inventory is maintained and reviewed
3. User access control
- Users have individual accounts — no shared accounts for business use
- Admin and standard accounts are separated — admin accounts not used for email/web browsing
- MFA is enforced for all cloud services and admin access
- Account provisioning and deprovisioning follows a documented process
- Privileged account review happens at least quarterly
4. Malware protection
- All in-scope devices have malware protection enabled (AV or EDR)
- Signatures or detection models update at least daily
- On-access scanning is enabled
- Scan on web content is enabled
- Untrusted software cannot run on user devices (allowlisting for CE Plus)
5. Patch management
- All operating systems and applications have vendor support (no end-of-life software in scope)
- High and critical patches are applied within 14 days of release
- Automatic updates are enabled where possible
- Firmware is kept up to date on network devices
- A process exists for emergency out-of-band patching
Common reasons for failure
- End-of-life software still in production (old Windows Server, PHP, Node)
- Admin accounts used for day-to-day work
- MFA missing on one or more cloud admin portals
- Patch window exceeds 14 days for critical CVEs
- BYOD devices in scope without matching controls
CyberZonic runs engagements that turn material like this into evidence.
If you need help scoping the work, turning this into a project plan, or running the assessment itself, get in touch.


