Phone us
Cyber Essentials is now a recognised benchmark for UK businesses that want to demonstrate good cyber hygiene, reassure customers, meet supply chain expectations, and prepare for public sector or regulated-sector requirements.

But many SMEs only discover gaps when they begin the assessment — missing MFA, unsupported software, unmanaged devices, weak administrator controls, or unclear cloud security responsibilities.

Use this checklist to assess whether your business is ready for Cyber Essentials or Cyber Essentials Plus in 2026.

Can your business answer “yes” to these key areas?

Assessment Scope
  • Have you identified all laptops, desktops, mobiles, tablets and servers used for business?
  • Are remote and hybrid working devices included?
  • Do any BYOD devices access company data or services?
  • Have you listed all cloud services, including email, file storage, CRM, finance and collaboration tools?
  • Do you know which systems are managed internally and which are managed by a third party or IT provider?
Firewalls & Internet Gateways
  • Is every device protected by a firewall?
  • Have default administrator passwords been changed?
  • Are unnecessary firewall rules removed?
  • Is remote access properly controlled?
  • Are unused or insecure services blocked?
Secure Configuration
  • Have unnecessary applications, services and accounts been removed?
  • Are default settings changed where required?
  • Are laptops, desktops, mobiles, servers and cloud services securely configured?
  • Are administrator accounts limited to those who genuinely need them?
  • Are configuration standards reviewed regularly?
Security Update Management
  • Are all operating systems and applications still supported?
  • Are critical and high-risk updates applied promptly?
  • Are unsupported devices or applications removed or replaced?
  • Are updates managed across remote and hybrid working devices?
  • Is there a clear process for checking patch compliance?
User Access Controls
  • Are user accounts reviewed regularly?
  • Are leavers removed promptly?
  • Are inactive or unused accounts disabled?
  • Do users only have access to what they need?
  • Are administrator privileges tightly controlled?
Multi-Factor Authentication
  • Is MFA enabled for email accounts?
  • Is MFA enabled across cloud services such as Microsoft 365, Google Workspace, CRM, file sharing and finance platforms?
  • Are administrator accounts protected with MFA?
  • Are shared accounts avoided wherever possible?
  • Have you checked whether any cloud service requires a licence upgrade to enable MFA?
Malware Protection
  • Is endpoint protection active across all devices?
  • Are anti-malware tools kept up to date?
  • Are laptops, desktops and remote devices protected?
  • Are alerts monitored and acted on?
  • Are mobile and cloud environments considered where relevant?
Preparing for Cyber Essentials Plus

Cyber Essentials Plus goes beyond the self-assessment and includes independent technical verification of your controls. Before booking Cyber Essentials Plus, your organisation should check that:

  • Devices are patched and ready for testing
  • Unsupported software has been removed
  • Malware protection is active and updated
  • MFA is enabled where required
  • Remote and hybrid devices are included in preparation
  • Vulnerability issues are reviewed before assessment day
  • Internal teams know what access and evidence may be needed

Download the full Cyber Essentials 2026 Readiness Checklist.

Use the checklist to identify gaps before starting your Cyber Essentials or Cyber Essentials Plus assessment.

Download the full Cyber Essentials 2026 Readiness Checklist

    By submitting this form you are consenting to receiving our monthly newsletter. Your data will be handled in accordance with our Privacy Policy and we will be in touch regarding your enquiry.

     

    Final Thoughts

    Cyber Essentials is no longer viewed as simply a compliance requirement. It has become a recognised benchmark for demonstrating strong baseline cybersecurity controls and building trust with customers, suppliers, and stakeholders.

    Businesses that review their security posture early will be in a stronger position to achieve certification and improve resilience throughout 2026.

    At A Jolly Consulting, we support organisations with Cyber Essentials and Cyber Essentials Plus readiness, helping businesses prepare for certification with practical and effective cybersecurity guidance.

    Please contact us on 020 7101 4861 email us info@ajollyconsulting.co.uk  if you think we can help.

     

     

    Image accreditation: Philipp Katzenberger (January 2019) from Unsplash.com. Last accessed on 12th March 2024. Available at: https://unsplash.com/photos/closeup-photo-of-turned-on-blue-and-white-laptop-computer-iIJrUoeRoCQ

    In case you missed it...

    UK Air Traffic Control Disruption
    UK Air Traffic Control Disruption: Why...

    Recent disruption across UK airports has shown how quickly the failure of a critical system can have far-reaching consequences. While...

    Read More
    cyber security healthCARE
    Patient Data Breaches: Why Cyber Security...

    Protecting patient data is not just about securing systems and technology. This article looks at how human behaviour, organisational processes...

    Read More
    uber GDPR fine
    What Uber’s GDPR €825 Million Fine...

    A recent €825 million GDPR fine against Uber has put automated decision making firmly in the spotlight. This article looks...

    Read More

    Get in touch

      By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.