Cyber Security
What Does Cyber Essentials Actually Require?
Cyber Essentials is built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Here's what each one actually means in plain English.
FNS Team · 5 min read · Updated September 2026
Cyber Essentials requires five technical controls to be in place: boundary firewalls, secure configuration, security update (patch) management, user access control, and malware protection. Between them, they cover the basic ways most cyber attacks actually get in.
Cyber Essentials was set up by the UK government, and is administered on the NCSC's behalf by certification bodies including IASME, specifically to address the fact that the vast majority of successful cyber attacks against small and medium businesses exploit basic, avoidable weaknesses rather than sophisticated techniques. The scheme deliberately doesn't try to cover everything — it focuses on five areas that, done properly, close off most of the common routes in.
If you're deciding between the two levels of certification, our companion article on Cyber Essentials vs Cyber Essentials Plus explains how they're assessed differently. This one focuses on what the five controls actually mean.
1. Firewalls
Every device and network needs a properly configured boundary firewall (or equivalent network device) sitting between it and the internet. In practice, for most SMEs, this means:
- The router/firewall provided by your internet connection or IT provider has default administrative passwords changed.
- Unnecessary inbound services aren't left open to the internet.
- Software firewalls are enabled on individual devices, particularly laptops that travel outside the office network — for example Windows Defender Firewall or the macOS firewall.
A common mistake here is leaving factory default passwords on routers, or opening ports "temporarily" for a specific need and never closing them again.
2. Secure configuration
This is about not leaving systems in an insecure "out of the box" state. Cyber Essentials expects you to:
- Remove or disable software, apps and services you don't actually use.
- Change default passwords on all devices and accounts.
- Disable auto-run features that let removable media execute code automatically.
- Use a password, PIN or biometric lock on every device.
In our experience, this is one of the areas where quick wins are easiest — most of it is about tidying up settings that were never changed after a device was set up, rather than buying anything new.
3. Security update (patch) management
All software and firmware in scope needs to be kept up to date, specifically:
- Only using software that's still supported by its vendor (no unsupported operating systems or applications with known unpatched vulnerabilities).
- Applying security updates within defined timescales — Cyber Essentials expects "critical" and "high risk" updates applied promptly, generally within 14 days of release, though you should check current requirements on ncsc.gov.uk as the scheme's requirements documents are reviewed periodically.
- Removing software once it's reached end of life and a vendor no longer issues security updates.
This is one of the areas Cyber Essentials Plus tests most rigorously, because it's easy to believe updates are current and be wrong.
4. User access control
This control is about making sure people only have the access they genuinely need, and that accounts are properly managed:
- Each user has their own account — no shared logins.
- Accounts are created through a proper process, and removed promptly when someone leaves.
- Administrator-level access is only given to those who need it, and used only when needed (not for day-to-day work).
- Strong, unique passwords or passphrases are used, ideally backed by multi-factor authentication (MFA) wherever it's available — something that's increasingly a specific requirement within the scheme, so it's worth checking the latest question set.
A worked example: a small firm where every member of staff has logged into the same generic "Reception PC" account for years, with a password nobody can quite remember choosing, is a classic Cyber Essentials failure point — there's no way to know who did what, and no way to revoke access for one leaver without disrupting everyone else.
5. Malware protection
Finally, devices need protection against malicious software. Cyber Essentials generally accepts either:
- Anti-malware software (such as Microsoft Defender, which comes built into Windows) kept up to date and actively scanning, or
- Application allow-listing, where only specifically approved software is permitted to run, or
- Running software in isolated sandboxed environments.
Most SMEs meet this through built-in or endpoint protection tools rather than allow-listing, which suits environments with tightly controlled software use. Whether the built-in option alone is sufficient for your risk level is a separate question — we cover that in Is Microsoft Defender enough for a small business?
Putting it together
| Control | Plain-English meaning |
|---|---|
| Firewalls | Lock the front door of your network |
| Secure configuration | Don't leave settings on "default" or unused features switched on |
| Security update management | Keep software patched and retire what's no longer supported |
| User access control | Right people, right access, nothing more |
| Malware protection | Keep malicious software off your devices |
Common mistakes we see
- Treating Cyber Essentials as a one-off project rather than an ongoing standard to maintain.
- Assuming a firewall from years ago, never reviewed, is "good enough."
- Forgetting mobile devices and laptops used outside the office are still in scope.
- Not having a leaver process, so ex-employees' accounts linger with access long after they've gone.
- Believing antivirus alone covers every requirement, when configuration and patching matter just as much.
Getting ready in practice
- Inventory every device, account and piece of software that would fall in scope.
- Work through each of the five controls and note gaps honestly — this is where a second pair of eyes from an IT provider is genuinely useful.
- Fix the gaps (changing defaults and removing unused software is often quick; patch and account hygiene processes take a bit longer to bed in).
- Complete the self-assessment questionnaire, or arrange a Plus audit if that's the level you need.
- Keep the controls in place year-round, not just before renewal.
Related questions
- Cyber Essentials vs Cyber Essentials Plus: what's the difference?
- Is Microsoft Defender enough for a small business?
- How much should managed IT support cost in the UK?
If working through the five controls feels daunting, that's what we're here for. Our Cyber Security team helps SMEs get Cyber Essentials-ready as part of day-to-day Managed IT support — get in touch to find out where you stand.


