Cyber Essentials for UK SMEs: A Practical Prep Checklist Before You Apply

Cyber Essentials is a UK government-backed scheme designed to help organisations put a solid baseline of cybersecurity controls in place. For many SMEs, it becomes important for one of three reasons.

Blog Main Image

Cyber Essentials is a UK government-backed scheme designed to help organisations put a solid baseline of cybersecurity controls in place. For many SMEs, it becomes important for one of three reasons:

  • A customer or partner asks for it as part of procurement
  • You need it to bid for certain contracts
  • You want clearer assurance for insurers and stakeholders

If that sounds familiar, the good news is that preparing for Cyber Essentials is usually less about buying lots of new tools and more about tightening everyday controls you may already have.

This guide is a practical, non-technical checklist to help you get ready before you apply, so you avoid last-minute scrambles, inconsistent answers, or changes that disrupt the business.

1) Start with a clear "scope" (what's included?)

Before you do anything else, decide what systems are in scope for your Cyber Essentials assessment. This matters because your answers must reflect what's actually protected.

For a typical UK SME, the key items to consider are:

  • Company laptops and desktops (including home-working devices if they access business systems)
  • Mobile devices that access company email or files
  • Your firewall/router and Wi-Fi setup
  • Microsoft 365 or Google Workspace accounts
  • Servers or hosted services you manage

If you keep scope too broad, you create unnecessary work. If you keep it unrealistically narrow, you may not get the business value you want.

A practical approach is to include the systems people use to access email, files and core business apps, and the accounts that can administer those systems.

2) Make account access "boring" (and controlled)

Access is where many SMEs quietly build risk over time: old accounts, shared logins, admin rights that were granted "temporarily" and never removed.

Your prep checklist:

  • List your admin accounts. Identify who has administrator access to Microsoft 365, endpoints, your firewall, and any line-of-business platforms.
  • Remove shared admin logins. Admin access should be traceable to an individual.
  • Check leavers and dormant accounts. Disable or remove accounts that are no longer needed.
  • Use the principle of least privilege. People should have the minimum access needed for their role.

This improves security and makes your Cyber Essentials answers easier, because you can confidently describe who can administer your systems.

3) Turn on MFA in the right places

Multi-factor authentication (MFA) is one of the most effective ways to reduce account takeover risk. Many SMEs have it enabled for some users but not consistently for admins, remote access, or legacy sign-ins.

A practical minimum:

  • MFA for Microsoft 365 (or your email platform), especially for anyone with access to shared mailboxes, finance, or confidential documents
  • MFA for admin accounts, no exceptions
  • MFA for remote access: VPN, remote desktop tools, and any portals that can reach internal systems

Also consider the user experience. If MFA is inconsistent, people will try to "work around" it. A consistent, well-communicated setup is safer and reduces support noise.

4) Get patching and updates under control (not perfect)

Cyber Essentials expects you to be managing updates. The goal is not to claim you update everything instantly, but to have a sensible process that applies updates reliably, covers the devices and software you actually use, and avoids leaving known vulnerabilities unpatched for long periods.

Your checklist:

  • Confirm Windows Update / macOS update policies are enabled and enforced
  • Check browsers and productivity apps (e.g., Microsoft 365 apps) update automatically
  • Identify your key business apps (accounting, CRM, industry tools) and confirm an update approach
  • Make sure "end-of-life" systems are identified so you can plan replacements

Where SMEs often get stuck is when updates are managed ad-hoc: one person clicks "remind me tomorrow" for weeks, or updates happen only when something breaks. A managed approach makes downtime less likely, not more, because you control change rather than letting it surprise you.

5) Review device security: laptops, mobiles and lost devices

If someone leaves a laptop on a train or a phone is stolen, you want to be confident that company data is protected.

Basics to confirm:

  • Device encryption is enabled (so data isn't readable if a device is lost)
  • A strong sign-in method is required (PIN/password/biometrics depending on the platform)
  • Devices lock automatically after a short idle period
  • You can remotely wipe a device if it's lost

If you already use Microsoft 365, device management and security policies can often be improved significantly without buying a new stack. It's about configuring what you have.

6) Make sure your firewall and Wi-Fi aren't "set and forget"

For many SMEs, the firewall is treated like a one-time install. Over time, remote access rules, port forwards, and "temporary" exceptions accumulate.

A sensible prep review:

  • List any inbound rules/port forwards and challenge whether they're still needed
  • Confirm remote access is controlled (and protected by MFA)
  • Separate guest Wi-Fi from business systems
  • Make sure the admin interface isn't exposed unnecessarily

You don't need the most expensive firewall in the world, but you do need one that's properly configured and kept up to date.

7) Standardise how malware protection is handled

Cyber Essentials expects malware protection appropriate to your systems.

In practice, you want a consistent approach across devices (not "some have X, others have nothing"), central visibility so you can see if protection is disabled, and clear handling of detections (who gets alerted, what happens next).

Many SMEs rely on built-in protections and that can be fine when configured properly. The key is consistency and oversight.

8) Document your answers (and the evidence behind them)

One of the most useful things you can do before applying is to write down what you will answer for each control area, who owns that area internally (even if IT is outsourced), and where the "evidence" is (screenshots, policy statements, configuration notes).

This saves a huge amount of time if you need to renew later, onboard a new team member, or answer security questionnaires from customers. It also reduces the risk of accidentally giving inconsistent answers, which can lead to rework or uncomfortable conversations.

9) Do a small "gap check" before you book time for the application

At this point, you should have a clear view of what's already in place, what needs to be tightened, and what decisions are needed from leadership (e.g., replacing old devices, enforcing MFA, removing legacy access).

A short gap check with a trusted IT partner can be the difference between a smooth application and a frustrating one. The aim is to reduce surprises.

10) Keep it practical: reduce risk and disruption

Cyber Essentials should support day-to-day business, not become a box-ticking exercise that everyone resents.

A simple way to keep it grounded is to link each control back to a business outcome. MFA and controlled admin access reduces the chance of fraud and account takeover. Reliable patching reduces the chance of avoidable downtime. Device protection reduces the impact of lost or stolen equipment. Firewall and remote access hygiene reduces the risk of external compromise.

When these basics are handled well, your team can work confidently, and you're in a stronger position with customers, insurers and partners.

How Managed Technology Group Can Help

If you're preparing for Cyber Essentials and want a practical, non-disruptive plan, Managed Technology Group can help you review your current setup, tighten the essentials, and get your environment ready for assessment.

Our focus is on outcomes: reducing risk, keeping people productive, and making security feel manageable, Your Technology, Managed the Right Way.

If you'd like, we can start with a short discovery call to understand your scope, your current tooling (especially Microsoft 365), and the quickest improvements that will make the biggest difference.

Ready to Work With an IT Company That Actually Gives a Damn?

Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.

IT Review Consultation