Free readiness check - Cyber Essentials

Cyber Essentials Self-Assessment: How to Tell If You Are Ready to Certify

Cyber Essentials begins with a self-assessment questionnaire to see where you stand against the current v3.3 standard. Our free quick check tool is designed to help you understand where your gaps are, so you can fix them before you apply.

  • Covers all five Cyber Essentials controls
  • Checked against the current v3.3 standard, in force since April 2026
  • Shows where your gaps are and what to fix first
  • Email the check to whoever runs your IT if you need help answering
Free readiness check

Check your Cyber Essentials readiness

Free Readiness Assessment

Cyber Essentials Readiness Assessment

Answer the readiness questions covering the five Cyber Essentials controls. If you need help with any answer, email this to your IT provider.

This assessment covers the key controls and gives a strong indication of your readiness. It does not guarantee a pass, but it will tell you exactly where you stand and what to address if there are gaps.

1 - Firewalls

Have you changed all default administrative passwords on your routers and firewalls?

Default passwords are published online and widely exploited. If you do not have an external firewall and rely on built-in laptop firewalls, you can answer yes.

Have your firewall rules been reviewed and documented in the last 12 months, with unnecessary rules removed?

Over-permissive or forgotten rules can expose services. If you have never changed the built-in firewall rules on your laptops, you can answer yes.

2 - Secure Configuration

Do you remove or disable unused accounts, software and services across all laptops, desktops, servers and mobile devices?

Unused software and dormant accounts widen your attack surface.

Does every device lock automatically, requiring a PIN, password or biometric to get back in?

An unlocked, unattended device is an open door to your systems and data.

3 - Security Update Management

Are operating system and firmware security updates applied within 14 days of release?

Attackers routinely exploit freshly disclosed vulnerabilities. The 14-day window is a hard Cyber Essentials requirement.

Are updates to third-party applications (browsers, messaging and VPN clients and similar) applied within 14 days?

Unpatched applications provide the same foothold as unpatched operating systems. The same 14-day rule applies.

4 - User Access Control

Does everyone with an admin account use it only when needed, not for everyday work?

Admin accounts have powerful permissions and should not be used for routine daily work.

Does everyone use a separate standard (non-admin) account for email and browsing?

Separating admin and standard duties limits the damage if a user account is compromised.

Is multi-factor authentication switched on for all cloud services, including email, SaaS tools and admin consoles?

Compromised accounts are the leading cause of breaches. MFA for all cloud services is mandatory under Cyber Essentials v3.3 and failing to enable it is an automatic fail.

Does every account have its own unique login, with no shared logins?

Shared accounts defeat accountability and auditing. Every user must have a unique identity.

5 - Malware Protection

Do all computers run up-to-date anti-malware software, or enforced application allow-listing?

Malware remains a primary cause of breaches. Built-in tools like Windows Defender are sufficient if kept up to date.

Are jailbroken or rooted mobile devices blocked from accessing business data and email?

Jailbroken or rooted mobile devices bypass important security controls and should not access business data.
Almost there

Where shall we send your report?

Your result appears on screen the moment you submit. We will also email your personalised report to the work email address you provide.

Please enter your name.
Please enter a valid work email address.
Please enter your organisation name.

Forensic Control will use your details to show your readiness result, store this assessment securely, and email your personalised Cyber Essentials Gap Analysis report. Your data is stored in the UK/EU and never sold to third parties.

We will email your personalised report to the work email address above.

Submission controls are loading. If this message remains, please refresh the page or use the contact link below.

The basics

What the Cyber Essentials self-assessment is

Cyber Essentials is a UK government-backed certification scheme. It is run by the IASME Consortium, the organisation the National Cyber Security Centre appoints to deliver it, and administered by certification bodies such as Forensic Control. The basic level is a self-assessment: you complete a questionnaire about your security controls and an assessor reviews it. Cyber Essentials Plus is the same five controls, verified by a hands-on technical audit rather than self-declared.

One term worth knowing early is scope: the set of devices and services your certificate covers. Part of getting ready is being clear about what is in it, because some things, cloud services in particular, can no longer be left out.

The questionnaire changed on 27 April 2026. The previous question set, called Willow, was replaced by a new set called Danzell, which reflects the tightened requirements in version 3.3 of the scheme. Anyone applying now completes the Danzell set. The five controls keep their names, but several of the things they require have changed.

The practical facts

What it costs and how long it takes

01

From £450 + VAT

a year for Cyber Essentials, renewed annually. Cyber Essentials Plus starts from £1,350.

02

1 to 3 working days

typical time to certify once your answers meet the standard.

03

No charge to resubmit

if something needs fixing, you correct it and resubmit at no extra cost.

The five controls

Where the gaps usually are

The self-assessment covers five technical controls. Here is what each one checks, and the gap we see most often when we assess against it.

01

Firewalls

You confirm that default administrative passwords on routers and firewalls have been changed, and that firewall rules have been reviewed and documented within the last year.

Common gap: The usual miss is the review: rules get added over time and rarely removed.

02

Secure configuration

You confirm that unused accounts, software and services have been removed, and that every device locks automatically behind a PIN, password or biometric.

Common gap: Dormant accounts left behind by former staff and pre-installed software nobody uses are the common gaps.

03

Security update management

Operating system, firmware and application updates that fix serious vulnerabilities must be applied within fourteen days.

Common gap: Third-party applications, browsers, messaging clients and VPN clients are where most organisations slip.

04

User access control

Administrator accounts must be used only when needed, every account must have unique credentials, and multi-factor authentication must be enabled on all cloud services.

Common gap: MFA not being rolled out to everyone is the v3.3 blocker most likely to fail an assessment.

05

Malware protection

Every device must run up-to-date anti-malware software or enforced application allow-listing, and jailbroken or rooted mobile devices must be kept away from business data.

Common gap: Mobile devices are often left out, or antivirus is assumed to be active when it is not enforced or updating.

What changed in 2026

The three v3.3 changes most likely to affect you

Version 3.3 kept the five controls but tightened three things. These are the ones worth checking first.
01

MFA is now an automatic fail

If a cloud service offers multi-factor authentication and you have not enabled it for every user, the assessment fails automatically. There is no remediation within that assessment cycle.

02

Patching covers more than patches

The fourteen-day deadline now applies to any vendor-recommended fix for a serious vulnerability, including configuration changes and scripts, not only downloadable updates.

03

Cloud services cannot be excluded

Any cloud tool that stores or processes your business data is in scope, regardless of who manages it.

Common questions

Cyber Essentials self-assessment FAQs

What is the Cyber Essentials self-assessment?
Can you self-certify Cyber Essentials?
What happens if I fail the assessment?
How much does Cyber Essentials cost?
How do I get Cyber Essentials certified?
What are the five Cyber Essentials controls?
Is Cyber Essentials a legal requirement?
Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.