Skip to main content
    NixInfinity-AI
    G-Cloud 15

    G-Cloud 15 Cyber Essentials Readiness Checklist for Suppliers

    Published 29 July 2026

    1. Scope decisions

    • Whole organisation vs delivery unit – most G-Cloud 15 suppliers certify the whole organisation to avoid scope disputes.
    • Cloud services in scope: Microsoft 365, Google Workspace, AWS/Azure/GCP tenants used to deliver the service.
    • BYOD policy documented – see BYOD rules.
    • Subcontractor scope confirmed – each in-scope supplier holds their own certificate.

    2. User access control

    • MFA enforced on every cloud user account, not just admins (Danzell 2026 tightening).
    • Admin accounts separated from day-to-day accounts.
    • Documented leaver process with evidence for the last three leavers.
    • Password policy meets 8+ characters with either MFA or 12-character alternative.

    3. Secure configuration

    • Default passwords changed on all devices and network kit.
    • Unused services and accounts disabled.
    • Auto-lock enabled on all devices.

    4. Malware protection

    • Anti-malware deployed on every in-scope device (Microsoft Defender is fine when configured).
    • Signature update schedule evidenced.
    • Mobile devices covered via MDM or app-store restriction.

    5. Security update management

    • Documented 14-day patch policy for high/critical vulnerabilities.
    • Patch status report from Intune, RMM or equivalent.
    • No unsupported operating systems in scope – check every server and end-user device.

    6. Firewalls and routers

    • Boundary firewall configured and admin password changed.
    • Host-based firewall enabled on every device.
    • Inbound services list documented with business justification.

    7. Evidence pack for the submission

    • Asset list (laptops, phones, servers, cloud tenants).
    • MFA enforcement screenshots.
    • Patch status export.
    • Admin account list with justification.
    • Anti-malware deployment evidence.

    8. G-Cloud 15 specific items

    • Certificate must be valid at contract award – plan renewal date around your bid window.
    • Save the PDF certificate and IASME registry link for the GCA supplier declaration.
    • If bidding on higher-impact lots, check whether CE Plus is called out.

    Fully prepared but running out of time? Our 24-hour fast-track is designed for this. The evergreen supplier page is at Cyber Essentials for G-Cloud suppliers; the framework-specific hub is G-Cloud 15 Cyber Essentials.

    Want us to run this checklist for you?

    30-minute call with a named IASME assessor to pressure-test your G-Cloud 15 readiness.

    Frequently Asked Questions

    Related Cyber Essentials Guides