The 5 Cyber Essentials Controls Explained
A practical, NCSC-aligned breakdown of every Cyber Essentials control, what auditors look for, and the common pitfalls that cause first-time failures. Updated for the 2026 IASME requirements.
Cyber Essentials is the UK government-backed scheme set by the National Cyber Security Centre (NCSC) and delivered by IASME. Implementing the five controls below correctly stops around 80% of common internet-based attacks.
1. Firewalls
Boundary firewalls and software firewalls that protect every device connecting to the internet.
What auditors check
- Block all unauthenticated inbound connections by default.
- Change the default administrative password on every firewall.
- Disable remote administrative access from the internet (or protect with MFA).
- Document and approve all open inbound ports through a documented business case.
Common pitfall: Forgetting that home routers used by remote workers are in scope. Software firewalls on each device are usually the cleanest solution.
2. Secure Configuration
Build devices and software to a known-secure baseline, removing unnecessary functionality.
What auditors check
- Remove or disable unused user accounts.
- Change all default passwords and apply strong password policy or MFA.
- Disable auto-run/auto-play for removable media.
- Lock screens after no more than 10 minutes of inactivity.
Common pitfall: Inherited builds with old default accounts. Use a hardened build image or MDM baseline policy.
3. User Access Control
Grant users only the access they need to do their job – no more.
What auditors check
- Unique account for every user – no shared logins.
- Multi-factor authentication on all cloud services and admin accounts.
- Standard users cannot install software or change system settings.
- Documented joiner / mover / leaver process with prompt access revocation.
Common pitfall: Users running with local admin rights for convenience. Use a separate admin account that is only used when needed.
4. Malware Protection
Prevent malicious software from running on your devices using one of three approved approaches.
What auditors check
- Anti-malware software with daily updates and real-time scanning, OR
- Application allow-listing limiting execution to approved software, OR
- Sandboxing / containerisation that isolates untrusted code.
- Block access to malicious websites at the network layer where possible.
Common pitfall: Choosing allow-listing without the operational maturity to maintain it. For most SMEs, modern anti-malware (e.g. Microsoft Defender for Endpoint) is the practical choice.
5. Security Update Management
Keep all software and firmware patched against known vulnerabilities.
What auditors check
- Use only software that is licensed and supported by the vendor.
- Enable automatic updates where the vendor provides them.
- Apply high and critical severity patches within 14 days of release.
- Remove unsupported / end-of-life software from in-scope devices.
Common pitfall: Lingering Windows 10 devices after end-of-support, or unmanaged firmware on routers. Maintain a live software inventory.
Frequently Asked Questions
Need help implementing the 5 controls?
As an IASME accredited certification body, our qualified assessors walk you through every control from start to finish. 100% first-time pass rate.
Start your certification