Skip to content
Guides

What are the five Cyber Essentials controls?

The five Cyber Essentials controls are: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations.

human hand

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

What are the five Cyber Essentials controls?

The five Cyber Essentials controls are: (1) boundary firewalls and internet gateways, (2) secure configuration, (3) user access control, (4) malware protection, and (5) security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations, assessed by IASME-licensed certification bodies under the Cyber Essentials scheme.

Section 02

1. Boundary firewalls and internet gateways

Every internet-facing boundary must be controlled by a firewall or equivalent network device with:

  • Default admin credentials changed from factory defaults
  • Only necessary ports and services exposed
  • Firmware current and supported
  • Organisation-supplied remote-worker routers are in scope; ordinary privately owned home routers are excluded under v3.3

See the full pillar guide: Cyber Essentials firewall requirements: what assessors actually check.

Section 03

2. Secure configuration

Devices, servers, and cloud services must be hardened against known weaknesses:

  • Unnecessary accounts removed or disabled and default/guessable passwords changed
  • Unused services removed
  • Auto-run disabled
  • Screen locks enforced
  • Secure baseline configuration applied

See the pillar guide: Secure Configuration for Cyber Essentials: the controls assessors expect to see.

Section 04

3. User access control

Every user has an individual named account; admin rights are separated from day-to-day accounts; authentication is strong:

  • Individual accounts for every real user
  • No shared interactive credentials
  • Admin / user account separation for anyone with admin rights
  • MFA enforced for every user on every cloud service in scope
  • MFA wherever available; phishing-resistant admin methods are recommended hardening, not a FIDO2-only mandate. Generic authenticator apps are not necessarily phishing-resistant
  • Documented joiner / mover / leaver process

See the pillar guide: User Access Control for Cyber Essentials v3.3.

Section 05

4. Malware protection

Use an active qualifying mechanism on every in-scope device. The NCSC requirements, pages 23-24, provide two options:

  • Windows/macOS anti-malware: updates according to the vendor, malware and malicious-code prevention, and blocking connections to malicious websites.
  • All-device application allow-listing: active approval, a maintained approved list and code-signing restrictions preventing unsigned or invalidly signed application installation.

Sandboxing is not a third route. Application allow-listing is not limited to high-risk estates, and a product name alone does not prove functional coverage.

See the pillar guide: Malware Protection for Cyber Essentials.

Section 06

5. Security update management

Software, firmware, and operating systems must be maintained within the defined patching windows:

  • Licensed and vendor-supported software, checking exact lifecycle and qualifying active extended-support arrangements
  • Fourteen days from release for vendor high/critical, CVSS v3 base score 7+ or unspecified-severity vulnerability fixes, including vendor-approved configuration fixes
  • Automatic updates where possible and effective update coverage; Intune, Jamf and MDM are optional management tools
  • Supported-version check applied to browsers, applications, and firmware

See the pillar guide: Security Update Management for Cyber Essentials v3.3.

Section 07

Why these five?

These controls address common internet-based attack routes, including unpatched software, weak access controls and unsafe default configurations. They are risk-reduction measures, not a universal quantified prevention guarantee.

They are deliberately narrow. They are not a complete security programme. But they are the baseline the UK government considers essential.

Section 08

How many questions cover the five controls?

Use IASME’s current question-set preview for the applicable version and branching questions. Counts and completion time depend on the question set and your estate; there is no fixed seventy-five-question total that applies to every applicant.

Section 09

Bottom line

The five Cyber Essentials controls - firewalls, secure configuration, user access, malware protection, and patching - are the UK's baseline cybersecurity standard. Fig Group guarantees certification within 6 working hours for complete compliant submissions received before midday on a UK business day, from £299.99 + VAT.

Start Cyber Essentials from £299.99 + VAT | All five pillar guides | Free readiness check

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group