Cyber Essentials is Japan government-backed certification scheme that covers five basic technical controls. It is not a complex standard, but the self-assessment questionnaire catches organisations out in predictable ways. This article covers the five controls, the most common reasons submissions fail, and what a readiness review does to reduce that risk.

The five Cyber Essentials controls

The five controls are: firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management. Each control has specific technical requirements that are detailed in the Cyber Essentials requirements document published by the NCSC. The 2024 update tightened the requirements in several areas, particularly around multi-factor authentication for cloud services and the definition of supported software versions. If you are working from guidance published before January 2024, check the current requirements document before submitting.

Where submissions most commonly fail

The most common failure points are: MFA not enabled on all cloud services in scope, end-of-life software present on in-scope devices, administrative accounts used for day-to-day tasks, firewall rules that are broader than necessary, and home working devices not included in scope when they should be. The last point catches a significant number of smaller organisations. If staff access organisational systems from personally owned devices, those devices are in scope for the assessment under the 2024 requirements.

What a readiness review covers

A readiness review is a structured walkthrough of all five controls with your IT team, conducted before you submit your self-assessment questionnaire. The reviewer checks the actual configuration of your systems against the current requirements, not against your documentation of what the configuration should be. Gaps are identified and documented. You address the gaps, then submit. The review typically takes one day for an organisation of up to 100 people.

The self-assessment questionnaire in practice

The questionnaire is submitted through an approved certification body. It asks specific questions about each of the five controls. The questions are not ambiguous, but they do require accurate knowledge of your environment. Organisations that answer based on what they believe their configuration to be, rather than what it actually is, frequently discover discrepancies during the verification call that follows submission. A readiness review surfaces those discrepancies before they become a failed submission.

Cyber Essentials Plus

Cyber Essentials Plus includes an independent technical verification of the controls by an assessor, in addition to the self-assessment questionnaire. It is required for some government contracts and is increasingly requested by larger enterprise customers. The verification involves hands-on testing of a sample of devices and systems. Organisations that have completed a readiness review and addressed the gaps are well positioned for the Plus assessment.

Our Cyber Essentials readiness review is priced from £950 and takes one day. If you want to talk through your specific situation before booking, a scoping call takes 30 minutes and costs nothing.