64TEQ Tools Cyber Essentials readiness

Cyber Essentials readiness · free, runs in your browser

See how close you are to Cyber Essentials, in twenty questions.

Insurers, public sector buyers and larger customers increasingly ask suppliers for Cyber Essentials, and most small businesses are closer than they think. Twenty plain questions across the five controls give you a readiness read, the things that would fail the assessment outright and the fixes in the order that matters, with a rough time against each.

Cyber Essentials readiness

Would you pass Cyber Essentials this month?

Twenty plain questions across the five controls the assessment checks. You get a readiness read, the fixes in the order that matters and roughly how long each one takes.

Cyber Essentials is the UK government-backed baseline that insurers, public sector buyers and larger customers increasingly ask suppliers for. This is a readiness read against the published requirements (NCSC Requirements for IT Infrastructure version 3.3 and the IASME question set for assessments started after 26 April 2026), not the assessment itself: that is done through an IASME certification body. Four of the answers fail the assessment on their own rather than counting as a gap, and they are marked. Your answers stay in your browser.

Firewalls
01Every internet router or firewall has had its default password changed, and its admin screen is not reachable from the internet.

A home router that staff own is out of scope (one you supplied is in); the software firewall on their laptop is what counts.

02Nothing on the network accepts connections from the internet unless someone decided it should and wrote down why.

Port forwards for cameras, remote desktop or an old server are the usual culprits.

03The built-in software firewall is switched on for every laptop and desktop, including personal ones used for work.
Secure configuration
04Default passwords have been changed on every device and cloud service, and accounts nobody uses have been removed.

Includes printers, switches, the guest account on Windows and old shared logins.

05Software and apps nobody uses have been removed from company devices.
06Every device locks itself after a few minutes and needs a PIN of at least six digits, a password or a fingerprint to unlock, phones included.

Six is the published minimum for a PIN that only unlocks the device.

07People cannot install whatever they like: apps come from the official store or an approved list, and auto-run from USB is off.
Security update management
08Everything in use is still supported by its maker and licensed: operating systems, applications and router or firewall firmware. No Windows 10 without paid extended updates, no old Android or iOS, no abandoned apps.

IASME lists unsupported software in scope as an automatic fail. Windows 11 feature versions expire too; check each machine is on a version still receiving updates.

09Automatic updates are switched on for operating systems and applications on every device.
10Critical and high-risk updates for operating systems and for router and firewall firmware are installed within 14 days of release.

Question A6.4 on the form. An automatic fail since April 2026.

11Critical and high-risk updates for applications, browsers and their extensions are installed within 14 days of release.

Question A6.5 on the form, an automatic fail since April 2026. Browsers, Office, PDF readers and meeting apps are the usual stragglers.

User access control
12Admin rights sit on separate accounts used only for admin work, never for email or browsing.

A common failure: a director's daily Microsoft 365 or Google account is also the global admin.

13Multi-factor authentication is switched on for every user and every admin on every cloud service that offers it.

An automatic fail since April 2026. Cloud services cannot be left out of scope, and passkeys count.

14New accounts are created only when approved and removed the day someone leaves, and the list is reviewed at least quarterly.
15There is a written password rule: at least 12 characters (8 with MFA or a blocklist of common passwords), no reuse, a password manager and a lock or slow-down after no more than 10 failed attempts.
16There is an up-to-date list of every device and every cloud service in use, with who owns it and which OS version it runs.

The assessment form asks for devices by type and OS version, so you need this to fill it in.

Malware protection
17Anti-malware software is installed, updating itself and scanning on every laptop and desktop.
18Phones and tablets only run apps from the official app stores.
19Known malicious websites are blocked, by the anti-malware product, the browser or a DNS filter.
20Personal devices used for company email or files meet all of the above, and you have checked rather than assumed.

Bring-your-own devices are in scope the moment they touch company data. A ten-minute screen share per person is enough to check.

0 of 20 answered

Your readiness by control, anything that would fail the assessment outright and the fixes in order appear here.

How it works

Four steps, no account.

Answer twenty questions

Firewalls, secure configuration, updates, user access and malware protection, in plain words. Yes, partly, no or not sure.

See the read

A score per control, the answers that fail the assessment on their own and an honest overall: ready, nearly or not yet.

Fix in order

Each gap comes with what to do and roughly how long it takes. Most are an hour or half a day; the admin accounts one is the usual sticking point.

Book the assessment

Certification is through an IASME-licensed body. We help you prepare and can sit with you while you submit.

Straight answers

Questions about this tool.

Which version of the requirements is this against?
The published ones, not our own checklist: the NCSC Requirements for IT Infrastructure version 3.3 and the IASME question set for assessments started after 26 April 2026. The password rule, the 14-day update rule, the six-digit PIN and the multi-factor requirement are as written there, and the tool links to both.
Which answers fail the assessment on their own?
IASME names four: multi-factor authentication missing on a cloud service that offers it; critical or high-risk updates not applied within 14 days to operating systems and router or firewall firmware; the same 14-day rule missed for applications; unsupported software in scope. Everything else the assessor marks non-compliant gets two working days to fix and resubmit. Separate admin accounts are required too, but they are a gap to close rather than an automatic fail.
Do personal laptops and phones count?
Yes, the moment they touch company email or files. The assessment expects the same controls on them, and the safest way to prove it is to enrol them in device management rather than ask.
How is this different from the real assessment?
The real one is a longer question set answered under a director's declaration and checked by an assessor; this is twenty questions and your own honesty. It tells you whether to book the assessment now or in a month.
Does 64TEQ hold Cyber Essentials?
Our managed service partner holds Cyber Essentials Plus and ISO 27001. 64TEQ itself is working through this same list; when we certify, this page will say so.

Take the result to a person.

This tool is part of our managed it services work. A specialist reads what you found and says what we would do next, and if the answer is nothing, we say that.

Message a specialist on WhatsApp Speak to a person · 0203 858 0264 Email michelle.nayee@64teq.com