Viewee
Start free
Pricing
Sign in
← Legal and assurance

Requirements

RequirementWhat it means for VieweeOwner (Instinct / Alex+Cain / External assessor)EffortStatusEvidence neededSource URL
Use current scheme requirements (v3.3, April 2026)Prepare against v3.3 and the current IASME question set; do not claim certification until verified.Alex+CainMDo nowVersion-controlled readiness checklist and downloaded question sethttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Define and agree assessment scopeCover the whole business IT estate or a clearly bounded, separately managed subset; agree scope with the certification body and justify exclusions.Alex+CainMDo nowScope statement: business unit, network boundary, physical locations, exclusions and rationalehttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Include endpoints and remote/BYOD devicesFounder laptops and any personal devices accessing Viewee data/services are in scope; a scope excluding end-user devices is not acceptable. Home routers normally remain out of scope unless Viewee supplies them.Alex+CainMDo nowDevice register, ownership, OS/version, remote-working configurationhttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Include all cloud services and owned third-party accountsGoogle Workspace, code hosting, cloud hosting, monitoring, CRM/outreach admin and SaaS accounts used for Viewee must be assessed. Provider controls need contractual/trust-centre evidence.Alex+CainHDo now; finalise after vendors selectedCloud service register, shared-responsibility mapping, contracts/security statementshttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Maintain usable asset and software inventoryAsset management supports all five controls: track devices, software, services, versions, owners and support status.InstinctMDo nowAuthoritative asset/software/cloud inventory and review loghttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Protect every in-scope device with a firewallUse host firewall on laptops used on untrusted/home networks and cloud firewall/data-flow rules for hosted infrastructure.Alex+CainMDo now; extend when product liveEndpoint firewall screenshots/config export; cloud network ruleshttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Harden firewall administrationChange default admin passwords; prevent internet admin access unless documented and protected by MFA or tightly managed IP allow-list plus password.Alex+CainMDo now; extend when hosting chosenAdmin configuration, MFA evidence, documented exception/allow-listhttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Default-block unauthenticated inbound trafficInbound connections should be denied by default; each allowed inbound rule needs approval, business need and removal when no longer needed.Alex+CainMNeeds hosting architectureFirewall/security-group exports, approvals, rule-review loghttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Secure configuration baselineRemove unused accounts, software, utilities and services; change defaults; disable autorun; require authentication and device locking.Alex+CainMDo nowFounder device baseline and cloud/SaaS configuration checklistshttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Protect device unlockUse biometric/password/PIN; configure throttling or lock after no more than 10 failed attempts where possible; unlock PIN/password at least 6 characters.Alex+CainLDo nowMDM/OS policy screenshots or device check recordshttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Use supported and licensed softwareAll in-scope software must be licensed and vendor-supported; remove unsupported software or isolate it in a no-internet subset.Alex+CainMDo now and ongoingSoftware inventory with support/EOL dates and removal recordshttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Apply security updates within 14 daysEnable automatic updates where possible; install fixes within 14 days where vendor says critical/high, CVSS v3 is 7+, or severity is not given.Alex+CainMDo now and ongoingPatch policy, endpoint and dependency update reports, exception/remediation loghttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Approve and uniquely identify usersHave a process to create/approve accounts; use unique credentials; disable leavers and inactive accounts. Includes supplier/support accounts.Alex+CainMDo now; product process before launchJoiner/mover/leaver procedure, account lists, approvals and disablement evidencehttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Least privilege and privileged-account separationGrant only access needed; remove elevated access when no longer needed; use separate admin-only accounts, not for email/browsing.Alex+CainMDo now; extend before launchRole/access matrix, privileged-account register, access reviewshttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
MFA for cloud servicesAll authentication to cloud services must use MFA where available. Internet-accessible/admin accounts should always have MFA.Alex+CainMDo nowMFA enforcement exports for Workspace, GitHub, cloud and other SaaShttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Password controls where passwords remainProtect against guessing with MFA/throttling/lockout. Use 12+ characters, or 8+ with common-password deny-list, or MFA; no maximum restriction; do not force routine expiry; enable prompt reset on suspected compromise.Alex+CainMDo now; app control before launchIdentity-provider policy, password-manager standard, reset process and test evidencehttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Active malware protection on all devicesUse configured, updated anti-malware on Windows/macOS, application allow-listing, or sandboxed app-store model as applicable; block malicious code/sites.Alex+CainMDo nowEndpoint security status/export, update and policy evidencehttps://www.ncsc.gov.uk/sites/default/files/documents/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf
Complete verified self-assessmentAnswer the current IASME questionnaire accurately, retain evidence and remediate before submission; CE Plus, if pursued, adds independent technical testing.External assessorMAfter controls operateCompleted question set, assessor correspondence, remediation loghttps://iasme.co.uk/cyber-essentials/preview-the-self-assessment-questions-for-cyber-essentials/
Renew annually and manage material changeTreat certification as a point-in-time verified assessment and schedule annual renewal plus control reviews when estate/vendors change.Alex+CainLAfter certificationRenewal calendar and change-trigger review recordhttps://iasme.co.uk/cyber-essentials/frequently-asked-questions/