ChecklistCyber Essentials PlusPDF · 2.7 MB

Cyber Essentials Plus Requirements Checklist

Complete checkbox checklist of all Cyber Essentials Plus requirements organised by the five control areas, with evidence needed and pass/fail criteria for each item.

About This Resource

The Cyber Essentials Plus examination assesses your organisation against specific technical requirements across five control areas. This checklist breaks down every requirement into actionable checkbox items so you can systematically work through each one, document your evidence, and track your progress toward certification. Each item includes the specific requirement, what evidence the assessor will look for, and the pass/fail criteria. Use this as your master tracking document throughout the preparation process to ensure nothing is missed before examination day.

What's Included

  • Complete requirements for all five control areas with checkbox tracking
  • Evidence requirements: what assessors look for at each checkpoint
  • Pass/fail criteria for every individual requirement
  • Scoring system to quantify your certification readiness
  • Space to document actions needed and responsible parties
  • Organised by control area for systematic preparation

Who Is This For?

IT teams and compliance officers who need a structured, trackable checklist to systematically prepare for and verify readiness for Cyber Essentials Plus examination.

Frequently asked questions

Assessors typically want to see firewall configuration exports, a current asset inventory, patch status reports, screenshots of MFA settings, and antivirus deployment records. Evidence should reflect your actual environment at the time of examination, not a point-in-time snapshot from months earlier, since assessors often test live.

Basic Cyber Essentials relies on a self-assessed questionnaire, while Plus adds an independent technical audit including vulnerability scanning and on-site or remote testing of devices. Plus is generally required for government contracts involving sensitive data and gives clients stronger assurance that controls are actually implemented, not just declared.

Certification requires every in-scope device to meet all five control requirements with no critical or high-severity vulnerabilities left unpatched. A single unpatched critical vulnerability on an in-scope device can result in a fail, so organisations typically need a clean sweep across all sampled devices, not just a majority.

Yes, this checklist is designed as a shared tracking document with checkbox items, evidence fields, and a scoring system so IT teams and compliance officers can divide work by control area and monitor overall readiness before booking the examination.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

3
  • IT Office Moves

The Hidden Costs of an Office Move: A UK Business Guide to Budgeting for IT Relocation in 2026

3 Sep, 2026

Almost every office move IT budget we see arrives at the same shape: a removals quote, a furniture allowance, a signage line, a contingency of ten per cent,...

Read more
2
  • IT Support

IT Support Response Times: A UK Business Guide to Setting SLAs That Actually Match Your Risk in 2026

2 Sep, 2026

An IT support SLA is the only part of a managed service contract that tells you what happens on the worst day of your year, and it is routinely the least...

Read more
1
  • Microsoft 365 Copilot

Microsoft 365 Copilot Data Security: A UK Business Guide to Controlling What Copilot Can See in 2026

1 Sep, 2026

Copilot data security is not a Copilot problem. It is a permissions problem that Copilot makes impossible to ignore. Microsoft 365 Copilot has no private...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.