// UK Standards
Cyber Essentials Compliance Software
UK government-backed scheme covering five technical controls: firewalls, secure configuration, access control, malware protection and patching.
Framework at a glance
Short name
Cyber Essentials
Version
—
Category
UK Standards
Controls
62
What Cyber Essentials covers
62 controls across 5 domains — every one tracked, owned and evidenced in Cyber Horizon.
Network Security
14 controls- A4.1 Do you have firewalls at the boundaries between your organisation’s internal networks, laptops, desktops, servers and the internet?
- A4.1.1 Do you have software firewalls enabled on all of your computers, laptops and servers?
- A4.1.2 If you answered no to question A4.1.1, is this because software firewalls are not installed by default as part of the operating system you are using? Please list the operating systems.
- A4.2 When you first receive an internet router or hardware firewall device, it may have had a default password on it. Have you changed all the default passwords on your boundary firewall devices?
- A4.2.1 Please describe the process for changing your firewall password. Home routers not supplied by your organisation are not included in this requirement.
System Hardening
10 controls- A5.1 Have you removed or disabled software and services that you do not use on your laptops, desktop computers, thin clients, servers, tablets, mobile phones and cloud services? Describe how you achieve this.
- A5.2 Have you ensured that all your laptops, computers, servers, tablets, mobile devices and cloud services only contain necessary user accounts that are regularly used in the course of your business?
- A5.3 Have you changed the default password for all user and administrator accounts on all your desktop computers, laptops, thin clients, servers, tablets and mobile phones that follow the Password-based authentication requirements of Cyber Essentials?
- A5.4 Do you run or host external services that provide access to data (that shouldn't be made public) to users across the internet?
- A5.5 If yes to question A5.4, which authentication option do you use? A. Multi-factor authentication, with a minimum password length of 8 characters and no maximum length B. Automatic blocking of common passwords, with a minimum password length of 8 characters a...
Vulnerability Management
16 controls- A6.1 Are all operating systems on your devices supported by a vendor that produces regular security updates and vulnerability fixes? If you have included firewall or router devices in your scope, the firmware of these devices is considered to be an operating sys...
- A6.2 Is all the software on your devices supported by a supplier that produces regular vulnerability fixes for any security problems?
- A6.2.1 Please list your internet browser(s). The version is required.
- A6.2.2 Please list your malware protection software The version is required.
- A6.2.3 Please list your email applications installed on end user devices and servers. The version is required.
Identity & Access
17 controls- A7.1 Are your users only provided with user accounts after a process has been followed to approve their creation? Describe the process.
- A7.2 Are all your user and administrative accounts accessed by entering unique credentials?
- A7.3 How do you ensure you have deleted, or disabled, any accounts for staff who are no longer with your organisation?
- A7.4 Do you ensure that staff only have the access privileges that they need to do their current job? How do you do this?
- A7.5 Do you have a formal process for giving someone access to systems at an “administrator” level and can you describe this process?
Endpoint Security
5 controls- A8.1 Are all of your desktop computers, laptops, tablets and mobile phones protected from malware by either: A - Having anti-malware software installed and/or B - Limiting installation of applications by application allow listing - for example, using an app stor...
- A8.2 If Option A has been selected: Where you have anti-malware software installed, is it set to update in line with the vendor's guidelines and prevent malware from running on detection?
- A8.3 If Option A has been selected: Where you have anti-malware software installed, is it set to scan web pages you visit and warn you about accessing malicious websites?
- A8.4 If Option B has been selected: Where you use an app-store or application signing, are users restricted from installing unsigned applications?
- A8.5 If Option B has been selected: Where you use an app-store or application signing, do you ensure that users only install applications that have been approved by your organisation and do you maintain this list of approved applications?
How Cyber Horizon automates Cyber Essentials
Every Cyber Essentials control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is Cyber Essentials?
UK government-backed scheme covering five technical controls: firewalls, secure configuration, access control, malware protection and patching.
How many controls does Cyber Essentials have?
Cyber Essentials has 62 controls in Cyber Horizon's catalogue, organised across 5 domains.
How does Cyber Horizon help with Cyber Essentials?
Cyber Horizon maps Cyber Essentials into a shared control library alongside every other framework you run, so evidence collected once counts towards Cyber Essentials and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
See Cyber Essentials mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of Cyber Essentials in Cyber Horizon.