Free Cyber Essentials Readiness Self-Assessment

Fifteen plain English questions covering all five Cyber Essentials technical controls. Answer honestly and get an instant breakdown of where you stand -- and what needs to change before you submit for formal certification.

This is an informal self-assessment, not the official IASME questionnaire. It does not represent, replace or guarantee the outcome of a formal Cyber Essentials assessment.

The five Cyber Essentials technical controls

Cyber Essentials is built around five controls that address the most common ways organisations are compromised online. Certification requires all five to be in place, for all devices and users within your defined scope.

  1. Firewalls -- protect the boundary between your network and the internet, and ensure each device connecting to the internet has a correctly configured firewall.
  2. Secure configuration -- devices and software must be set up securely: default credentials changed, unnecessary features removed, and users running with the minimum access needed.
  3. Security update management -- all software, operating systems and firmware must be kept up to date. Critical and high-severity updates must be applied within 14 days of release, and no unsupported software may be in use.
  4. User access control -- every user must have their own named account with least-privilege permissions. Multi-factor authentication must be enabled on all cloud services and remote access.
  5. Malware protection -- all in-scope devices must have active, up-to-date malware protection that scans automatically.

The full requirements document is published by IASME and covers every control in detail, including what counts as in-scope and what evidence assessors expect.

Frequently asked questions

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme managed by IASME on behalf of the NCSC. It covers five technical controls and is designed to protect organisations against the most common internet-based threats. There are two levels: Cyber Essentials (self-assessed with independent verification) and Cyber Essentials Plus (self-assessed plus an independent technical audit). More information is available from the NCSC.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials requires you to complete a structured self-assessment questionnaire, signed off by a board-level signatory, which is then reviewed by an independent assessor. Cyber Essentials Plus includes everything in Cyber Essentials plus a hands-on technical audit where an independent assessor verifies that your controls are actually in place. You cannot go straight to Plus -- you need a current Cyber Essentials certificate first, and the Plus audit must be completed within three months of that certification date. Plus carries more weight with larger buyers and is required for some government contracts.

How much does Cyber Essentials certification cost?

Cyber Essentials self-assessment fees start from £320 plus VAT for small organisations, with the cost scaling with organisation size. Cyber Essentials Plus costs more because it includes a technical audit. You may also pay for external support to prepare, which varies depending on how much remediation your environment needs.

How long does Cyber Essentials certification take?

For most small businesses, the process from initial gap assessment to receiving certification takes two to four weeks, depending on how much remediation is needed. If your controls are already close to compliant, it can be faster. Certification is valid for twelve months and must be renewed annually.

What happens if an organisation fails the Cyber Essentials assessment?

If you fail, your assessor will identify the specific controls that are not compliant. You can then remediate those gaps and resubmit. The most common reasons for failure are missing multi-factor authentication on cloud services, out-of-date or unsupported software, and incomplete coverage of devices within scope.

Ready to get certified?

Our team guides UK businesses through the full Cyber Essentials process -- gap assessment, remediation support and certification submission -- with CREST-certified expertise throughout.

Our Cyber Essentials Service

Also free: our Website & Email Security Checker, Password Strength & Breach Checker and Phishing Awareness Quiz -- no signup required for any of them.