Is there a Cyber Essentials checklist?

The following checklist applies to both Cyber Essentials and Cyber Essentials Plus requirements, the difference being that with the latter a technical expert conducts a vulnerability scan and remote audit of your IT systems, including a representative set of user devices, all Internet gateways and all servers with services accessible to unauthenticated Internet users.

The questions that will need to be answered include:

  • Are all of your operating systems supported including phones, tablets, servers, workstations etc…?
  • Have all the security patches been applied to the operating systems?
  • Is your Office suite up to date? Is your anti-malware up to date?
  • Are your browsers up to date with security patches?
  • Have you disabled auto-run?
  • Have you disabled remote scripts from being run?
  • Are all of your applications up to date with security patches?
  • Are all the applications used in the organisation supported?
I would like to thank URM’s assessor for such a pleasurable experience of going through an assessment! He made the whole experience pain free, clear, and transparent, and enjoyable. Also grateful for the expert guidance our URM Account Manager provided to us.
Digital solutions provider
Apply for Cyber Essentials certificationApply for Cyber Essentials Plus

Mitigating Cyber Risks: Why Cyber Essentials Matters More Than Ever

Published on
16 Apr
2026

URM’s blog highlights the growing threat to cyber security in the UK and the importance of the Cyber Essentials scheme in mitigating these risks.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/4/2026
Cyber Essentials Requirements Update

URM’s blog breaks down the latest changes to the Cyber Essentials requirements and outlines why these updates matter for organisations seeking certification.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/4/2026
Cyber Essentials Update 2026

URM’s blog breaks down key changes to the Cyber Essentials scheme coming into force on 27 April 2026, including the new Danzell Question Set.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
9/4/2026
NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
"
It was a pleasure working with URM’s consultant today and we were impressed with his technical knowledge and the thoroughness of the Audit.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.