NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
Cyber Essentials Checklist (Free Excel, 2026)
Resources

Cyber Essentials Checklist (Free Excel, 2026)

·Alexander Sverdlov

This Cyber Essentials checklist is a free, self-assessment spreadsheet that walks you through the five technical controls before you apply for certification. If you are a compliance lead, IT manager, or CISO preparing for a Cyber Essentials checklist review, it gives you a structured way to see exactly where you stand and what to fix first. Cyber Essentials is a UK government-backed scheme run by IASME under the NCSC, and it certifies five control areas: firewalls, secure configuration, security update management, user access control, and malware protection. This resource maps all five so nothing gets missed. It is not the official IASME assessment, but it mirrors the same control areas, so your answers and evidence are ready when you certify. Download it below and start self-assessing in minutes.

Free download

Get the Cyber Essentials Readiness Checklist

Self-assess against the five Cyber Essentials technical controls before you certify. 47 items.

By downloading, you agree to receive occasional relevant emails from Venvera. Unsubscribe anytime. See our Privacy Policy. This template is a starting point, not legal advice.

One evidence library covering Cyber Essentials and overlapping frameworks
One evidence library, mapped across Cyber Essentials and the frameworks it shares controls with.

What the Cyber Essentials Readiness Checklist covers

The file is a single Excel workbook with 47 items spread across the five Cyber Essentials control areas, so every question maps back to something an assessor will actually look at. Each row is a concrete requirement, and each column helps you turn a vague "we think we are fine" into evidence you can point to.

Inside you will find columns for:

  • Control area - which of the five it belongs to (firewalls, secure configuration, security update management, user access control, or malware protection).
  • Requirement - the specific thing to check, written in plain English.
  • Status - a dropdown for Met, Partial, Not met, or Not applicable.
  • Evidence and notes - where you record the screenshot, policy, or config that proves it.
  • Owner - the person accountable for closing the gap.
  • Priority - so you fix the blocking items before the nice-to-haves.

The 47 items are grouped by the five controls, which means you can hand one section to your network engineer and another to whoever manages laptops, and everyone works in the same file.

Mapping a Cyber Essentials control across other frameworks
A control entered once maps across Cyber Essentials and every framework it also satisfies.

Cyber Essentials the honest way: what actually matters

Cyber Essentials is a UK government-backed scheme run by IASME under the NCSC. It certifies five technical controls, and the scheme is built around getting these five basics right rather than chasing exotic threats. Here is what each one actually asks of you.

  • Firewalls - every device that connects to the internet sits behind a correctly configured firewall or equivalent, with default passwords changed and unnecessary inbound access closed.
  • Secure configuration - devices and software are set up to reduce their attack surface: remove or disable what you do not use, and never ship default credentials.
  • Security update management - software is supported, licensed, and patched, with high and critical updates applied promptly.
  • User access control - accounts belong to named individuals, admin rights are limited and used only when needed, and leavers lose access.
  • Malware protection - you defend your devices against malware, whether through anti-malware software, application allow-listing, or sandboxing.

Two things people get wrong. First, certification is a self-assessment that a certification body verifies: you answer the official IASME question set honestly, and a certifying body checks it. Second, Cyber Essentials Plus is not a different set of controls; it is the same five, but with an independent, hands-on technical audit on top. Passing the self-assessment first is the sensible route to Plus. Cyber Essentials is aimed at organisations of all sizes, especially SMEs, and many UK public-sector contracts require you to hold the certificate before you can bid, which is why getting the five controls right early matters.

Cyber Essentials control health tracked in one dashboard
Track Cyber Essentials readiness continuously instead of in a point-in-time spreadsheet.

How to use the Cyber Essentials Readiness Checklist

  1. Download the file below and open it in Excel or Google Sheets.
  2. Assign an owner to each of the five control areas so no section is orphaned.
  3. Go row by row and set each item's status to Met, Partial, Not met, or Not applicable. Be honest, not optimistic.
  4. For every Met item, drop the evidence (screenshot, policy link, config export) into the notes column so it is ready when you certify.
  5. Sort by Priority and work the Not met and Partial items first.
  6. Re-run the Cyber Essentials checklist a week before your assessment to confirm nothing has drifted.
A live Cyber Essentials posture for the board
A live posture keeps the Cyber Essentials picture current for leadership and auditors.

Do this automatically in Venvera

The spreadsheet is a solid starting point, but a static file goes stale the moment your firewall rules or user list change. In Venvera, the same five control areas live in a continuously tracked workspace: Cyber Essentials in the product keeps each control current, stores the evidence behind it, and reuses that evidence across other frameworks you may also need, so you answer once and satisfy many. Plans start from EUR 399/month. You still own the certification decision. Venvera just removes the copy-paste and the spreadsheet drift between now and your assessment.

Frequently Asked Questions

Is this the official Cyber Essentials assessment?

No. This is a readiness checklist that maps the five Cyber Essentials control areas so you can self-assess and gather evidence in advance. The official assessment is the IASME question set, which you submit through a certification body.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

They cover the same five technical controls. Cyber Essentials is a self-assessment verified by a certification body, while Cyber Essentials Plus adds an independent, hands-on technical audit to confirm the controls are actually in place.

Who needs Cyber Essentials?

It is aimed at organisations of all sizes, especially SMEs, and is often required to bid for UK public-sector contracts. If a tender lists it as a prerequisite, you need the certificate before you can submit.

How many controls does the Cyber Essentials checklist cover?

Five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. This checklist breaks them into 47 concrete items so you can see the gaps clearly.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS