FNS
guide · 17 September 2026

What Does Cyber Essentials Actually Require?

Cyber Essentials is built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Here's what each one actually means in plain English.

Cyber Essentials requires five technical controls to be in place: boundary firewalls, secure configuration, security update (patch) management, user access control, and malware protection. Between them, they cover the basic ways most cyber attacks actually get in.

Cyber Essentials was set up by the UK government, and is administered on the NCSC's behalf by certification bodies including IASME, specifically to address the fact that the vast majority of successful cyber attacks against small and medium businesses exploit basic, avoidable weaknesses rather than sophisticated techniques. The scheme deliberately doesn't try to cover everything — it focuses on five areas that, done properly, close off most of the common routes in.

If you're deciding between the two levels of certification, our companion article on Cyber Essentials vs Cyber Essentials Plus explains how they're assessed differently. This one focuses on what the five controls actually mean.

1. Firewalls

Every device and network needs a properly configured boundary firewall (or equivalent network device) sitting between it and the internet. In practice, for most SMEs, this means:

A common mistake here is leaving factory default passwords on routers, or opening ports "temporarily" for a specific need and never closing them again.

2. Secure configuration

This is about not leaving systems in an insecure "out of the box" state. Cyber Essentials expects you to:

In our experience, this is one of the areas where quick wins are easiest — most of it is about tidying up settings that were never changed after a device was set up, rather than buying anything new.

3. Security update (patch) management

All software and firmware in scope needs to be kept up to date, specifically:

This is one of the areas Cyber Essentials Plus tests most rigorously, because it's easy to believe updates are current and be wrong.

4. User access control

This control is about making sure people only have the access they genuinely need, and that accounts are properly managed:

A worked example: a small firm where every member of staff has logged into the same generic "Reception PC" account for years, with a password nobody can quite remember choosing, is a classic Cyber Essentials failure point — there's no way to know who did what, and no way to revoke access for one leaver without disrupting everyone else.

5. Malware protection

Finally, devices need protection against malicious software. Cyber Essentials generally accepts either:

Most SMEs meet this through built-in or endpoint protection tools rather than allow-listing, which suits environments with tightly controlled software use. Whether the built-in option alone is sufficient for your risk level is a separate question — we cover that in Is Microsoft Defender enough for a small business?

Putting it together

| Control | Plain-English meaning |
|---|---|
| Firewalls | Lock the front door of your network |
| Secure configuration | Don't leave settings on "default" or unused features switched on |
| Security update management | Keep software patched and retire what's no longer supported |
| User access control | Right people, right access, nothing more |
| Malware protection | Keep malicious software off your devices |

Common mistakes we see

Getting ready in practice

  1. Inventory every device, account and piece of software that would fall in scope.
  2. Work through each of the five controls and note gaps honestly — this is where a second pair of eyes from an IT provider is genuinely useful.
  3. Fix the gaps (changing defaults and removing unused software is often quick; patch and account hygiene processes take a bit longer to bed in).
  4. Complete the self-assessment questionnaire, or arrange a Plus audit if that's the level you need.
  5. Keep the controls in place year-round, not just before renewal.

Related questions

If working through the five controls feels daunting, that's what we're here for. Our Cyber Security team helps SMEs get Cyber Essentials-ready as part of day-to-day Managed IT support — get in touch to find out where you stand.