TeamTalk
Cyber Essentials
Readiness checklist
Question set: Danzell ยท [date]

Cyber Essentials: readiness checklist

The five control areas mapped to a Laravel application on AWS provisioned through Laravel Forge, plus laptops. What to have in place, what evidence to keep, and how to answer the self-assessment. Cyber Essentials is the certificate UK construction, facilities management and public-sector buyers ask for most often, and it is the cheapest item on the whole procurement list.

What you are applying for, and what it costs

ItemPosition as at 28 August 2026
Scheme ownerThe National Cyber Security Centre owns the scheme. IASME is the sole delivery partner and licenses the certification bodies that mark your submission.
Current question setDanzell, version 16.3 (May 2026), in effect for assessment accounts created on or after 27 April 2026. Accounts created before that date continue on the previous set, Willow. The question set is published free by IASME, so you can read every question before you pay.
Current requirements documentCyber Essentials: Requirements for IT Infrastructure, version 3.3 (April 2026), effective 27 April 2026. This is the document the assessor marks you against. Read it once, end to end; it is 25 pages.
Fee, by organisation sizeMicro, 0 to 9 staff: £320 + VAT. Small, 10 to 49: £440 + VAT. Medium, 50 to 249: £500 + VAT. Large, 250+: £600 + VAT. TeamTalk is in the micro band.
Cyber Essentials PlusPrice is not published: it is quoted individually by a certification body on the size and complexity of the network. Budget [£1,400 to £2,500] for a company this size get three quotes. To avoid repeating the self-assessment you must certify to Plus within three months of passing the basic assessment. Do this only when a named deal is gated on it in writing.
Validity and renewalCertificates expire after 12 months. Renewal is a full re-assessment, not a light-touch renewal: you re-enter every answer, and the questions may have changed. IASME reminds you about a month before expiry.
Time to completeYou have six months from application to submit before the account closes without refund. If you fail, you get the assessor's comments and two working days to fix and resubmit free of charge. Realistically: one to three weeks of elapsed time for a prepared micro business.
Free preparationIASME's Cyber Essentials Readiness Tool (getreadyforcyberessentials.iasme.co.uk) produces a tailored action plan. The NCSC Cyber Action Toolkit (cybertoolkit.service.ncsc.gov.uk) is broader and not scheme-specific.

Get the scope right before you answer anything

Scope is where micro businesses fail. Three rules decide almost everything:

Aim for whole organisation certification. A "partial organisation" scope is allowed but it is what a procurement reviewer will notice and ask about, and it undoes most of the value of holding the certificate.

The five controls, mapped to this stack

1 Firewalls

Evidence to keep · a dated export or screenshot of the AWS security group rules with a one-line business justification per rule; the output of ufw status verbose; a screenshot of the firewall setting on each laptop; the name of the person who approves rule changes.

2 Secure configuration

Evidence to keep · a build or provisioning note for the server describing what is installed and why; a list of accounts on each server and cloud service with a last-reviewed date; laptop screen-lock settings.

3 Security update management two auto-fail questions

Evidence to keep · the unattended-upgrades configuration and its log; a dated list of operating system versions and their end-of-support dates; dependency alert history; the date and version of the last framework and PHP upgrade.

4 User access control four auto-fail questions

This is the control that changed in April 2026 and the one most likely to fail a micro business. Multi-factor authentication on cloud services is now mandatory and is assessed as an automatic fail, whether the provider offers it free, bundled or as a paid option.

Evidence to keep · a single spreadsheet listing every cloud service, its account holders, whether each is an administrator, and whether MFA is on, with a date; the account approval note; the access review record; a screenshot of the AWS IAM credential report.

5 Malware protection

Evidence to keep · a screenshot per laptop showing protection enabled and definitions current; a written note of the server approach and the reasoning.

Not a requirement, but say it anyway

Backups are not a technical requirement of Cyber Essentials. The v3.3 requirements say so explicitly while strongly recommending them, and version 3.3 added emphasis on backing up. Answer the backup question fully anyway: it costs nothing and the same answer feeds straight into the supplier questionnaire, which does treat backup and restore as a scored item.

How to answer the self-assessment

Before you apply: the ten-minute pre-flight

CheckWhy it matters
Every cloud service listed, with MFA onFour automatic fails live here
No unsupported software anywhere in scopeAn automatic certification blocker
14-day patching demonstrable, not just claimedTwo automatic fails
Separate administrative accounts, not one account doing both jobsThe most common micro-business finding
Password expiry switched offAn old habit that is now a non-conformance
Laptop software firewalls on, home routers not mentionedScope error that triggers assessor questions
Whole organisation scope, not partialPartial scope invites procurement questions
Named signatory ready for the board declarationSubmission cannot complete without it
Not legal or assurance advice. This checklist summarises the published scheme documents; the certification body's marking of your answers is what determines the outcome. Verify the question set and requirements version in force on the day you apply, because IASME revises them annually in April. Sources, verified 28 August 2026: NCSC, Cyber Essentials overview and the five controls ncsc.gov.uk/cyberessentials/overview; NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3, April 2026, effective 27 April 2026 ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf; IASME, Danzell question set version 16.3, May 2026 iasme.co.uk preview the self-assessment questions; IASME, Cyber Essentials pricing and frequently asked questions iasme.co.uk/cyber-essentials; IASME, changes to Cyber Essentials for April 2026 iasme.co.uk/articles; IASME Readiness Tool getreadyforcyberessentials.iasme.co.uk; NCSC Cyber Action Toolkit cybertoolkit.service.ncsc.gov.uk.