Cyber Essentials Firewall Requirements (Boundary + Host)
Published 4 June 2026
What "firewall" actually means under Cyber Essentials
The scheme uses "firewall" to cover three things: the network device protecting your office, the software firewall on each laptop and desktop, and (for home workers) the broadband router. All three matter. A perfect office firewall doesn't help if a home worker's router still has its factory password.
Boundary firewall – the office or data centre device
For most UK SMEs this is the business-grade router from your ISP, a dedicated firewall (Sophos, WatchGuard, Fortinet, Meraki) or a cloud-managed device. Cyber Essentials expects:
- Default admin password changed.
- Admin interface not exposed to the internet.
- No inbound services exposed unless documented and justified (a business reason, with a date for review).
- Firmware reasonably up to date – not on the version that shipped two years ago.
- A documented configuration backup or change log.
Host firewall – every laptop and desktop
Every Windows machine should have Windows Defender Firewall enabled. Every Mac should have the Application Firewall enabled. Linux machines need ufw, nftables or equivalent active.
A common slip: developers' machines and "build" laptops with the firewall off "for convenience". The assessor will ask, and one machine off is enough to fail.
Home workers – the awkward middle
When a staff member works from home and their corporate laptop connects through their home broadband, the home router becomes a boundary device. Cyber Essentials' rule is sensible: the user must change the router's default admin password and ensure no unrequested inbound services are exposed.
You don't need to inspect every home router personally. A short BYOD/remote-working note that staff sign, plus a simple how-to, is the standard approach. Pair it with a host firewall on the corporate device and you've covered the requirement.
Cloud-only businesses
"We don't have an office network – everything's in AWS or M365" is increasingly common. You still have:
- Host firewalls on every laptop (mandatory).
- Cloud security groups / network ACLs around any production cloud workload (effectively your boundary).
- Home-router rules for remote workers, as above.
The certificate is still achievable; the answers just look different in the question set.
Common assessor flags
- One server with port 3389 (RDP) or 22 (SSH) open to the internet.
- An old "test" VPN endpoint nobody documented.
- A printer or NAS exposed via UPnP because the router shipped with it on.
- "We don't have a firewall, our ISP handles it" – not enough on its own.
- Software firewall disabled on a developer's laptop.
The simple proof pack
A half-page note per location: device model, default password changed (date), no inbound services exposed, firmware version. Plus a screenshot showing host firewall enabled on a sample of devices. That's the evidence most assessors are looking for. See our evidence pack guide for the wider list.
For the broader picture see the five controls breakdown and Cyber Essentials.
