Cybersecurity

Cyber Essentials for small businesses: a 2026 checklist

8 min read

The UK government scheme is now a buying requirement as often as it is a security project. Here is what to fix before you sit the assessment.

Preparing a Cyber Essentials checklist in a UK small-business office

Cyber Essentials used to sit in the “nice to have” pile for many Hampshire SMEs. In 2026 it is a buying requirement. Insurers, councils, NHS trusts and larger customers increasingly ask for a current certificate before they will work with you — or before they will renew cover.

This is a practical checklist for small businesses, not a recitation of the scheme brochure. If you want Axis IT to run the technical work, start with managed cyber security or the contact form.

What Cyber Essentials actually is

It is a UK government-backed certification, aligned with NCSC guidance, that confirms you have five families of control in place: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. The point is not to turn a ten-person firm into a bank. It is to close the holes commodity ransomware and account-takeover still walk through.

There are two levels. Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds an independent technical test of devices and the network boundary. Start with Essentials unless a tender already specifies Plus.

Why small businesses are being asked for it now

Three pressures landed at once. Public-sector and NHS supply-chain contracts treat the certificate as a hygiene factor. Cyber insurers use it as a proxy for “you have done the basics”, and premiums or excesses move when you cannot show it. And customers who have already certified do not want an uncertified supplier as the weak link.

If you still run on break-fix IT, the assessment will surface that immediately. The managed IT model exists partly so those controls stay true after the certificate is on the wall.

The 2026 checklist before you sit the assessment

Work through these in order. Most failed or delayed assessments are not mysterious — they are MFA, admin accounts, or unpatched servers.

1. Know what is in scope

List every internet-connected device, cloud tenant and user account that can reach business data: laptops, servers, firewalls, Microsoft 365, phones used for email, and any home PCs that still have VPN access. If you cannot name the estate, you cannot certify it. A simple asset list is enough at this size — it does not need a CMDB.

2. Turn on MFA everywhere that holds mail or files

Multi-factor authentication on Microsoft 365, remote access, VPN, banking and any cloud admin portal is non-negotiable. SMS is better than nothing; an authenticator app or phishing-resistant method is better still. Shared mailboxes with a single password and no MFA are a common fail.

3. Shrink who is an administrator

Day-to-day work should run as a standard user. Named admin accounts, used only for admin work, with MFA. No generic “admin” logins on the firewall, the server or Microsoft 365. Starters and leavers need a written process so access dies on the last working day, not “when someone remembers”.

4. Patch on a calendar, not when something breaks

Windows, Microsoft 365 apps, browsers, firewalls and firmware need a defined cadence. Automatic updates on laptops are fine. Servers and firewalls need a window and an owner. End-of-life operating systems — including any Windows 10 boxes still lingering after October 2025 — will block certification until they are upgraded or isolated.

5. Put a real firewall at the edge

The office internet connection needs a business firewall with a default-deny inbound policy, not a consumer router in “exposed host” mode. Remote access should be via VPN or a hosted desktop with MFA, not port-forwarded RDP. Home workers need the same rule: no accidental exposure of the company tenant through a domestic router.

6. Malware protection that you actually manage

Consumer antivirus ticking in the system tray is not enough. You want central visibility, a current signature or behavioural engine, and someone looking at alerts. On Axis IT packages that is XDR as standard on managed cyber. Turn off local admin rights so staff cannot uninstall it “because it was slow”.

7. Backups you have restored this quarter

Cyber Essentials is not a backup certification, but assessors and insurers will still ask. Daily backups, offsite or immutable copies, and a restore test you can describe. If ransomware landed tomorrow, could you recover Microsoft 365 and file data without paying? That is the same question we cover in our ransomware guide.

Cyber Essentials vs Plus — which should you book?

Book Essentials first unless a tender already names Plus. Plus will probe devices and the boundary: unpatched laptops, open ports, and weak Wi-Fi will fail it even if the questionnaire looked clean. Treat Plus as a technical audit you prepare for, not a badge you buy.

What Hampshire SMEs usually get stuck on

The same three issues come up in Portsmouth, Southampton and the surrounding towns: leftover Windows 10 machines, Microsoft 365 tenants that were set up years ago with no MFA or Secure Score work, and a firewall that has never had a rule review. None of those are expensive to fix. They are expensive to ignore once a buyer or insurer sets a deadline.

How Axis IT runs the process

We inventory the estate, close the five controls, tighten Microsoft 365, and stay with you through the assessment. On-site engineers cover Portsmouth, Southampton, Havant, Waterlooville and Hayling Island; remote work covers the rest of Hampshire. Call 02394 331 999 or use the contact form if you want a date, not a brochure.

Still have Qs?

Questions we often get asked

Still have questions? Contact us

What is Cyber Essentials?

Cyber Essentials is a UK government-backed scheme, run with the NCSC, that certifies a baseline of technical controls: firewalls, secure configuration, user access control, malware protection and patch management. It is aimed at organisations of every size, including small businesses.

Do small businesses need Cyber Essentials in 2026?

If you bid for public-sector work, sit in an NHS or local-authority supply chain, or renew cyber insurance, you will often be asked for a current certificate. Even where it is not mandatory, it is the clearest way to prove you have the basics in place.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment against the five controls, independently verified. Plus adds a hands-on technical audit of devices and the boundary. Many buyers now want Plus for higher-risk contracts.

How long does Cyber Essentials take for an SME?

If Microsoft 365, patching, MFA and backups are already well managed, the questionnaire can be completed in days. If those controls are missing, the implementation work is the real timeline — often two to six weeks with an MSP.

Can Axis IT help us get certified?

Yes. We implement the five controls on Hampshire estates, tighten Microsoft 365, and support both Cyber Essentials and Cyber Essentials Plus assessments as part of managed cyber.

Ready to talk?

Get Cyber Essentials-ready without the guesswork.

We will tell you what is already in place, what would fail an assessment, and what a managed package looks like for your estate.

Call us