- IT Office Moves
Downsizing Your Office? How to Consolidate Your IT
5 Aug, 2025
Check your IT security controls against Cyber Essentials Plus requirements. Identify specific gaps and get a prioritised remediation checklist.
Tick each control you have in place. Unchecked items will be flagged as gaps in your Cyber Essentials Plus compliance.
| Control Area | Key Requirements | CE+ Test Method | Common Failures |
|---|---|---|---|
| Firewalls | Boundary config, host-based firewalls on all devices | External vulnerability scan | Open ports, default credentials |
| Secure Configuration | Hardened builds, no default passwords or unnecessary services | Authenticated scan, manual check | Default passwords, unnecessary services |
| Access Control | Least privilege, individual accounts, MFA on cloud | Account review, cloud service check | Shared accounts, excessive privileges |
| Malware Protection | Real-time protection, automatic updates, on-access scanning | Malware detection test | Outdated signatures, disabled scanning |
| Patch Management | 14-day critical patches, no end-of-life software | Vulnerability scan, version check | Missing patches, EOL software |
Based on the NCSC Cyber Essentials Plus requirements. This tool provides guidance only and does not guarantee certification. Contact Cloudswitched for professional CE+ certification support.
Try our other free security assessments and IT planning tools.
Compare your current firewall rules, device configurations, user permissions, antivirus coverage, and patching cadence against the five Cyber Essentials control areas. This gap checker walks through each requirement and flags where your setup falls short, giving a prioritised remediation checklist rather than a generic pass or fail score.
Missing or inconsistent multi-factor authentication on cloud accounts and admin logins is the most common reason UK SMEs fail their first assessment, followed closely by software over 14 days out of date on internet-facing devices. Both are quick to fix once identified, which is why gap analysis before booking the audit saves time and money.
Yes, a self-review against the five Cyber Essentials controls is a sensible first step and can catch the majority of common issues like outdated software, weak password policies, and unmanaged BYOD devices. Many UK SMEs then bring in a managed IT provider like Cloudswitched to close remaining gaps before the formal assessment.
If you fail, the assessment body details which controls didn't meet requirements, and you typically get a short window to fix minor issues and resubmit at reduced or no extra cost, depending on the certification body's policy. More significant gaps may require a full reassessment and additional fee, which is why pre-audit gap checking is worthwhile.
Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.