6 min read

Cyber Essentials readiness: the self-check to do before you pay an assessor

The five Cyber Essentials controls, the three where small UK firms fail, and an afternoon’s self-check to run on every Windows device before the assessment.

PCRiskPro Cyber Essentials module showing pass, warning and fail results per control

Cyber Essentials costs between £300 and £600 plus VAT to assess, depending on the size of your organisation. That is the cheap part. The expensive part is failing, fixing things in a rush, and paying to be assessed again while an insurer, a customer’s procurement team or a public-sector contract waits on the certificate.

Most small firms that fail do so on the same handful of things. None of them needs a consultant to find. This is the self-check to run on every Windows device before you fill in the questionnaire.

What Cyber Essentials actually is

Cyber Essentials is the National Cyber Security Centre’s baseline scheme. You answer a self-assessment questionnaire about your organisation and its devices, and a certification body accredited by IASME checks the answers. Pass, and you get a certificate valid for twelve months, plus free cyber insurance if your turnover is under £20 million. Cyber Essentials Plus adds an independent technical audit on top.

The scheme rests on five controls:

Control

What it asks

Firewalls

A boundary or software firewall on every device, properly configured

Secure configuration

No default passwords, no unnecessary software or services, no autorun

Security update management

Critical and high-risk fixes applied within 14 days; no unsupported software

User access control

Unique accounts, least privilege, multi-factor authentication on cloud services

Malware protection

Anti-malware active and updating, or application allow-listing

Two recent versions of the requirements changed where firms trip. Version 3.2, from April 2025, made unsupported software a hard requirement to remove or segregate, and widened “security update” to include configuration changes and vendor-recommended fixes, not only patches. Version 3.3, from 27 April 2026, made incomplete MFA an automatic fail: if a cloud service offers multi-factor authentication and it is not enabled for every user, the assessment fails. It also tightened scope to a simple test: if a device connects to the internet, it is in scope.

The three controls where small firms fail

Unsupported software. This is the largest single cause of failure, and since 14 October 2025 it has an obvious driver: Windows 10 no longer receives security updates. A year on, it is still running on reception PCs, nursing stations, warehouse terminals and the finance laptop that “works fine”. Old versions of Office, Adobe Reader and the software that came with a label printer count too. Under the current requirements these devices must be upgraded, replaced, or segregated from the rest of the network with documented justification.

Incomplete MFA. The usual gap is not the main mailboxes. It is the shared info@ account, the mailbox for a colleague who left, the director who turned MFA off because it was annoying, and the cloud accounting or HR system nobody thinks of as “IT”. Since April 2026 any one of those is a fail.

Patching slower than 14 days. Windows Update is usually fine. Third-party applications are not. 7-Zip, Adobe Reader, Java, a browser on a machine nobody logs into, and any line-of-business application that is not in the Microsoft catalogue will sit for months. Fourteen days from the vendor publishing a fix is a hard target to hit by hand across even ten machines, and the assessor can now ask for an audit trail rather than a sample.

Two quieter causes deserve a mention. Staff who use a local administrator account for everyday work fail secure configuration and make every phishing click worse. And an incomplete asset list, the laptop in the drawer or the personal phone with work email on it, undermines every other answer, because a control you have not applied to a device you did not list is a control you have not applied.

The afternoon self-check

Run this on each Windows device, or on a representative one per type. It takes an afternoon for a ten-device firm, and most of it is looking rather than fixing.

  1. List every device. Desktops, laptops, phones and tablets that touch company data or email. Include personal phones with work mail on them. This list is your scope; get it right before anything else.

  2. Windows version. Settings → System → About. Anything on Windows 10 is a fail as of October 2025. On Windows 11, check that updates are installing: Settings → Windows Update → Update history.

  3. Third-party application versions. Open a terminal and run winget upgrade. Everything it lists has a newer version available. Then compare the update dates against 14 days. Applications not in the list need checking by hand.

  4. Who has local admin. Run net localgroup Administrators. Anyone who uses that account for daily work needs a standard account instead.

  5. MFA on every cloud service, every user. Microsoft 365 admin centre, Google Workspace, the accounting platform, the HR platform. Do not sample; check the list of users without MFA on each service.

  6. Password policy on local accounts. Run net accounts. Minimum password length of 0 and a lockout threshold of “Never” are both common on machines that were set up quickly and never revisited. We published a sample report from a real machine with exactly those two failures, because they are that ordinary.

  7. Firewall. Settings → Privacy & security → Windows Security → Firewall & network protection. On for every profile.

  8. Anti-malware. Same screen, Virus & threat protection. Active, updated within the last day. If a third-party product is in charge, confirm it reports the same.

  9. Unsupported software. Anything the vendor no longer updates. Remove it, or document why it is isolated.

  10. Write down what you found. Date, device, result. That record is the difference between a self-assessment you can defend and one you hope is right.

Where a readiness check fits

Steps 2 to 9 are what PCRiskPro’s Cyber Essentials module checks on a Windows device, in about ten seconds, and it reports pass, warning or fail per control with the fix, who should perform it, and whether it needs administrator rights. The Free Edition runs the full check on any machine with no time limit; exporting the report for an assessor, an insurer or a board pack needs a licence.

Be clear about what it is. It is a readiness check on the device it runs on. It is not a certificate, it does not replace the questionnaire, and the MFA state of your cloud services is something you verify in your admin consoles, not something a scan of a laptop can see. What it removes is the surprise: you find the failing control on a Tuesday afternoon instead of in the assessor’s report.

Run the check: pcriskpro.com/downloads. The installer is signed, the checksum is published, and a sample Cyber Essentials report is on the site so you can see the output before you install anything.

Sources

  • NCSC, Cyber Essentials overview — ncsc.gov.uk/cyberessentials/overview

  • IASME, Cyber Essentials FAQ (assessment fees by organisation size) — iasme.co.uk/cyber-essentials/frequently-asked-questions

  • Cyber Essentials v3.2 “Willow” changes (April 2025) — cybercompliance.org.uk/blogs/news/whats-new-in-cyber-essentials-v3-2-willow

  • Cyber Essentials v3.3 “Danzell” changes (27 April 2026) — forensiccontrol.com/news/cyber-essentials-v3-3-2026-update

  • Common failure causes — intelance.co.uk/cyber-essentials-failures ; nexusos.co.uk/how-to-pass-cyber-essentials-first-time-complete-checklist-2026

  • Microsoft, Windows 10 end of support 14 October 2025 — support.microsoft.com

Run the free assessment

PCRiskPro checks Cyber Essentials readiness, installed software and where personal data sits on a Windows PC. The Free Edition has no time limit.

Download the Free Edition

More notes