| Requirement | What it means for Viewee | Owner (Instinct / Alex+Cain / External assessor) | Effort | Status | Evidence needed | Source URL |
|---|
| Use current scheme requirements (v3.3, April 2026) | Prepare against v3.3 and the current IASME question set; do not claim certification until verified. | Alex+Cain | M | Do now | Version-controlled readiness checklist and downloaded question set | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Define and agree assessment scope | Cover the whole business IT estate or a clearly bounded, separately managed subset; agree scope with the certification body and justify exclusions. | Alex+Cain | M | Do now | Scope statement: business unit, network boundary, physical locations, exclusions and rationale | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Include endpoints and remote/BYOD devices | Founder laptops and any personal devices accessing Viewee data/services are in scope; a scope excluding end-user devices is not acceptable. Home routers normally remain out of scope unless Viewee supplies them. | Alex+Cain | M | Do now | Device register, ownership, OS/version, remote-working configuration | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Include all cloud services and owned third-party accounts | Google Workspace, code hosting, cloud hosting, monitoring, CRM/outreach admin and SaaS accounts used for Viewee must be assessed. Provider controls need contractual/trust-centre evidence. | Alex+Cain | H | Do now; finalise after vendors selected | Cloud service register, shared-responsibility mapping, contracts/security statements | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Maintain usable asset and software inventory | Asset management supports all five controls: track devices, software, services, versions, owners and support status. | Instinct | M | Do now | Authoritative asset/software/cloud inventory and review log | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Protect every in-scope device with a firewall | Use host firewall on laptops used on untrusted/home networks and cloud firewall/data-flow rules for hosted infrastructure. | Alex+Cain | M | Do now; extend when product live | Endpoint firewall screenshots/config export; cloud network rules | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Harden firewall administration | Change default admin passwords; prevent internet admin access unless documented and protected by MFA or tightly managed IP allow-list plus password. | Alex+Cain | M | Do now; extend when hosting chosen | Admin configuration, MFA evidence, documented exception/allow-list | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Default-block unauthenticated inbound traffic | Inbound connections should be denied by default; each allowed inbound rule needs approval, business need and removal when no longer needed. | Alex+Cain | M | Needs hosting architecture | Firewall/security-group exports, approvals, rule-review log | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Secure configuration baseline | Remove unused accounts, software, utilities and services; change defaults; disable autorun; require authentication and device locking. | Alex+Cain | M | Do now | Founder device baseline and cloud/SaaS configuration checklists | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Protect device unlock | Use biometric/password/PIN; configure throttling or lock after no more than 10 failed attempts where possible; unlock PIN/password at least 6 characters. | Alex+Cain | L | Do now | MDM/OS policy screenshots or device check records | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Use supported and licensed software | All in-scope software must be licensed and vendor-supported; remove unsupported software or isolate it in a no-internet subset. | Alex+Cain | M | Do now and ongoing | Software inventory with support/EOL dates and removal records | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Apply security updates within 14 days | Enable automatic updates where possible; install fixes within 14 days where vendor says critical/high, CVSS v3 is 7+, or severity is not given. | Alex+Cain | M | Do now and ongoing | Patch policy, endpoint and dependency update reports, exception/remediation log | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Approve and uniquely identify users | Have a process to create/approve accounts; use unique credentials; disable leavers and inactive accounts. Includes supplier/support accounts. | Alex+Cain | M | Do now; product process before launch | Joiner/mover/leaver procedure, account lists, approvals and disablement evidence | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Least privilege and privileged-account separation | Grant only access needed; remove elevated access when no longer needed; use separate admin-only accounts, not for email/browsing. | Alex+Cain | M | Do now; extend before launch | Role/access matrix, privileged-account register, access reviews | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| MFA for cloud services | All authentication to cloud services must use MFA where available. Internet-accessible/admin accounts should always have MFA. | Alex+Cain | M | Do now | MFA enforcement exports for Workspace, GitHub, cloud and other SaaS | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Password controls where passwords remain | Protect against guessing with MFA/throttling/lockout. Use 12+ characters, or 8+ with common-password deny-list, or MFA; no maximum restriction; do not force routine expiry; enable prompt reset on suspected compromise. | Alex+Cain | M | Do now; app control before launch | Identity-provider policy, password-manager standard, reset process and test evidence | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Active malware protection on all devices | Use configured, updated anti-malware on Windows/macOS, application allow-listing, or sandboxed app-store model as applicable; block malicious code/sites. | Alex+Cain | M | Do now | Endpoint security status/export, update and policy evidence | https://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf |
| Complete verified self-assessment | Answer the current IASME questionnaire accurately, retain evidence and remediate before submission; CE Plus, if pursued, adds independent technical testing. | External assessor | M | After controls operate | Completed question set, assessor correspondence, remediation log | https://iasme.co.uk/cyber-essentials/preview-the-self-assessment-questions-for-cyber-essentials/ |
| Renew annually and manage material change | Treat certification as a point-in-time verified assessment and schedule annual renewal plus control reviews when estate/vendors change. | Alex+Cain | L | After certification | Renewal calendar and change-trigger review record | https://iasme.co.uk/cyber-essentials/frequently-asked-questions/ |