Patch evidence every fortnight, not once a year
A recurring schedule starts a short patch and MFA check every two weeks and assigns it to your IT lead. Each run carries its patch report, so your answers to A6.4 and A6.5 rest on 26 dated records.
Cyber Essentials is the UK government-backed certification built on five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. This free Cyber Essentials checklist is for organisations certifying or renewing, suppliers bidding for public contracts, and MSPs running it for clients. It covers scoping, each control as the Danzell question set tests it, sign-off and submission, the optional Cyber Essentials Plus audit and renewal. You finish with evidence behind every answer and a record next year’s renewal starts from.
The National Cyber Security Centre owns the scheme and IASME delivers it as its Delivery Partner, through licensed Certification Bodies. The standard itself is the NCSC’s Requirements for IT Infrastructure, now at v3.3. Accounts created from 27 April 2026 answer the Danzell question set, which replaced Willow (v3.2, in use since 28 April 2025).
The five controls did not change; the scope and the marking did. Version 3.3 defines a cloud service for the first time, states that cloud services cannot be excluded from scope, requires a justification for any partial scope and gives passkeys and other passwordless sign-in more prominence. Danzell makes several answers automatic fails.
How: you answer the questions in IASME’s platform and a board-level representative or owner approves them.
Checked by: an Assessor at a Certification Body. No scan or site visit.
Cost: IASME’s fee is set by headcount, from £320 + VAT for 0–9 employees to £600 + VAT for 250 or more, at the time of review.
Lasts: 12 months from the date the certificate is issued.
How: an Assessor tests sampled devices and every cloud service: external and authenticated scans, malware tests, MFA prompts and account separation.
Prerequisite: a Cyber Essentials certificate, with the audit completed within three months of it. Both can run together.
Cost: quoted by the Certification Body on the size and complexity of your network.
Lasts: 12 months, like the self-assessment.
A “no” to A6.4 or A6.5: high-risk or critical updates for operating systems, firmware and applications installed within 14 days of release. A “no” to A7.16 or A7.17: MFA for every administrator and user of every cloud service that offers it, free or paid. Listing a service under A7.15 as having no MFA when it does. And, as before, unsupported software in scope.
Five phases take you from scope to a certificate, a sixth appears only for Plus, and the last keeps you compliant through the year. Question numbers are from the Danzell question set.
Answers on the first task decide whether Phase 6 appears and switch on the renewal, sub-set, legal entity and supplier account tasks.
A6.4 and A6.5 are automatic fails. Attach patch reports that show the 14 days were met, not a policy.
A7.16 and A7.17 are automatic fails. The last task appears only when a third party manages or supports your IT.
Shown only when Phase 1 records Plus. The booking task falls due three months after the Phase 5 certificate date.
The certificate is a point-in-time check, but the declaration covers the year. Run the fortnightly check as its own recurring checklist and attach the runs here.
The table maps each part of the Requirements for IT Infrastructure v3.3 to the Danzell questions and Plus test that check it, and to the phase that collects the evidence. Check the version your assessment account uses, and treat the table as a starting point, not legal advice.
| Requirement (v3.3) | What it asks for | Danzell questions | Plus test | Evidenced in |
|---|---|---|---|---|
| Scope | Whole organisation or a segregated sub-set; end-user devices, BYOD and cloud services always included | A1.6, A2 | Scope and sub-set segregation verified before testing | Phase 1 |
| 1. Firewalls | Every device behind a correctly configured firewall; no default passwords; admin interfaces protected | A4 | External vulnerability scan | Phase 2 |
| 2. Secure configuration | Unused accounts and software removed; auto-run off; device locking | A5 | No separate test case | Phase 2 |
| 3. Security update management | Licensed, supported software; automatic updates; high-risk fixes within 14 days | A6 | Authenticated patch scan | Phases 3 and 7 |
| 4. User access control | Approved, unique accounts; separate admin accounts; MFA on every cloud service | A7 | MFA prompt and account separation tests | Phases 4 and 7 |
| 5. Malware protection | Anti-malware or application allow listing on every device | A8 | Test files by email and browser, or manual checks | Phase 5 |
Accounts opened before 27 April 2026 can still be completed against Willow within their six-month window, so the last of those close in late October 2026. The scheme is reviewed yearly: the April 2026 changes were announced in November 2025, and at the time of review no version after v3.3 had been announced. Procurement Policy Note 014 (February 2025) remains current for public buyers and says a fuller update will follow the NCSC’s redevelopment of the scheme.
A recurring schedule starts a short patch and MFA check every two weeks and assigns it to your IT lead. Each run carries its patch report, so your answers to A6.4 and A6.5 rest on 26 dated records.
Conditional logic reads the Phase 1 answers and shows the Plus audit, sub-set, legal entity and supplier tasks only where they apply. An MSP can run it per client and share a white-labelled view with the client’s director, whose sign-off is recorded as an approval before anyone submits.
Dynamic due dates set the Plus booking from the certificate date and the renewal from the expiry. Answers, evidence and feedback stay on the completed checklist, and template versioning updates the tasks when the question set changes without losing last year’s record.
CheckFlow is not a Certification Body, a vulnerability scanner or a device management tool, and it does not submit your assessment: you answer in IASME’s platform and a licensed Assessor marks it. CheckFlow runs the preparation, evidence and sign-off. MSPs can see how one template runs across a client base on CheckFlow for MSPs, and CheckFlow’s compliance checklist software shows how the renewal sits alongside the rest of your compliance calendar.
Cyber Essentials is a baseline, not a security programme. When a customer asks for more, see the ISO 27001 Compliance Checklist or the NIST CSF 2.0 Checklist.
For assessment accounts created from 27 April 2026, the requirements moved to v3.3 and the question set to Danzell. Missing MFA on a cloud service that offers it is now an automatic fail, as is missing the 14-day window for high-risk updates. Cloud services cannot be excluded from scope, partial scopes need a justification, every legal entity must be listed, the declaration covers ongoing compliance, and answers cannot be changed after Plus testing.
The controls are identical. Cyber Essentials is a verified self-assessment that an Assessor marks. Plus adds a technical audit of sampled devices and your cloud services: vulnerability scans, patch levels, malware defences, MFA and admin account separation. You need the self-assessment certificate first, and the Plus audit must be completed within three months of it.
Once you pay, you have six months to submit. IASME says marking takes about three working days, and a failed submission gets two working days to fix and resubmit without paying again. Most of the time goes on preparation. The certificate expires 12 months after issue; IASME sends a reminder about a month before, and the checklist schedules renewal earlier.
Often, yes. PPN 014, which replaced PPN 09/14 and PPN 09/23 in February 2025, tells central government departments, their agencies and NHS bodies to require Cyber Essentials or Plus, or equivalent controls, where a supplier handles citizens’ or government staff’s personal data or supplies ICT systems handling OFFICIAL information, among other cases. Evidence is needed before data passes to the supplier, and certification must be renewed yearly for the contract’s duration.
An MSP can do most of the work: inventory, configuration changes, patch evidence and draft answers. Three things stay with you. A board-level person or owner must approve the answers. The person named as responsible for your IT in question A2.10 must be a member of your organisation, not someone employed by the provider. And the accounts the MSP uses on your systems are in scope, with the same MFA and admin separation.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.