UK Cyber Essentials
Evidence request list. 36 controls, 36 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Firewalls
Every device in scope must be protected by a correctly configured firewall (or network device with firewall functionality) at the boundary of the internet connection.
- firewall device list
- topology diagram showing boundary
- rule base export
- home workers without device firewall
- consumer routers with default config
Change all default administrative passwords on boundary firewalls to a non-guessable password, or disable remote admin access entirely.
- admin account list
- password change log/attestation
- config snapshot
- consumer router admin/admin retained
- vendor default kept
Prevent access to firewall administrative interface from the internet unless protected by MFA or IP allowlist limited to specific trusted addresses.
- inbound rule export
- MFA configuration screenshot
- trusted IP allowlist
- admin port exposed to internet
- no MFA on admin interface
Every inbound firewall rule that permits traffic must be approved and documented by an authorised individual with documented business need.
- firewall change tickets
- rule register with owner/justification
- approval workflow evidence
- legacy rules with no owner
- any-any rules retained
Remove or disable permissive firewall rules promptly when no longer required to limit attack surface.
- periodic firewall rule review records
- disabled/removed rule log
- no scheduled rule review
- stale rules accumulate
Where devices are used on untrusted networks (home, public Wi-Fi), the host-based software firewall must be enabled and configured.
- endpoint firewall policy
- MDM compliance report
- sample screenshots
- Windows Defender Firewall disabled
- macOS firewall off
Block internet access to the firewall administrative interface unless there is a clear documented business need, and where allowed protect it with multi-factor authentication or a restricted IP allow list combined with managed password authentication.
- firewall management-interface configuration export
- documented business need and approval for any internet-facing admin access
- MFA enrolment evidence or IP allow list definition for the admin interface
- router or firewall web admin reachable from the internet with password only
- allow list too broad or never reviewed
- business need asserted verbally with no record
Malware Protection
Implement anti-malware on all in-scope devices: anti-malware software (signature/heuristic), application allowlisting, or sandboxing of untrusted code.
- AV/EDR console inventory vs asset list
- coverage percentage report
- servers without AV
- Linux endpoints excluded
Where anti-malware software is used, it must be kept up to date with the latest signatures and engine updates.
- AV signature age report
- out-of-date device list with remediation
- offline laptops with stale signatures
- no monitoring of signature age
Anti-malware software must scan files automatically on access, scan web pages when accessed, and prevent connections to malicious websites.
- on-access scan policy
- web protection enabled screenshot
- SafeBrowsing/SmartScreen evidence
- scheduled-scan only
- web filtering disabled
Where allowlisting is used instead of AV, only approved applications (signed or hash-listed) can execute. List must be actively maintained.
- WDAC/AppLocker policy
- allowlist register
- exception process
- allowlist in audit-only mode
- no maintenance process
Scope
Define the scope of certification covering all end user devices, servers, networks, cloud services, and remote workers. Sub-set scoping must use clear boundary by firewall or VLAN.
- scope description document
- boundary firewall/VLAN evidence
- device inventory list (make/model/OS)
- BYOD excluded incorrectly
- cloud services missed
- home worker routers not addressed
All cloud services (IaaS, PaaS, SaaS) used by the organisation must be in scope and the applicant retains responsibility for CE controls regardless of cloud provider.
- list of SaaS/IaaS/PaaS services
- responsibility matrix per service
- admin account list per cloud
- SaaS apps overlooked
- responsibility wrongly delegated to provider
User-owned devices accessing organisational data or services are in scope. Home routers provided by ISP are out of scope but the device firewall must be configured.
- BYOD register
- MDM enrolment evidence
- host firewall configuration
- BYOD not enrolled in MDM
- host firewall disabled
Secure Configuration
Remove or disable unnecessary user accounts, software, and services on devices to reduce the attack surface.
- gold image documentation
- installed software inventory
- disabled services list
- OEM bloatware retained
- guest accounts active
Change any default passwords on devices and software before deployment, or remove the account if not needed.
- deployment checklist
- credential vault entries
- no-default attestation
- printer/scanner defaults retained
- IoT devices ignored
Disable auto-run or auto-play features that automatically execute code without user authorisation on removable media or network shares.
- AutoPlay disabled GPO export
- Intune/Jamf policy screenshot
- legacy machines with AutoPlay enabled
Authenticate users with a unique credential before granting access to applications and devices. Auto-logon must be disabled.
