How to Prepare for Cyber Essentials Audit

How to Prepare for Cyber Essentials Audit

A Cyber Essentials assessment can expose the small gaps that day-to-day IT management often misses: an old laptop still in use, a former employee’s account, or a critical update waiting to be installed. Knowing how to prepare for cyber essentials audit means turning those gaps into clear, manageable actions before they affect your certification, customers or ability to bid for work.

For many UK businesses, Cyber Essentials is more than a badge. It is a requirement in supply chains, public-sector contracts and client due diligence. The preparation should therefore be practical, evidence-led and suited to how your team actually works, whether staff are office-based, remote or spread across several locations.

Check out our Business Maturity Assessment to see if your business is ready for Cyber Essentials.

First, understand which assessment you are preparing for

Cyber Essentials and Cyber Essentials Plus require similar security foundations, but the assessment process is different. Cyber Essentials is based on a verified self-assessment questionnaire. A senior member of the organisation confirms that the answers are accurate, and a certification body reviews the submission.

Cyber Essentials Plus follows the basic certification and includes independent technical testing. Assessors may sample devices and look at controls such as patching, malware protection, account security and internet-facing services. Preparation for Plus needs more than correct answers on a form: your live environment must match what you say you have in place.

Do not treat the questionnaire as a document to complete at the end. Use it as a work plan. Obtain the current question set from your certification body, read every question before answering, and identify who owns the information for each area. IT may know the technical detail, but HR, operations and directors may be needed to confirm joiner-leaver processes, working arrangements and the systems used across the business.

Define your Cyber Essentials audit scope properly

The fastest way to create problems is to prepare only the computers in the office while overlooking home workers, cloud services or devices used by a satellite site. Before checking settings, build an accurate picture of the organisation and the technology covered by the certification.

Confirm the legal entity being certified, its sites, subsidiaries, remote workers, company-owned devices and personally owned equipment used for work. Record your cloud platforms, key business applications, routers, firewalls, Wi-Fi equipment, servers and any systems exposed to the internet. If a service is managed by a third party, you still need to understand how it is protected and who is responsible for each control.

Scope can be nuanced. A business with a separate group company or an isolated system may not have the same assessment boundary as a single-site company. Avoid making assumptions or excluding systems simply because they are inconvenient to review. Discuss uncertain areas with the certification body before submission and document the agreed position.

How to prepare for a Cyber Essentials audit: check the five controls

Cyber Essentials is built around five technical control areas. The best preparation is to test each one against real devices and real user behaviour, not just written policy.

Secure your boundary and internet-facing services

Your firewall or router should be properly configured, supported and protected with strong administration credentials. Review who can manage it, remove unused remote administration access, and make sure default passwords have been changed. Check that no unnecessary ports or services are open to the internet.

This is also the point to identify services that have been set up for convenience and forgotten. Old remote desktop access, test websites, legacy VPN accounts and unused port forwards can all create avoidable exposure. If staff need remote access, make it controlled, authenticated and appropriate for the sensitivity of the systems involved.

Control access to systems and data

Every user should have their own account. Shared accounts make it difficult to prove who accessed a system and make leaver management far riskier. Review administrator rights in Microsoft 365, servers, cloud platforms, line-of-business applications and individual devices. Staff should only have elevated access where there is a genuine operational need.

Multi-factor authentication should be enabled wherever it is available, particularly for email, cloud administration, remote access and accounts holding sensitive data. Check that former employees, contractors and temporary users have been removed promptly. A documented joiner, mover and leaver process is useful only if it is being followed consistently.

Keep devices and software up to date

Create a current asset list, then compare it with what people are actually using. Include laptops kept at home, spare devices, mobile phones where they access business data, virtual machines and servers. Unsupported operating systems and applications are a common reason for difficult remediation work, because they cannot receive the security updates the scheme expects.

Apply security updates within the timescales required by the current Cyber Essentials requirements, with particular attention to vulnerabilities rated critical or high risk. Automatic updates can reduce the administrative burden, but they are not a substitute for monitoring. Check that updates have installed successfully, investigate failures and maintain a clear process for urgent patches.

Sometimes an old application cannot be patched because it supports vital equipment or a specialist workflow. In that case, do not hide the issue. Speak to your assessor and IT partner early. Replacement, isolation, removal of internet access or a planned upgrade may be needed, depending on the system and the scheme guidance.

Protect against malware

Use supported anti-malware protection or an equivalent centrally managed security approach on relevant endpoints. More importantly, confirm that it is active, receiving updates and reporting issues. A device with an expired licence or disabled protection is not secure simply because a policy says protection should be installed.

Email filtering, web protection and staff awareness also matter. Most malware incidents begin with a convincing email, a stolen password or an unsafe download. Give people a simple route to report suspicious messages, and ensure your team knows that reporting a mistake quickly is better than staying silent.

Control software and user activity

Staff should not be able to install unapproved software without appropriate control. Review local administrator privileges, application installation practices and software purchasing routes. This is particularly relevant where employees work remotely and may download tools to solve a short-term problem.

Your goal is not to make work unnecessarily difficult. It is to ensure software is legitimate, supported and known to the business. A clear approved-software process gives employees a practical alternative to finding their own solutions.

Gather evidence while you remediate

Even where the assessment is questionnaire-based, preparation is easier when your answers can be backed up quickly. Keep an organised evidence folder containing asset registers, patch reports, screenshots of key security settings, firewall configuration records, anti-malware reports and access review notes. Record dates, owners and actions taken.

Evidence should reflect the current environment. A screenshot from last year, a device list that omits recent starters or a policy that staff do not follow can create unnecessary questions. For Cyber Essentials Plus, assessors may validate controls directly, so use evidence as a way to verify that management reports match the live estate.

Run a short internal dry run

Before submitting anything, ask someone who was not involved in completing the answers to challenge them. Can they identify every device? Can they confirm multi-factor authentication is enforced rather than merely available? Can they see which accounts have administrative privileges and when those were last reviewed?

A useful dry run should cover at least these areas:

  • the accuracy of the hardware, software and user account inventories;
  • patch status on a representative set of laptops, servers and mobile devices;
  • removal of leavers and unnecessary administrator access;
  • external exposure, including remote access and open services; and
  • whether policies and evidence reflect the way staff work now.

This review often reveals the difference between a control that exists in theory and one that is working. Resolve findings before the assessment rather than relying on an explanation after submission.

Give yourself time to fix what you find

Preparation is rarely a one-day exercise. Small environments may be ready within a few weeks, while businesses with legacy systems, multiple locations or inconsistent device management may need longer. Allow time for updates to install, devices to be replaced, accounts to be reviewed and staff to adopt new sign-in methods.

Avoid scheduling the assessment immediately after an office move, Microsoft 365 migration, merger or major IT project if you can. Those changes can alter the technology estate quickly and leave documentation behind. A stable period makes it easier to provide accurate answers and demonstrate reliable controls.

If you need experienced support, Nubis 365 can help turn the requirements into a clear remediation plan, manage the technical checks and prepare your business for certification without losing sight of everyday support.

A well-prepared Cyber Essentials assessment should leave you with more than a certificate. It should give your business a cleaner view of its technology, fewer avoidable security risks and greater confidence that staff can keep working when it matters most.

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.
Are you human? Please solve:Captcha