CyberSpec

Cyber Essentials: the five controls, the 2026 rules, and what a scan can check

Cyber Essentials is the UK government-backed certification run by IASME on behalf of the NCSC. It covers five technical controls. Three of them are largely visible from the internet, and two are not. Knowing which is which tells you what to fix and what you have to vouch for yourself.

The five controls under v3.3

From the NCSC's Requirements for IT Infrastructure v3.3 (April 2026), with an honest note on what an external scan can see for each.

Firewalls

Block unauthenticated inbound connections by default. Every inbound rule is approved, documented and has a business need. An admin interface is not reachable from the internet unless there is a documented need and it is protected by MFA or an IP allow list.

Visible to an external scan: Mostly. A scan sees which services answer from the internet. It cannot see whether each one has an approved business need written down.

Secure configuration

Remove or disable unnecessary accounts, software and network services. Change default or guessable passwords. Disable auto-run.

Visible to an external scan: Partly. A scan sees exposed services and files that usually should not be public. It never tries passwords, so default credentials stay invisible to it.

Security update management

All software is licensed and supported. Unsupported software is removed or cut off from the internet. Critical and high-risk updates are installed within 14 days of release.

Visible to an external scan: Mostly. A scan sees end-of-life versions and known vulnerabilities on internet-facing services. Laptops and internal systems are out of its reach.

User access control

Accounts are approved, unique and removed when no longer needed. Admin accounts are used only for admin work. MFA is on wherever available, and always for cloud services.

Visible to an external scan: No. This is about how accounts are run inside the organisation.

Malware protection

Every in-scope device has active anti-malware software or application allow-listing, kept up to date and configured to stop malicious code and websites.

Visible to an external scan: No. This lives on each device.

What changed in 2026

Assessment accounts created after 26 April 2026 use v3.3 and the Danzell question set. Older accounts had six months to finish on the previous rules, so from around 27 October 2026 every basic assessment is v3.3. Three areas became automatic fails: MFA on cloud services, and the two questions on installing critical and high-risk updates within 14 days (A6.4 for operating systems and firmware, A6.5 for applications). Cloud services can no longer be excluded from scope, and every legal entity in scope must be named. The full list of changes.

Cyber Essentials or Cyber Essentials Plus

Basic Cyber Essentials is a self-assessment questionnaire, verified by a certification body. Cyber Essentials Plus adds a hands-on technical audit: an external vulnerability scan of every internet-facing service in scope, an authenticated scan of a sample of devices, and tests of how email and browsers handle malicious files.

The external scan is the strict part. Any internet-facing service with a vulnerability scoring 7.0 or more fails, with no grace period. The 14-day window only applies to the sampled-device scan. How the CE Plus scan decides.

Where assessments usually fail

  • Unsupported software still running on an in-scope system. Why it is an automatic problem.
  • A known vulnerability scoring 7.0 or more on an internet-facing service on the day of the CE Plus scan.
  • A cloud service without MFA, which is now an automatic fail in the self-assessment.
  • Services open to the internet with no documented reason. The usual suspects.
  • A declared scope that leaves out systems which are actually reachable.

Cyber Essentials guides

Check your own exposure

The free website security check reads your TLS setup, certificate, security headers and email records without scanning ports or signing up. Those are good-practice checks rather than Cyber Essentials requirements, and the tool labels them that way.

CyberSpec's continuous scanning goes further on the assets you verify you own: open services, known vulnerabilities with their CVSS scores and how long each has been open, and end-of-life software. On the Pro plan, a readiness view reads those findings against the three controls a scan can measure, records your own statement for the two it cannot, and lists what the scan could not check. It reports readiness. Certification comes only from IASME and its certification bodies.