Free Tool

Security Controls Gap Checker

Check your IT security controls against Cyber Essentials Plus requirements. Identify specific gaps and get a prioritised remediation checklist.

Your Security Controls

Tick each control you have in place. Unchecked items will be flagged as gaps in your Cyber Essentials Plus compliance.

1. Firewalls & Internet Gateways

2. Secure Configuration

3. User Access Control

4. Malware Protection

5. Patch Management

Cyber Essentials Plus Technical Requirements

Control AreaKey RequirementsCE+ Test MethodCommon Failures
FirewallsBoundary config, host-based firewalls on all devicesExternal vulnerability scanOpen ports, default credentials
Secure ConfigurationHardened builds, no default passwords or unnecessary servicesAuthenticated scan, manual checkDefault passwords, unnecessary services
Access ControlLeast privilege, individual accounts, MFA on cloudAccount review, cloud service checkShared accounts, excessive privileges
Malware ProtectionReal-time protection, automatic updates, on-access scanningMalware detection testOutdated signatures, disabled scanning
Patch Management14-day critical patches, no end-of-life softwareVulnerability scan, version checkMissing patches, EOL software

Based on the NCSC Cyber Essentials Plus requirements. This tool provides guidance only and does not guarantee certification. Contact Cloudswitched for professional CE+ certification support.

More Free Tools

Try our other free security assessments and IT planning tools.

Frequently asked questions

Compare your current firewall rules, device configurations, user permissions, antivirus coverage, and patching cadence against the five Cyber Essentials control areas. This gap checker walks through each requirement and flags where your setup falls short, giving a prioritised remediation checklist rather than a generic pass or fail score.

Missing or inconsistent multi-factor authentication on cloud accounts and admin logins is the most common reason UK SMEs fail their first assessment, followed closely by software over 14 days out of date on internet-facing devices. Both are quick to fix once identified, which is why gap analysis before booking the audit saves time and money.

Yes, a self-review against the five Cyber Essentials controls is a sensible first step and can catch the majority of common issues like outdated software, weak password policies, and unmanaged BYOD devices. Many UK SMEs then bring in a managed IT provider like Cloudswitched to close remaining gaps before the formal assessment.

If you fail, the assessment body details which controls didn't meet requirements, and you typically get a short window to fix minor issues and resubmit at reduced or no extra cost, depending on the certification body's policy. More significant gaps may require a full reassessment and additional fee, which is why pre-audit gap checking is worthwhile.

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

5
  • IT Office Moves

Downsizing Your Office? How to Consolidate Your IT

5 Aug, 2025

Read more
28
  • SEO

Voice Search Optimisation: Preparing for How People Search Now

28 Apr, 2026

Read more
3
  • IT Support

In-House vs. Outsourced IT Support: Which Is Right for Your Business?

3 Mar, 2026

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.