Cyber Essentials readiness
Cyber Essentials For SMEs: What Should You Prepare?
A practical guide to the five Cyber Essentials control areas and the evidence SMEs usually need before assessment.
The short answer
Cyber Essentials focuses on five control areas: firewalls, secure configuration, user access control, malware protection, and security update management. Managed IT can support readiness evidence, but certification and Cyber Essentials Plus are separate.
The takeaways
- Cyber Essentials focuses on five practical technical control areas.
- Preparation is easier when devices, users, admin access, and update status are already documented.
- Secure Complete supports readiness and evidence, but certification outcomes are not guaranteed.
What are the five Cyber Essentials control areas?
| Control area | What it is trying to prove | Useful SME evidence |
|---|---|---|
| Firewalls | Internet-facing access is controlled. | Firewall status notes, exposed service notes, and recommendations for risky rules. |
| Secure configuration | Devices and services are configured securely enough for normal use. | Baseline notes, local admin review, browser/security settings, and exception list. |
| User access control | People have appropriate access and privileged access is controlled. | User lists, admin roles, MFA status, leaver records, and access exceptions. |
| Malware protection | Devices have suitable protection against malicious software. | Endpoint protection status and managed device coverage notes. |
| Security update management | Supported software is kept up to date. | Patch status, supported software list, unsupported software notes, and exceptions. |
What should you prepare first?
- List in-scope devices, operating systems, and owners.
- Confirm supported software and remove or replace unsupported software where appropriate.
- Review admin accounts and privileged access.
- Confirm MFA or stronger sign-in controls for key cloud services.
- Check malware protection or endpoint protection status.
- Review patch status and exceptions.
- Document joiner and leaver processes.
- Collect policy notes for personal device use if it applies.
How can Secure Complete help remotely?
Device and software records
Secure Complete can help maintain practical records for device assignment, managed status, update status, and endpoint protection status.
Access review
User access control becomes easier when joiner, mover, and leaver steps are documented and admin access is reviewed regularly.
Patch rhythm
Security update management needs a repeatable process, not a last-minute scramble before assessment.
Readiness evidence
Secure Complete includes readiness tracking and evidence conversations, alongside monthly security scorecards and quarterly security reviews.
What are the important limits?
Secure Complete is Cyber Essentials readiness support, not a certification guarantee. The business still needs accurate scope, evidence, decisions, and truthful answers.
Certification fees are separate unless a proposal explicitly includes them, and certification should be completed through an appropriate certification body.
Cyber Essentials Plus is separately scoped because it depends on testing scope, network complexity, and assessment route. Kindura's public packages should not imply in-person Cyber Essentials Plus assessment activity or a guaranteed pass.
Questions to ask any provider
Use these on any Cyber Essentials support proposal - including ours. Avoid vague compliance promises.
- Are you supporting readiness, certification, assessment, or Cyber Essentials Plus?
- Which evidence will you help collect for the five control areas?
- What still needs a decision or truthful answer from the business?
- Are certification body fees included or separate?
- What happens if devices, software, or access records are incomplete?
Where Kindura fits
Kindura supports readiness, not guaranteed certification
Kindura's Secure Complete package supports Cyber Essentials readiness evidence remotely, including device, access, patching, and control-area review. Certification fees, formal assessment, and Cyber Essentials Plus are separate unless written into a proposal. Whether or not that suits you, we will not describe readiness work as a guaranteed pass.
Related resources
Checklist
Device And Patch Management Checklist: What Should SMEs Track?
A practical checklist for SME device inventory, ownership, patch status, endpoint protection, unsupported software, exceptions, and monthly review.
Guide
Microsoft 365 Security: What Should Small Businesses Review?
A practical Microsoft 365 security guide for SMEs covering MFA, admin access, mail and file sharing, devices, leavers, and monthly review.
Checklist
SME IT Operations Checklist: What Should You Review Monthly?
A practical monthly checklist for keeping devices, users, access, patching, support trends, suppliers, and security basics visible in a growing SME.