All resources
Cyber EssentialsNCSCChecklist

Cyber Essentials checklist: the five UK NCSC technical controls

Official source: UK NCSC

Cyber Essentials' five UK NCSC technical controls mapped to the evidence assessors expect, with each flagged for what a platform can automate.

What Cyber Essentials requires

Cyber Essentials is assessed against 5 technical controls: Firewalls, Secure configuration, Access control, Malware protection, Patch management. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.

The control checklist

All five Cyber Essentials technical control themes. Use the table below as your working checklist — 5 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.

ControlRequirementCoverage
The five controls
CE 1Firewalls & internet gatewaysAuto
CE 2Secure configurationAuto
CE 3User access controlAuto
CE 4Malware protectionAuto
CE 5Security update managementAuto

Evidence you must collect

For every control, an auditor expects evidence it operated throughout the review period. Common examples:

  • Access reviews with timestamps and approver
  • Change tickets linked to deployments
  • Encryption and configuration snapshots
  • Vendor / supplier risk assessments on file

Automating the checklist

Roughly two-thirds of Cyber Essentials controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.

Frequently asked questions

What are the five technical controls?
Firewalls, secure configuration, security update management (patching), user access control, and malware protection. All five are mandatory to certify.

What is the difference between Cyber Essentials and Plus?
Cyber Essentials is a self-assessment verified by a certification body. Cyber Essentials Plus adds an independent hands-on technical audit — vulnerability scans and tests of a sample of devices.

How long is a certificate valid?
Twelve months. Organizations must recertify annually, and the technical requirements are updated periodically by the UK NCSC.

Which controls can be automated?
Secure configuration, patch management, and malware protection can be monitored continuously with timestamped evidence. Firewall policy and access-control reviews still benefit from documented process.

Turn this checklist into a live dashboard

SBCMSP tracks every Cyber Essentials control continuously across all your clients.