What are the five Cyber Essentials controls?
The five Cyber Essentials controls are: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations.

Section 01
What are the five Cyber Essentials controls?
The five Cyber Essentials controls are: (1) boundary firewalls and internet gateways, (2) secure configuration, (3) user access control, (4) malware protection, and (5) security update management. Together they form the NCSC's baseline of technical cybersecurity expectations for UK organisations, assessed by IASME-licensed certification bodies under the Cyber Essentials scheme.
Section 02
1. Boundary firewalls and internet gateways
Every internet-facing boundary must be controlled by a firewall or equivalent network device with:
- Default admin credentials changed from factory defaults
- Only necessary ports and services exposed
- Firmware current and supported
- Organisation-supplied remote-worker routers are in scope; ordinary privately owned home routers are excluded under v3.3
See the full pillar guide: Cyber Essentials firewall requirements: what assessors actually check.
Section 03
2. Secure configuration
Devices, servers, and cloud services must be hardened against known weaknesses:
- Unnecessary accounts removed or disabled and default/guessable passwords changed
- Unused services removed
- Auto-run disabled
- Screen locks enforced
- Secure baseline configuration applied
See the pillar guide: Secure Configuration for Cyber Essentials: the controls assessors expect to see.
Section 04
3. User access control
Every user has an individual named account; admin rights are separated from day-to-day accounts; authentication is strong:
- Individual accounts for every real user
- No shared interactive credentials
- Admin / user account separation for anyone with admin rights
- MFA enforced for every user on every cloud service in scope
- MFA wherever available; phishing-resistant admin methods are recommended hardening, not a FIDO2-only mandate. Generic authenticator apps are not necessarily phishing-resistant
- Documented joiner / mover / leaver process
See the pillar guide: User Access Control for Cyber Essentials v3.3.
Section 05
4. Malware protection
Use an active qualifying mechanism on every in-scope device. The NCSC requirements, pages 23-24, provide two options:
- Windows/macOS anti-malware: updates according to the vendor, malware and malicious-code prevention, and blocking connections to malicious websites.
- All-device application allow-listing: active approval, a maintained approved list and code-signing restrictions preventing unsigned or invalidly signed application installation.
Sandboxing is not a third route. Application allow-listing is not limited to high-risk estates, and a product name alone does not prove functional coverage.
See the pillar guide: Malware Protection for Cyber Essentials.
Section 06
5. Security update management
Software, firmware, and operating systems must be maintained within the defined patching windows:
- Licensed and vendor-supported software, checking exact lifecycle and qualifying active extended-support arrangements
- Fourteen days from release for vendor high/critical, CVSS v3 base score 7+ or unspecified-severity vulnerability fixes, including vendor-approved configuration fixes
- Automatic updates where possible and effective update coverage; Intune, Jamf and MDM are optional management tools
- Supported-version check applied to browsers, applications, and firmware
See the pillar guide: Security Update Management for Cyber Essentials v3.3.
Section 07
Why these five?
These controls address common internet-based attack routes, including unpatched software, weak access controls and unsafe default configurations. They are risk-reduction measures, not a universal quantified prevention guarantee.
They are deliberately narrow. They are not a complete security programme. But they are the baseline the UK government considers essential.
Section 08
How many questions cover the five controls?
Use IASME’s current question-set preview for the applicable version and branching questions. Counts and completion time depend on the question set and your estate; there is no fixed seventy-five-question total that applies to every applicant.
Section 09
Bottom line
The five Cyber Essentials controls - firewalls, secure configuration, user access, malware protection, and patching - are the UK's baseline cybersecurity standard. Fig Group guarantees certification within 6 working hours for complete compliant submissions received before midday on a UK business day, from £299.99 + VAT.
Start Cyber Essentials from £299.99 + VAT | All five pillar guides | Free readiness check
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Does Cyber Essentials protect against ransomware?
Cyber Essentials addresses ransomware risks through five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. MFA is an important requirement within the applicable controls; recovery needs additional measures.
Read articleGuides
Does Cyber Essentials cover GDPR?
No - Cyber Essentials does not cover GDPR. Cyber Essentials is a technical cybersecurity baseline; GDPR is a data-protection regulation covering lawful basis, rights, transfers, and accountability. They overlap at the technical-security boundary but neither replaces the other.
Read articleTechnical Guides
Cyber Essentials for AWS: configuration guide
How to configure an AWS account for Cyber Essentials v3.3 - IAM with MFA, SCPs, Security Hub baseline, Security Groups, and Systems Manager Patch Manager. Specific settings and evidence expectations.
Read article

