How to get Cyber Essentials certification, step by step
8 September 2026 · 6 min read
Cyber Essentials is a self-assessed questionnaire verified by a certification body. You answer questions about five technical controls — firewalls, secure configuration, security updates, user access control and malware protection — across everything your organisation uses for work.
Step one is scope. List every device and cloud service your staff use: laptops, phones, home machines, email, file storage, accounting, CRM. Personal devices used for work count. Most failed assessments trace back to something that was left off this list.
Step two is the tidy-up. For each item in scope, confirm the five controls are genuinely in place: automatic updates switched on, multi-factor authentication enforced, no shared or dormant accounts, and supported software only. Write down what you checked and when — dated evidence is what separates a confident submission from a hopeful one.
Step three is the submission. You complete the questionnaire through a licensed certification body, and a director signs a declaration that the answers are accurate. Answer exactly what is asked; embellishment helps nobody.
Step four is the wait, which is usually short. If the assessor comes back with questions, answer them promptly and precisely. Once you pass, you receive a certificate valid for twelve months.
Kept walks you through steps one and two: the free scan shows where you stand, the policy generator produces the patching and access-control documents, and the evidence vault keeps a monthly snapshot so your next renewal starts from proof, not memory.