For anyone preparing a Cyber Essentials submission

Preparing for Cyber Essentials? See what an assessor can see.

Certification is a self-assessment questionnaire, but the parts of your setup that face the internet are visible to anyone. Check them before you submit, not after a question comes back.

Cyber Essentials is a UK certification scheme built around five basic controls. Two of them — secure configuration and security update management — leave traces an assessor can see from outside your network, and so can anyone else. This page explains which parts of the scheme are externally visible and what to tidy up before you submit.

What the scheme actually covers

Certification is a self-assessment questionnaire, verified against five control areas: firewalls, secure configuration, security update management, user access control and malware protection. Most of the evidence is internal — device settings, account policies, patching processes. What an external check adds is a view of the part you cannot see from the inside: what your internet-facing services are telling the world about themselves.

  • Firewalls and boundary devices
  • Secure configuration of systems and services
  • Security update management
  • User access control
  • Malware protection

What is visible from outside

An assessor reviewing your submission — or a competitor, or a researcher — can see the same public signals this check reads. They tend to be the ones that quietly contradict a questionnaire answer.

  • Services exposed to the internet that nobody remembered leaving open
  • Software versions advertised in responses, and whether known vulnerabilities apply to them
  • Transport security: certificate health and the protocol versions still accepted
  • Email authentication records, which sit alongside the scheme rather than inside it but are routinely asked about

Before you submit

The most common surprise is scope. Certification covers everything in the boundary you declare, and organisations tend to declare the main site while forgetting an old subdomain, a campaign microsite or a supplier-hosted portal that still carries their name. Running an external check across everything that answers to your domain is a cheap way to find those before the assessment does.

  • List every host that answers to your domain, not just the website
  • Close or firewall anything exposed that has no reason to be
  • Fix transport-layer items first — they are quick and unambiguous

Common questions

Does this certify us for Cyber Essentials?

No. Certification is issued by an accredited certification body following a self-assessment questionnaire. This is a pre-assessment check of externally visible signals, useful for finding gaps beforehand and nothing more.

Which of the five controls can an external check see?

Mainly secure configuration and security update management, because both leave visible traces in what your internet-facing services expose. Firewalls are partly inferable from what is reachable. User access control and malware protection are internal and are not assessed here.

We are going for Cyber Essentials Plus. Is this still useful?

Yes, for the same reason. Plus adds hands-on technical verification, so anything visibly wrong from outside is more likely to be noticed, not less.

Advisory only. This is an external check of publicly visible signals. It is not a Cyber Essentials assessment, it does not confer certification, and it does not cover the internal controls the scheme requires.

Start free — 5 domains, no card