Free Tool

Security Controls Gap Checker

Check your IT security controls against Cyber Essentials Plus requirements. Identify specific gaps and get a prioritised remediation checklist.

Your Security Controls

Tick each control you have in place. Unchecked items will be flagged as gaps in your Cyber Essentials Plus compliance.

1. Firewalls & Internet Gateways

2. Secure Configuration

3. User Access Control

4. Malware Protection

5. Patch Management

Cyber Essentials Plus Technical Requirements

Control AreaKey RequirementsCE+ Test MethodCommon Failures
FirewallsBoundary config, host-based firewalls on all devicesExternal vulnerability scanOpen ports, default credentials
Secure ConfigurationHardened builds, no default passwords or unnecessary servicesAuthenticated scan, manual checkDefault passwords, unnecessary services
Access ControlLeast privilege, individual accounts, MFA on cloudAccount review, cloud service checkShared accounts, excessive privileges
Malware ProtectionReal-time protection, automatic updates, on-access scanningMalware detection testOutdated signatures, disabled scanning
Patch Management14-day critical patches, no end-of-life softwareVulnerability scan, version checkMissing patches, EOL software

Based on the NCSC Cyber Essentials Plus requirements. This tool provides guidance only and does not guarantee certification. Contact Cloudswitched for professional CE+ certification support.

More Free Tools

Try our other free security assessments and IT planning tools.