Free website security check
Preparing for Cyber Essentials? Start with what anyone on the internet can already see. Enter your domain for a passive check of your website's TLS, certificate, security headers and email records.
What Cyber Essentials actually tests
Be clear about what this page is: the checks above are good security practice, not Cyber Essentials requirements. The current requirements (v3.3) say nothing about TLS versions or HTTP security headers. A missing header won't fail you, and a clean result here won't pass you.
The secure configuration control is about removing unnecessary accounts, software and network services, and changing default passwords. The firewalls control is about which services are reachable from the internet at all, and whether each one has a documented reason to be. In a Cyber Essentials Plus external scan, any internet-reachable service with a vulnerability scoring 7.0 or more is a fail — there is no 14-day grace period on that test.
None of that is visible from one homepage request. It needs every exposed service on every address you own enumerated, versioned and checked against known vulnerabilities — which is a scan, and a scan needs your permission. That is what CyberSpec's readiness scanning does, after you verify you own the domain.
How this check works
One ordinary HTTPS visit to your homepage (exactly what a browser does), one plain-HTTP visit to see if it redirects, and public DNS lookups for SPF and DMARC. No port scanning, no probing, nothing a normal visitor wouldn't do. We don't store the domain you check.
This is a readiness indicator, not a certification. Cyber Essentials certification is issued by IASME and its certification bodies.