Cyber Essentials Check: would you pass the five control themes today?
Check your Cyber Essentials readiness against the five NCSC control themes. Free self-assessment aligned to current requirements. Predict your pass or fail in under 3 minutes.
Check your Cyber Essentials readiness against the five NCSC control themes. Free self-assessment aligned to current requirements. Predict your pass or fail in under 3 minutes.
Cyber Essentials covers five technical controls: firewalls, secure configuration, user access control, malware protection and security update management. You self-declare that each is in place and a certification body reviews your answers. This tool takes you through the same requirements as a checklist and shows where you would currently fall short.
The certification fee is modest and banded by organisation size; the real cost is the time to close the gaps before you apply. This readiness self-assessment is free and surfaces those gaps first, so you pass on the first attempt rather than paying to resubmit.
It is a free practice run at the self-assessment. It mirrors the five control themes and the kind of questions the real self-assessment asks, gives you an honest read on whether you would pass today, and points to the specific fixes. It is not the certified assessment itself, which a licensed body issues.
Cyber Essentials is a UK Government-backed certification scheme, administered by IASME on behalf of NCSC, that tests an organisation's controls across five themes: firewalls, secure configuration, security update management, user access control, and malware protection. It is the baseline certification required on many government and public sector contracts.
Cyber Essentials is a verified self-assessment: you answer questions about your controls and an assessor reviews your answers. Cyber Essentials Plus adds hands-on technical testing by an independent auditor who verifies that the controls you described actually work on your real systems. CE+ is the same five themes, independently tested.
The scheme is binary: one non-compliant device, account or cloud service in your declared scope fails the control for the whole organisation. Most first-time applicants underestimate their scope, have exceptions they consider minor, or have devices such as a director's personal laptop quietly excluded from their answers. The assessor's job is to find the exception.
No. This is a readiness signal, not a certificate. Cyber Essentials certification comes only through an IASME-licensed certification body. A PASS prediction here means your self-assessed answers are consistent with passing, which is worth knowing before you pay for the real assessment.
You answer across the five control themes and receive a pass or fail prediction at theme level, the exact findings an assessor would write up for every non-pass answer, and a prioritised remediation list.
Some basic familiarity with your IT setup is helpful. You need to know whether your devices are patched, whether MFA is on, and whether antivirus is running. If you cannot answer those questions, that is itself a finding worth knowing before you apply.