ChecklistCyber Essentials PlusPDF · 2.7 MB

Cyber Essentials Plus Requirements Checklist

Complete checkbox checklist of all Cyber Essentials Plus requirements organised by the five control areas, with evidence needed and pass/fail criteria for each item.

About This Resource

The Cyber Essentials Plus examination assesses your organisation against specific technical requirements across five control areas. This checklist breaks down every requirement into actionable checkbox items so you can systematically work through each one, document your evidence, and track your progress toward certification. Each item includes the specific requirement, what evidence the assessor will look for, and the pass/fail criteria. Use this as your master tracking document throughout the preparation process to ensure nothing is missed before examination day.

What's Included

  • Complete requirements for all five control areas with checkbox tracking
  • Evidence requirements: what assessors look for at each checkpoint
  • Pass/fail criteria for every individual requirement
  • Scoring system to quantify your certification readiness
  • Space to document actions needed and responsible parties
  • Organised by control area for systematic preparation

Who Is This For?

IT teams and compliance officers who need a structured, trackable checklist to systematically prepare for and verify readiness for Cyber Essentials Plus examination.

Frequently asked questions

Assessors typically want to see firewall configuration exports, a current asset inventory, patch status reports, screenshots of MFA settings, and antivirus deployment records. Evidence should reflect your actual environment at the time of examination, not a point-in-time snapshot from months earlier, since assessors often test live.

Basic Cyber Essentials relies on a self-assessed questionnaire, while Plus adds an independent technical audit including vulnerability scanning and on-site or remote testing of devices. Plus is generally required for government contracts involving sensitive data and gives clients stronger assurance that controls are actually implemented, not just declared.

Certification requires every in-scope device to meet all five control requirements with no critical or high-severity vulnerabilities left unpatched. A single unpatched critical vulnerability on an in-scope device can result in a fail, so organisations typically need a clean sweep across all sampled devices, not just a majority.

Yes, this checklist is designed as a shared tracking document with checkbox items, evidence fields, and a scoring system so IT teams and compliance officers can divide work by control area and monitor overall readiness before booking the examination.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

9
  • Google Ads & PPC

Google Ads Attribution: A UK Business Guide to Understanding Which Campaigns Actually Drive Sales in 2026

9 Sep, 2026

Every UK business running paid search eventually has the same meeting. Someone opens the Google Ads interface, sorts the campaign list by conversions, points...

Read more
8
  • SEO

Technical SEO Audit: A UK Business Guide to Finding and Fixing the Issues Killing Your Rankings in 2026

8 Sep, 2026

There is a particular kind of frustration that shows up in UK marketing meetings about eighteen months into a content programme. The blog is publishing...

Read more
7
  • Web Development

Website Accessibility Compliance: A UK Business Guide to Meeting WCAG 2.2 and Avoiding Legal Risk in 2026

7 Sep, 2026

Most UK businesses discover the state of their website accessibility in one of three ways: a customer complaint, a procurement questionnaire they cannot answer...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.