- screen lock GPO
- no-auto-logon attestation
- kiosk hardening documentation
- shared kiosk auto-logon
- reception machine logged in 24/7
Where passwords are the only factor, protect against brute force by lockout (max 10 attempts in 5 min), throttling, or by enforcing one of: MFA, password length 12+, length 8+ with deny list, or length 8+ with technical controls.
- AD/Entra password policy export
- account lockout config
- MFA enrolment report
- 8-char passwords without deny list
- no lockout threshold
MFA must be applied to all administrative accounts on cloud services and to all user accounts on cloud services where supported by the provider.
- Entra Conditional Access policy
- Google Workspace 2SV report
- AWS IAM MFA report
- admin breakglass without MFA
- legacy SaaS without MFA
Educate users to avoid common, predictable, or compromised passwords and on the importance of unique passwords per account.
- password guidance document
- training attendance log
- phishing/password module evidence
- no documented user guidance
- training not refreshed
Have a process to change passwords promptly when the user knows or suspects the password or account has been compromised.
- password reset procedure
- incident playbook section
- service desk ticket sample
- no documented reset workflow
- users unaware how to report
Require a biometric, password or PIN before a physically present user reaches device services, protect that credential against brute force by throttling attempts or locking after a small number of failures, and enforce a minimum credential length for unlock-only credentials.
- MDM or group policy showing lock settings and attempt limits
- screenshot or export of PIN and password length enforcement
- record of vendor default used where the setting is not configurable
- laptops and phones with no lock credential
- unlimited unlock attempts
- unlock PIN below the minimum length
- device-unlock credential reused for account authentication without meeting the full password rules
Security Update Management
All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.
- SCCM/Intune software inventory
- EOL/EOSL register
- segregation evidence for unsupported
- Windows 7/Server 2012 still in use
- EOL Java runtimes
Automatic updates must be enabled on devices and software where the option exists, to ensure security updates are applied without delay.
- Windows Update for Business policy
- macOS auto-update screenshot
- WSUS/Intune config
- auto-update deferred indefinitely
- users can opt out
All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.
- patch compliance dashboard (Defender/Tenable/Qualys)
- 14-day SLA report
- exception register
- patch backlog beyond 14 days
- no CVSS-based tracking
Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network.
- EOL removal log
- segregated VLAN evidence
- compensating control documentation
- EOL kept on production network
- no plan to retire
Firmware on routers, firewalls and other in-scope network devices must be kept current. Firmware is treated as software for update purposes.
- network device firmware report
- vendor advisory subscription
- firmware change tickets
- consumer router firmware never updated
- no inventory of firmware versions
User Access Control
Have a documented user account creation and approval process. All accounts must be approved by an authorised individual before creation.
- joiner workflow
- approval tickets
- HR-IT integration evidence
- accounts created without approval
- no documented JML
Authenticate users with a unique account and password (or other credential) before granting access to applications or devices.
- IdP user list (no shared accounts)
- directory export
- shared service mailbox login
- team shared account
Remove or disable user accounts when they are no longer required (leaver, role change, extended leave) within a defined timeframe.
- leaver tickets with disable timestamp
- monthly orphan account review
- HR-IDP sync evidence
- leavers active months later
- no review cadence
Implement an approval process and keep track of privileged (administrative) accounts. The granting of privileges must be controlled.
- list of all admin accounts with owner
- approval records
- PAM tool inventory
- unmanaged local admin
- no register of cloud admin roles
Use separate accounts to perform administrative activities only. Admin accounts must not be used for routine activities like email and web browsing.
- named admin accounts (e.g. adm-jdoe)
- conditional access blocking email/web for admin accounts
- daily-driver account with Global Admin
- browsing from admin account
Review user accounts with special access privileges on a regular basis and remove or downgrade where no longer needed.
- quarterly admin review records
- access review attestation
- removed/downgraded log
- no review evidence
- review performed but no action
Multi-factor authentication must be enabled for all administrative accounts on cloud services and where technically feasible on internal systems.
- MFA enrolment per admin
- Conditional Access policy targeting admin roles
- PAM enforcement
- breakglass admin without MFA
- service principals without protection
Where identity is established without a password, use a recognised passwordless method such as a FIDO2 authenticator or passkey, biometric, hardware security key or token, push notification or one-time code, and manage it as the authentication control for the account.
- list of accounts using passwordless authentication and the method in use
- authenticator registration and revocation records
- policy statement covering accepted passwordless methods
- passwordless treated as out of scope so no control is evidenced
- no revocation process when a security key or device is lost
- method claimed as MFA when no user authentication is performed
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Cyber Essentials framework page.