Cyber Insurance Subjectivity Tracker

Rules

Core list: United Kingdom

UK Cyber Essentials (Requirements for IT Infrastructure v3.3)

The core list for the United Kingdom: the government-backed baseline scheme. The test steps of Cyber Essentials Plus are not used.

edition NCSC Cyber Essentials: Requirements for IT Infrastructure v3.3, the copy we hold. 24 requirements cited here. Every Cyber Essentials clause we hold.

Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
CE-SC.6
Cyber Essentials
Multi-Factor Authentication for Cloud Services

MFA must be applied to all administrative accounts on cloud services and to all user accounts on cloud services where supported by the provider.

evidence an assessor asks for Identity provider conditional access policy requiring multi-factor authentication; Cloud office suite report of two-step verification enrolment; Cloud platform report of multi-factor authentication on each account

Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
CE-AC.7
Cyber Essentials
MFA for Administrative Accounts

Multi-factor authentication must be enabled for all administrative accounts on cloud services and where technically feasible on internal systems.

evidence an assessor asks for MFA enrolment per admin; Conditional Access policy targeting admin roles; PAM enforcement

The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)

ClauseThe held text, and the evidence an assessor asks for
CE-AC.8
Cyber Essentials
Passwordless Authentication

Where identity is established without a password, use a recognised passwordless method such as a FIDO2 authenticator or passkey, biometric, hardware security key or token, push notification or one-time code, and manage it as the authentication control for the account.

evidence an assessor asks for list of accounts using passwordless authentication and the method in use; authenticator registration and revocation records; policy statement covering accepted passwordless methods

Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement

ClauseThe held text, and the evidence an assessor asks for
CE-SU.3
Cyber Essentials
Critical and High Updates within 14 Days

All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.

The requirement's own words: within 14 days of release

evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register

CE-SU.5
Cyber Essentials
Firmware Updates

Firmware on routers, firewalls and other in-scope network devices must be kept current. Firmware is treated as software for update purposes.

evidence an assessor asks for network device firmware report; vendor advisory subscription; firmware change tickets

Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement

ClauseThe held text, and the evidence an assessor asks for
CE-SU.2
Cyber Essentials
Automatic Updates Enabled Where Possible

Automatic updates must be enabled on devices and software where the option exists, to ensure security updates are applied without delay.

evidence an assessor asks for Operating system automatic update policy; Automatic update setting on each desktop operating system; Update management or device management configuration

CE-SU.3
Cyber Essentials
Critical and High Updates within 14 Days

All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.

The requirement's own words: within 14 days of release

evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register

Other business applications are patched within the timeframe in the requirement

ClauseThe held text, and the evidence an assessor asks for
CE-SU.3
Cyber Essentials
Critical and High Updates within 14 Days

All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.

The requirement's own words: within 14 days of release

evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register

Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed

ClauseThe held text, and the evidence an assessor asks for
CE-SU.1
Cyber Essentials
Software Licensed and Supported

All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.

evidence an assessor asks for Software inventory from the device management tool; EOL/EOSL register; segregation evidence for unsupported

CE-SU.4
Cyber Essentials
Remove Out-of-Support Software

Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network.

evidence an assessor asks for EOL removal log; segregated VLAN evidence; compensating control documentation

Administrators use a separate privileged account and environment for admin work only, with no internet or email on it

ClauseThe held text, and the evidence an assessor asks for
CE-AC.5
Cyber Essentials
Separate Admin Accounts for Administrative Activities

Use separate accounts to perform administrative activities only. Admin accounts must not be used for routine activities like email and web browsing.

evidence an assessor asks for named admin accounts (e.g. adm-jdoe); conditional access blocking email/web for admin accounts

Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked

ClauseThe held text, and the evidence an assessor asks for
CE-AC.4
Cyber Essentials
Privileged Account Approval and Tracking

Implement an approval process and keep track of privileged (administrative) accounts. The granting of privileges must be controlled.

evidence an assessor asks for list of all admin accounts with owner; approval records; PAM tool inventory

Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated

ClauseThe held text, and the evidence an assessor asks for
CE-AC.6
Cyber Essentials
Periodic Review of Privileged Access

Review user accounts with special access privileges on a regular basis and remove or downgrade where no longer needed.

evidence an assessor asks for quarterly admin review records; access review attestation; removed/downgraded log

Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed

ClauseThe held text, and the evidence an assessor asks for
CE-SC.2
Cyber Essentials
Change Default Passwords on Devices and Software

Change any default passwords on devices and software before deployment, or remove the account if not needed.

evidence an assessor asks for deployment checklist; credential vault entries; no-default attestation

CE-FW.2
Cyber Essentials
Change Default Firewall Passwords

Change all default administrative passwords on boundary firewalls to a non-guessable password, or disable remote admin access entirely.

evidence an assessor asks for admin account list; password change log/attestation; config snapshot

Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders

ClauseThe held text, and the evidence an assessor asks for
CE-MP.4
Cyber Essentials
Application Allowlisting (Alternative)

Where allowlisting is used instead of AV, only approved applications (signed or hash-listed) can execute. List must be actively maintained.

evidence an assessor asks for WDAC/AppLocker policy; allowlist register; exception process

Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed

ClauseThe held text, and the evidence an assessor asks for
CE-SC.1
Cyber Essentials
Remove or Disable Unused Software

Remove or disable unnecessary user accounts, software, and services on devices to reduce the attack surface.

evidence an assessor asks for gold image documentation; installed software inventory; disabled services list

Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted

ClauseThe held text, and the evidence an assessor asks for
CE-SC.3
Cyber Essentials
Disable Auto-Run Features

Disable auto-run or auto-play features that automatically execute code without user authorisation on removable media or network shares.

evidence an assessor asks for AutoPlay disabled GPO export; Device management policy screenshot

Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)

ClauseThe held text, and the evidence an assessor asks for
CE-MP.1
Cyber Essentials
Anti-Malware Software Deployed

Implement anti-malware on all in-scope devices: anti-malware software (signature/heuristic), application allowlisting, or sandboxing of untrusted code.

evidence an assessor asks for AV/EDR console inventory vs asset list; coverage percentage report

CE-MP.2
Cyber Essentials
Anti-Malware Signatures Updated

Where anti-malware software is used, it must be kept up to date with the latest signatures and engine updates.

evidence an assessor asks for AV signature age report; out-of-date device list with remediation

CE-MP.3
Cyber Essentials
Anti-Malware Scans Files on Access and Web Pages

Anti-malware software must scan files automatically on access, scan web pages when accessed, and prevent connections to malicious websites.

evidence an assessor asks for on-access scan policy; web protection enabled screenshot; SafeBrowsing/SmartScreen evidence

Staff are trained to recognise phishing and other social engineering, and to report a suspected incident

ClauseThe held text, and the evidence an assessor asks for
CE-SC.7
Cyber Essentials
Educate Users on Strong Passwords

Educate users to avoid common, predictable, or compromised passwords and on the importance of unique passwords per account.

evidence an assessor asks for password guidance document; training attendance log; phishing/password module evidence

Every device sits behind a correctly configured boundary or host firewall, with inbound rules signed off and unused rules removed

ClauseThe held text, and the evidence an assessor asks for
CE-FW.1
Cyber Essentials
Boundary Firewalls Deployed

Every device in scope must be protected by a correctly configured firewall (or network device with firewall functionality) at the boundary of the internet connection.

evidence an assessor asks for firewall device list; topology diagram showing boundary; rule base export

CE-FW.4
Cyber Essentials
Approve and Document Inbound Rules

Every inbound firewall rule that permits traffic must be approved and documented by an authorised individual with documented business need.

evidence an assessor asks for firewall change tickets; rule register with owner/justification; approval workflow evidence

CE-FW.5
Cyber Essentials
Remove or Disable Unused Rules

Remove or disable permissive firewall rules promptly when no longer required to limit attack surface.

evidence an assessor asks for periodic firewall rule review records; disabled/removed rule log

CE-FW.6
Cyber Essentials
Host-Based Firewall for Remote Workers

Where devices are used on untrusted networks (home, public Wi-Fi), the host-based software firewall must be enabled and configured.

evidence an assessor asks for endpoint firewall policy; MDM compliance report; sample screenshots

Questions

When does Cyber Essentials apply here?
The core list for the United Kingdom: the government-backed baseline scheme. The test steps of Cyber Essentials Plus are not used.
Which edition is held?
NCSC Cyber Essentials: Requirements for IT Infrastructure v3.3, the copy we hold
Is a gap against it a finding about the business?
No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.