UK Cyber Essentials (Requirements for IT Infrastructure v3.3)
The core list for the United Kingdom: the government-backed baseline scheme. The test steps of Cyber Essentials Plus are not used.
edition NCSC Cyber Essentials: Requirements for IT Infrastructure v3.3, the copy we hold. 24 requirements cited here. Every Cyber Essentials clause we hold.
Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.6 Cyber Essentials | Multi-Factor Authentication for Cloud Services MFA must be applied to all administrative accounts on cloud services and to all user accounts on cloud services where supported by the provider. evidence an assessor asks for Identity provider conditional access policy requiring multi-factor authentication; Cloud office suite report of two-step verification enrolment; Cloud platform report of multi-factor authentication on each account |
Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-AC.7 Cyber Essentials | MFA for Administrative Accounts Multi-factor authentication must be enabled for all administrative accounts on cloud services and where technically feasible on internal systems. evidence an assessor asks for MFA enrolment per admin; Conditional Access policy targeting admin roles; PAM enforcement |
The multi-factor authentication staff use is phishing-resistant (security keys or passkeys rather than codes)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-AC.8 Cyber Essentials | Passwordless Authentication Where identity is established without a password, use a recognised passwordless method such as a FIDO2 authenticator or passkey, biometric, hardware security key or token, push notification or one-time code, and manage it as the authentication control for the account. evidence an assessor asks for list of accounts using passwordless authentication and the method in use; authenticator registration and revocation records; policy statement covering accepted passwordless methods |
Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SU.3 Cyber Essentials | Critical and High Updates within 14 Days All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release. The requirement's own words: within 14 days of release evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register |
| CE-SU.5 Cyber Essentials | Firmware Updates Firmware on routers, firewalls and other in-scope network devices must be kept current. Firmware is treated as software for update purposes. evidence an assessor asks for network device firmware report; vendor advisory subscription; firmware change tickets |
Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SU.2 Cyber Essentials | Automatic Updates Enabled Where Possible Automatic updates must be enabled on devices and software where the option exists, to ensure security updates are applied without delay. evidence an assessor asks for Operating system automatic update policy; Automatic update setting on each desktop operating system; Update management or device management configuration |
| CE-SU.3 Cyber Essentials | Critical and High Updates within 14 Days All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release. The requirement's own words: within 14 days of release evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register |
Other business applications are patched within the timeframe in the requirement
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SU.3 Cyber Essentials | Critical and High Updates within 14 Days All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release. The requirement's own words: within 14 days of release evidence an assessor asks for patch compliance dashboard from the patch or vulnerability management tool; 14-day SLA report; exception register |
Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SU.1 Cyber Essentials | Software Licensed and Supported All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated. evidence an assessor asks for Software inventory from the device management tool; EOL/EOSL register; segregation evidence for unsupported |
| CE-SU.4 Cyber Essentials | Remove Out-of-Support Software Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network. evidence an assessor asks for EOL removal log; segregated VLAN evidence; compensating control documentation |
Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-AC.5 Cyber Essentials | Separate Admin Accounts for Administrative Activities Use separate accounts to perform administrative activities only. Admin accounts must not be used for routine activities like email and web browsing. evidence an assessor asks for named admin accounts (e.g. adm-jdoe); conditional access blocking email/web for admin accounts |
Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-AC.4 Cyber Essentials | Privileged Account Approval and Tracking Implement an approval process and keep track of privileged (administrative) accounts. The granting of privileges must be controlled. evidence an assessor asks for list of all admin accounts with owner; approval records; PAM tool inventory |
Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-AC.6 Cyber Essentials | Periodic Review of Privileged Access Review user accounts with special access privileges on a regular basis and remove or downgrade where no longer needed. evidence an assessor asks for quarterly admin review records; access review attestation; removed/downgraded log |
Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.2 Cyber Essentials | Change Default Passwords on Devices and Software Change any default passwords on devices and software before deployment, or remove the account if not needed. evidence an assessor asks for deployment checklist; credential vault entries; no-default attestation |
| CE-FW.2 Cyber Essentials | Change Default Firewall Passwords Change all default administrative passwords on boundary firewalls to a non-guessable password, or disable remote admin access entirely. evidence an assessor asks for admin account list; password change log/attestation; config snapshot |
Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-MP.4 Cyber Essentials | Application Allowlisting (Alternative) Where allowlisting is used instead of AV, only approved applications (signed or hash-listed) can execute. List must be actively maintained. evidence an assessor asks for WDAC/AppLocker policy; allowlist register; exception process |
Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.1 Cyber Essentials | Remove or Disable Unused Software Remove or disable unnecessary user accounts, software, and services on devices to reduce the attack surface. evidence an assessor asks for gold image documentation; installed software inventory; disabled services list |
Office and PDF software are hardened, blocked from creating child processes and executable content, users cannot change their security settings, and old scripting runtimes are removed or restricted
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.3 Cyber Essentials | Disable Auto-Run Features Disable auto-run or auto-play features that automatically execute code without user authorisation on removable media or network shares. evidence an assessor asks for AutoPlay disabled GPO export; Device management policy screenshot |
Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-MP.1 Cyber Essentials | Anti-Malware Software Deployed Implement anti-malware on all in-scope devices: anti-malware software (signature/heuristic), application allowlisting, or sandboxing of untrusted code. evidence an assessor asks for AV/EDR console inventory vs asset list; coverage percentage report |
| CE-MP.2 Cyber Essentials | Anti-Malware Signatures Updated Where anti-malware software is used, it must be kept up to date with the latest signatures and engine updates. evidence an assessor asks for AV signature age report; out-of-date device list with remediation |
| CE-MP.3 Cyber Essentials | Anti-Malware Scans Files on Access and Web Pages Anti-malware software must scan files automatically on access, scan web pages when accessed, and prevent connections to malicious websites. evidence an assessor asks for on-access scan policy; web protection enabled screenshot; SafeBrowsing/SmartScreen evidence |
Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-SC.7 Cyber Essentials | Educate Users on Strong Passwords Educate users to avoid common, predictable, or compromised passwords and on the importance of unique passwords per account. evidence an assessor asks for password guidance document; training attendance log; phishing/password module evidence |
Every device sits behind a correctly configured boundary or host firewall, with inbound rules signed off and unused rules removed
| Clause | The held text, and the evidence an assessor asks for |
|---|---|
| CE-FW.1 Cyber Essentials | Boundary Firewalls Deployed Every device in scope must be protected by a correctly configured firewall (or network device with firewall functionality) at the boundary of the internet connection. evidence an assessor asks for firewall device list; topology diagram showing boundary; rule base export |
| CE-FW.4 Cyber Essentials | Approve and Document Inbound Rules Every inbound firewall rule that permits traffic must be approved and documented by an authorised individual with documented business need. evidence an assessor asks for firewall change tickets; rule register with owner/justification; approval workflow evidence |
| CE-FW.5 Cyber Essentials | Remove or Disable Unused Rules Remove or disable permissive firewall rules promptly when no longer required to limit attack surface. evidence an assessor asks for periodic firewall rule review records; disabled/removed rule log |
| CE-FW.6 Cyber Essentials | Host-Based Firewall for Remote Workers Where devices are used on untrusted networks (home, public Wi-Fi), the host-based software firewall must be enabled and configured. evidence an assessor asks for endpoint firewall policy; MDM compliance report; sample screenshots |
Questions
- When does Cyber Essentials apply here?
- The core list for the United Kingdom: the government-backed baseline scheme. The test steps of Cyber Essentials Plus are not used.
- Which edition is held?
- NCSC Cyber Essentials: Requirements for IT Infrastructure v3.3, the copy we hold
- Is a gap against it a finding about the business?
- No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.