What asset data does Cyber Essentials require?

Once the Cyber Essentials add-on is enabled, each of the five controls has specific fields you record against your devices, software, and user accounts. Here's exactly what feeds each control.

Firewalls & Secure Configuration (on Devices)

Open a device and fill in the Cyber Essentials section:

  • Firewall Enabled
  • Remote Admin (locked down or not)
  • Default Creds Changed
  • Hardening Baseline applied
  • Auto-run Disabled

Malware Protection (on Devices)

Also on each device record:

  • AV Product — the name of the anti-malware software installed
  • AV Real-time Scan — whether it scans in real time
  • AV Auto-update — whether definitions update automatically
  • AV Last Updated — when definitions last refreshed
!

Warning

"Real-time AV scanning not confirmed" on the Cyber Essentials page means exactly what it says — the AV Real-time Scan field on that device is blank or set to No. Update it on the device record to clear the issue.

Patch Management (on Devices and Software)

  • Devices: Auto-update OS, OS Last Patched
  • Software: Auto-update, Last Patched, Still Supported, EOL Date

User Access Control (on User Accounts)

  • Admin Account — whether the account has admin privileges
  • MFA Enabled — whether multi-factor authentication is turned on
!

Important

Under Cyber Essentials v3.3, an admin account without MFA is an automatic fail for the whole assessment when MFA is available on that service — not just a point deduction. Keep admin accounts to a minimum and confirm MFA on every one of them.

What's next