← All articles

Which policies do you need for Cyber Essentials?

27 August 2026 · 5 min read

Cyber Essentials is a technical assessment, not a paperwork exercise, but a handful of short documents make the questions far easier to answer — and they are what larger customers request during due diligence.

A patching and updates policy states how quickly security updates are applied, who is responsible, and what happens to devices that fall out of support. Assessors expect critical updates within fourteen days.

An access control policy covers how accounts are created, who approves administrative access, how multi-factor authentication is enforced, and how quickly leavers are removed. Same-day removal is the answer buyers want to see.

A device and acceptable use policy sets out what staff may use for work, including personal laptops and phones, and what basic protections those devices must have: screen locks, encryption, automatic updates and current malware protection.

An incident response note — even a single page — names who to contact, what gets recorded and when customers are told. It is short, and it is the document people are most grateful for on a bad day.

Keep each one to a page or two in plain English. Kept generates all of them from your own answers and keeps them versioned, so the copy you show an assessor matches the way you actually work.