Phone us
Cyber Essentials is now a recognised benchmark for UK businesses that want to demonstrate good cyber hygiene, reassure customers, meet supply chain expectations, and prepare for public sector or regulated-sector requirements.

But many SMEs only discover gaps when they begin the assessment — missing MFA, unsupported software, unmanaged devices, weak administrator controls, or unclear cloud security responsibilities.

Use this checklist to assess whether your business is ready for Cyber Essentials or Cyber Essentials Plus in 2026.

Can your business answer “yes” to these key areas?

Assessment Scope
  • Have you identified all laptops, desktops, mobiles, tablets and servers used for business?
  • Are remote and hybrid working devices included?
  • Do any BYOD devices access company data or services?
  • Have you listed all cloud services, including email, file storage, CRM, finance and collaboration tools?
  • Do you know which systems are managed internally and which are managed by a third party or IT provider?
Firewalls & Internet Gateways
  • Is every device protected by a firewall?
  • Have default administrator passwords been changed?
  • Are unnecessary firewall rules removed?
  • Is remote access properly controlled?
  • Are unused or insecure services blocked?
Secure Configuration
  • Have unnecessary applications, services and accounts been removed?
  • Are default settings changed where required?
  • Are laptops, desktops, mobiles, servers and cloud services securely configured?
  • Are administrator accounts limited to those who genuinely need them?
  • Are configuration standards reviewed regularly?
Security Update Management
  • Are all operating systems and applications still supported?
  • Are critical and high-risk updates applied promptly?
  • Are unsupported devices or applications removed or replaced?
  • Are updates managed across remote and hybrid working devices?
  • Is there a clear process for checking patch compliance?
User Access Controls
  • Are user accounts reviewed regularly?
  • Are leavers removed promptly?
  • Are inactive or unused accounts disabled?
  • Do users only have access to what they need?
  • Are administrator privileges tightly controlled?
Multi-Factor Authentication
  • Is MFA enabled for email accounts?
  • Is MFA enabled across cloud services such as Microsoft 365, Google Workspace, CRM, file sharing and finance platforms?
  • Are administrator accounts protected with MFA?
  • Are shared accounts avoided wherever possible?
  • Have you checked whether any cloud service requires a licence upgrade to enable MFA?
Malware Protection
  • Is endpoint protection active across all devices?
  • Are anti-malware tools kept up to date?
  • Are laptops, desktops and remote devices protected?
  • Are alerts monitored and acted on?
  • Are mobile and cloud environments considered where relevant?
Preparing for Cyber Essentials Plus

Cyber Essentials Plus goes beyond the self-assessment and includes independent technical verification of your controls. Before booking Cyber Essentials Plus, your organisation should check that:

  • Devices are patched and ready for testing
  • Unsupported software has been removed
  • Malware protection is active and updated
  • MFA is enabled where required
  • Remote and hybrid devices are included in preparation
  • Vulnerability issues are reviewed before assessment day
  • Internal teams know what access and evidence may be needed

Download the full Cyber Essentials 2026 Readiness Checklist.

Use the checklist to identify gaps before starting your Cyber Essentials or Cyber Essentials Plus assessment.

Download the full Cyber Essentials 2026 Readiness Checklist

    By submitting this form you are consenting to receiving our monthly newsletter. Your data will be handled in accordance with our Privacy Policy and we will be in touch regarding your enquiry.

     

    Final Thoughts

    Cyber Essentials is no longer viewed as simply a compliance requirement. It has become a recognised benchmark for demonstrating strong baseline cybersecurity controls and building trust with customers, suppliers, and stakeholders.

    Businesses that review their security posture early will be in a stronger position to achieve certification and improve resilience throughout 2026.

    At A Jolly Consulting, we support organisations with Cyber Essentials and Cyber Essentials Plus readiness, helping businesses prepare for certification with practical and effective cybersecurity guidance.

    Please contact us on 020 7101 4861 email us info@ajollyconsulting.co.uk  if you think we can help.

     

     

    Image accreditation: Philipp Katzenberger (January 2019) from Unsplash.com. Last accessed on 12th March 2024. Available at: https://unsplash.com/photos/closeup-photo-of-turned-on-blue-and-white-laptop-computer-iIJrUoeRoCQ

    In case you missed it...

    cyber essentials failure points
    The Key Failure Points in Cyber...

    Cyber Essentials helps organisations protect themselves against common cyber threats, but many businesses still find the assessment more challenging than...

    Read More
    Cybe Security Sports Clubs
    Why Cyber Security and Data Protection...

    In a fast-paced world driven by technology, sports clubs are increasingly dependent on digital systems, whether they are a small...

    Read More
    Evolution of scams
    The Quiet Evolution of Scams

    Fraud is changing in ways that can be difficult for organisations and individuals to detect. While many scams still rely...

    Read More

    Get in touch

      By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.