Skip to content
Compliance

Free Cyber Essentials Readiness Check: Test Your Compliance

Use Fig Group's free readiness checker to assess your organisation against the NCSC Cyber Essentials Requirements v3.3 before committing to formal certification.

A hand marks off items on a checklist

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Free Cyber Essentials Readiness Check: Test Your Compliance

Before spending money on Cyber Essentials certification, it makes sense to check whether your organisation is actually ready to pass. Fig Group offers a free readiness checker based on the NCSC Cyber Essentials Requirements v3.3 (effective 27 April 2026) that helps you identify areas to review before formal assessment. It is a preparation tool, not a certification decision or an exhaustive replacement for the current questionnaire.

Section 02

What Is the Readiness Checker?

The readiness checker is an interactive self-assessment tool that walks you through each of the five Cyber Essentials control categories:

1. Firewalls - Are your internet connections properly protected?

2. Secure Configuration - Are devices configured to reduce vulnerabilities?

3. Security Update Management - Is software kept up to date?

4. User Access Control - Are accounts managed with least privilege and MFA?

5. Malware Protection - Is the applicable anti-malware or approved code-signed application mechanism active and maintained?

For each category, you answer targeted questions about your organisation's current setup. The checker provides immediate feedback on your readiness.

Section 03

How Long Does It Take?

Allow approximately 10-15 minutes as a planning estimate; gathering missing IT details or reviewing gaps can take longer. You will need to know basic details about your IT environment:

  • How your firewall or router is configured
  • Whether all devices are running supported operating systems
  • Your patching and update approach
  • Whether cloud authentication uses MFA and MFA is implemented wherever available elsewhere
  • Which qualifying malware-protection route covers each device platform

If you manage your own IT, you should know most of this already. If you use a managed IT provider, they can provide the details you need.

Section 04

What Do You Get?

After completing the readiness check, you receive:

  • A clear indication of your readiness across all five control categories
  • Specific areas where your controls meet the requirements
  • Specific gaps that need addressing before formal certification
  • Guidance on how to remediate any issues found

This is not a pass/fail test - it is a diagnostic tool. The goal is to help you identify and fix gaps before you invest in formal assessment, so you can pass first time.

Section 05

Common Gaps the Checker Identifies

Practical gaps to review include:

Cloud MFA coverage - Authentication to cloud services must always use MFA, including ordinary users. Elsewhere implement MFA wherever available. Check effective enforcement, rather than registration alone.

Unsupported software - Devices running operating systems or applications that no longer receive security updates will fail the assessment. The checker asks about this specifically.

Default credentials - Routers, firewalls, and other devices that still use factory-default passwords are a common finding. Easy to fix, but easy to overlook.

Remote-worker scope handling - Many organisations forget that the laptop's software firewall must be configured for untrusted networks (home, hotel, coffee shop) once a worker is hybrid or fully remote. Note that ordinary privately owned home routers are out of scope; organisation-supplied routers are included. For private routers, the boundary follows the device that touches organisational data, not the home network.

Shared user accounts - v3.3 requires individual accounts for each user. Shared accounts are a compliance gap.

Section 06

From Readiness Check to Certification

If your answers suggest readiness, verify the underlying controls and complete the formal assessment; diagnostic results do not guarantee certification:

1. Visit Fig Group's Cyber Essentials pricing page

2. Select your organisation size band

3. Purchase your Cyber Essentials certification

4. Complete the self-assessment questionnaire using the current question set; the diagnostic is supporting preparation rather than a guarantee that every question has been covered

5. Submit complete compliant answers before midday on a UK business day for Fig Group’s six-working-hour certification guarantee

If the checker identifies gaps, fix them first. Most gaps (enabling MFA, changing default passwords, updating software) can be resolved in a few hours to a few days.

Section 07

Try It Now

The readiness checker is free, requires no account creation, with a suggested planning allowance of 10-15 minutes. There is no obligation to purchase certification afterwards - use it purely as a diagnostic tool if you prefer.

Take the readiness check now

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.

Request a demo

Related solutions

Continue exploring Fig Group