Cyber Essentials is a UK government-backed scheme that asks a business to confirm it has a baseline of technical controls in place. The self-assessment is a set of questions grouped into five control areas, reviewed by an assessor from an IASME-accredited certification body. Many customers also base their own supplier questionnaires on the same five areas, so understanding them helps either way.
A quick note on what this is: it is our own plain-English explanation of the control areas, written to help you prepare. It is not the official question set, we do not reproduce the scheme’s wording, and reading it does not certify you. The official assessment is administered by IASME and its accredited bodies. With that said, here is what each area is checking and how to answer it honestly.
Draft your answers free →First, get your scope right
Before the control questions, you define what is being assessed. By default Cyber Essentials covers your whole organisation, though you can certify a clearly separated part of it. In scope are all the devices that access your organisation’s data and services: laptops, desktops, servers, plus phones and tablets used for work, including staff-owned devices used for work (bring your own device), and people working from home.
The cloud services you use are in scope too, whether infrastructure, platform, or software as a service. Getting scope right first matters, because every later answer refers back to "in-scope devices and services".
The five control areas at a glance
The questions fall into five themes. The rest of this guide takes each in turn:
- Firewalls: controlling what can reach your devices from the internet.
- Secure configuration: setting devices and software up safely, not leaving defaults.
- Security update management: keeping everything patched and supported.
- User access control: making sure people only have the access they need.
- Malware protection: stopping malicious software from running.
Firewalls and internet gateways
This area checks that there is a firewall between your devices and the internet, and that it blocks connections coming in from the outside unless they are specifically needed and approved. That firewall might be a dedicated boundary device, your business router, or the software firewall built into each device, especially for people working from home or on the move.
Expect to confirm that inbound connections are blocked by default, that any exceptions are documented and approved, and that the default administrator password on the firewall or router has been changed to a strong, unique one.
Secure configuration
Here the questions check that devices and software are set up deliberately rather than left on their out-of-the-box defaults. That means removing or disabling accounts, software, and features you do not use, changing any default passwords, and making sure a device locks and requires a passcode or biometric to unlock.
The theme behind every question is "reduce what an attacker could reach or misuse". A short, honest description of how you set up a new laptop or account answers most of it.
Security update management (patching)
This area is about keeping software current. You confirm that the operating systems and applications on in-scope devices are still supported by their vendor, that security updates are applied promptly, and that software which is no longer supported has been removed or separated from the rest of your environment.
A common expectation is that high-risk security updates are applied within a short window of their release. Automatic updates, where available, are the simplest way to answer this honestly.
User access control
These questions check that people have their own individual accounts, that each person has only the access their role needs, and that accounts with administrative rights are controlled carefully and used only for administrative tasks, not day-to-day work or browsing.
You confirm that access is approved before it is granted, that it is removed promptly when someone leaves or changes role, and, importantly for the current requirements, that multi-factor authentication is enabled on your cloud services.
Malware protection
This area checks that in-scope devices are protected against malicious software. In practice that usually means anti-malware software that is kept up to date, or restricting devices so they can only run approved applications. Either recognised approach is acceptable, and you simply describe which you use.
Passwords and multi-factor authentication
The current requirements expect accounts to be protected against password guessing. In broad terms you can meet this with multi-factor authentication plus a reasonable minimum password length, with a longer minimum where multi-factor authentication is not available, or by moving to passwordless sign-in such as passkeys. Multi-factor authentication is now expected on all of your cloud services.
You will also be asked how you protect against automated guessing, for example by locking or throttling accounts after repeated failed attempts. Because the specifics are updated periodically, check the current published requirements when you certify.
How to answer honestly
Cyber Essentials is a self-declaration that an assessor reviews, so the answers must be true. If you do not yet meet a requirement, the right move is to fix it before you submit, not to claim it. For a customer questionnaire based on these areas, the same honesty applies: describe what you actually do, and note anything you are still putting in place.
Drafting your answers faster
Whether you are completing the official self-assessment or a customer questionnaire built on these five areas, the answers are repetitive and easy to phrase inconsistently. Tickbox reads the questionnaire, drafts a grounded answer to each question in your own words, and shows which control or policy it drew on. You review and edit rather than start from a blank box, and it never claims you are certified. Your first few answers are free.
Example answers to Cyber Essentials-style questions
These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.
Frequently asked questions
Is this the official Cyber Essentials questionnaire?
No. This is our own plain-English guide to the control areas, written to help you prepare. It does not reproduce the official question set, and reading it does not certify you. The official self-assessment is administered by IASME and its accredited certification bodies.
What changed for 2026?
Recent updates have put more emphasis on multi-factor authentication across cloud services, added passwordless options such as passkeys alongside password rules, and made clear that cloud services and home working are in scope. The exact wording is updated periodically, so check the current published requirements when you certify.
Do I need Cyber Essentials to answer a customer’s security questionnaire?
No. It helps and is sometimes requested, but you can answer most questionnaires honestly by describing the controls you have in place, whether or not you hold the certificate.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment that an assessor reviews. Cyber Essentials Plus adds a hands-on technical audit of the same controls by an assessor. This guide covers the self-assessment areas that both build on.
How long is Cyber Essentials valid?
A certificate is valid for twelve months, after which you reassess to renew. Keeping your controls and answers documented makes each renewal, and each customer questionnaire in between, much quicker.
More guides
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free