Is there a Cyber Essentials checklist?

The following checklist applies to both Cyber Essentials and Cyber Essentials Plus requirements, the difference being that with the latter a technical expert conducts a vulnerability scan and remote audit of your IT systems, including a representative set of user devices, all Internet gateways and all servers with services accessible to unauthenticated Internet users.

The questions that will need to be answered include:

  • Are all of your operating systems supported including phones, tablets, servers, workstations etc…?
  • Have all the security patches been applied to the operating systems?
  • Is your Office suite up to date? Is your anti-malware up to date?
  • Are your browsers up to date with security patches?
  • Have you disabled auto-run?
  • Have you disabled remote scripts from being run?
  • Are all of your applications up to date with security patches?
  • Are all the applications used in the organisation supported?
Our experience with URM was all around great and seamless, starting with our account manager who organised everything and was very accommodating, working around our schedule and fitting us in as soon as we wanted. This continued with our assessor for the CE questionnaire part; he was very helpful, taking the time to explain some aspects that were a bit unclear to me and guiding me the whole way through. The same was true of our assessor for the CE+, who took the time to answer any questions I had beforehand and guide me through elements that I was unfamiliar with. During the assessment, he was very helpful, made the process very easy and guided me through some points that needed some additional set up in order to ensure a successful process. This was our first year working with URM and I am sure we’ll be talking again next year. Thank you for all your help!
IT Security Services Provider
Apply for Cyber Essentials certificationApply for Cyber Essentials Plus

Cyber Essentials Update 2026

Published on
26 Mar
2026

URM’s blog breaks down key changes to the Cyber Essentials scheme coming into force on 27 April 2026, including the new Danzell Question Set.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
11/3/2026
Cyber Security and the Board: A Sign of What’s to Come

URM’s blog explains recent amendments to the Cyber Security and Resilience Bill, how they align with broader regulatory shifts, & practical steps to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/2/2026
NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
19/1/2026
Minimising the Impact When a Breach Occurs

URM’s blog explores the importance of cyber resilience & the steps organisations can take to prepare for and mitigate the impact of a cyber incident.

Read more
"
The feedback on URM’s report was that it was the best document the developer had ever received due to it being so concise and clear. He has saved it on his desktop and suggested that the business should use a similar template for internal docs. This great feedback reflects not only on the URM penetration tester who conducted the test, but also on the senior members of URM’s Cyber Team for all the work they have put in to producing such a brilliant reporting template.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.