Skip to main content
    NixInfinity-AI
    Submission Guide

    Cyber Essentials Evidence Pack: What to Submit

    Published 2 June 2026

    Cyber Essentials and evidence – the truth

    Cyber Essentials (the basic tier) is a verified self-assessment. You answer the IASME question set; an assessor reviews your answers. They don't audit you on site. But they can – and routinely do – ask for clarification or evidence on individual answers. If you can't supply it quickly, the answer gets marked down.

    Cyber Essentials Plus is different – an assessor independently tests a sample of devices. The evidence pack below still helps, but the testing itself is the evidence.

    What belongs in the pack

    1. Asset list

    A current spreadsheet (or MDM export) of every laptop, desktop, mobile and server that touches business data. Columns: device name, owner, OS, OS version, last seen. Date-stamped at the top.

    2. Cloud service inventory

    Every SaaS and cloud platform the business uses, with: number of users, MFA status, admin contact. M365, Google Workspace, Xero, your CRM, your code repo, anything storing business data.

    3. MFA proof

    Screenshots from each major cloud service showing MFA enforced on all users. In M365 this is the Conditional Access policy or the Security Defaults toggle. In Google Workspace it's the 2-step verification report.

    4. Patching evidence

    A current report from your patching tool (Intune compliance, Jamf inventory, ManageEngine, even Windows Update for Business reports). For small teams, a short walkthrough video showing update settings on a sample device works.

    5. Account and leavers proof

    M365/Google admin export of all active accounts, cross-checked against the HR leavers list. A one-page leavers procedure showing who disables what within how many hours.

    6. Firewall and router config

    A short note (half a page) per location: device model, default password changed, no inbound services exposed, firmware version. For home workers, a one-line declaration covering home routers.

    7. Anti-malware status

    Screenshot of Defender / Jamf Protect / your AV admin console showing status across the fleet. For Macs, evidence of either AV or app-store-only installation policy.

    8. Three short policies

    • Acceptable use (one page).
    • Password and MFA policy (one page).
    • Bring-your-own-device policy (one page) – even if it's "no BYOD allowed".

    How to organise it

    One folder. Numbered subfolders matching the list above. Filenames with dates – asset-list-2026-06-01.xlsx, not asset-list-final-FINAL-v3.xlsx. Keep it in a place the submission owner can reach in two clicks.

    What you don't need

    A 60-page information security manual. SOC 2 reports. ISO 27001 documentation (helpful if you have it, not required). Cyber Essentials is deliberately scoped to be achievable by a small UK business in a few weeks, so the evidence bar is correspondingly modest – it just has to be real and current.

    Refresh annually at renewal

    Block out two hours the month before your renewal date and refresh every item in the pack. It cuts renewal effort dramatically. For more on the renewal flow see Cyber Essentials renewal and the readiness checklist.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions