Is there a Cyber Essentials checklist?

The following checklist applies to both Cyber Essentials and Cyber Essentials Plus requirements, the difference being that with the latter a technical expert conducts a vulnerability scan and remote audit of your IT systems, including a representative set of user devices, all Internet gateways and all servers with services accessible to unauthenticated Internet users.

The questions that will need to be answered include:

  • Are all of your operating systems supported including phones, tablets, servers, workstations etc…?
  • Have all the security patches been applied to the operating systems?
  • Is your Office suite up to date? Is your anti-malware up to date?
  • Are your browsers up to date with security patches?
  • Have you disabled auto-run?
  • Have you disabled remote scripts from being run?
  • Are all of your applications up to date with security patches?
  • Are all the applications used in the organisation supported?
URM’s in-depth knowledge of cybersecurity best practices and the Cyber Essentials framework helped us strengthen both ours and our client’s security posture while ensuring full compliance. Their consultants were professional, approachable, and incredibly thorough, offering practical advice tailored to the specific needs. The Cyber Essentials Plus assessment was conducted with great efficiency, and URM’s supportive approach meant we felt well-prepared at every stage. Thanks to their expertise, we successfully achieved certification for us and our clients, giving us (and our clients) greater confidence in our cybersecurity resilience.
IT support company
Apply for Cyber Essentials certificationApply for Cyber Essentials Plus

NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

Published on
16 Feb
2026

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
19/1/2026
Minimising the Impact When a Breach Occurs

URM’s blog explores the importance of cyber resilience & the steps organisations can take to prepare for and mitigate the impact of a cyber incident.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
9/1/2026
Strengthening Your Cyber Defences: Practical Steps for Every Business

URM’s blog explores common weaknesses in organisations’ security programmes, & outlines practical, cost-effective measures to reduce the likelihood of a breach

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
18/12/2025
Deconstructing the EU Cyber Resilience Act

URM’s blog breaks down the new EU Cyber Resilience Act, what products/entities are in scope, the security requirements it imposes on organisations, and more.

Read more
"
Our assessor made our CE Plus assessment smooth and easy. We are going back to URM for our CE Plus this year
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.