SOLVBEAT
Home › Blog › Cyber Essentials evidence checklist: exactly what you need to submit

Cyber Essentials evidence checklist: exactly what you need to submit

Published 30 September 2026 · Solvbeat

To achieve Cyber Essentials you must submit a defined set of evidence. The evidence consists of documented policies, configuration screenshots, test results and a signed declaration. You will need to provide these items for each of the five technical controls covered by the scheme.

What the Cyber Essentials scheme expects

The Cyber Essentials programme looks at five core areas: secure configuration, boundary firewalls and internet gateways, access control, patch management and malware protection. For each area the assessor requires proof that you have put the required controls in place and that they are being maintained. The evidence is not a full audit; it is a snapshot that shows the controls are working today.

Core evidence categories

All evidence falls into one of four categories. Knowing the category helps you collect the right artefacts without chasing unnecessary paperwork.

How to gather each piece of evidence

Collecting the right files can feel like a chore, but a systematic approach keeps it quick.

1. Policies and procedures

Start with the documents you already have. Most small businesses maintain at least a basic Acceptable Use Policy and a Password Policy. If a formal Patch Management Procedure is missing, draft a one‑page outline that covers:

Save each document as a PDF and name it clearly, for example Password_Policy.pdf. The assessor will open the file and look for the key clauses listed in the Cyber Essentials guidance.

2. Configuration screenshots

Log into each device that forms part of your perimeter and internal security. For a typical small office you will have a router, a firewall appliance or a cloud‑based gateway, and a Windows or Linux server.

Label each file with the device name and date, for example Router_Firewall_Rules_2024-09-15.png. The assessor checks the date to confirm the evidence is recent.

3. Test and verification reports

Run a basic external scan against any public IP addresses you own. Free tools such as Qualys FreeScan or Nessus Essentials will produce a PDF report. The report should include:

If the scan shows a vulnerability, fix it first, then re‑run the scan and keep the clean report. The assessor expects to see a clear “no critical findings” result for the external test.

4. Signed declaration

The final piece is a one‑page statement signed by a director or senior manager. The wording is provided in the Cyber Essentials application portal; you simply need to add the name, title and signature. Print, sign and scan the page, or use a digital signature if your organisation accepts it.

Common pitfalls to avoid

Even with the right evidence, small mistakes can cause a rejection.

Using Solvbeat to simplify the process

Solvbeat offers a free website scanner that checks many of the technical controls covered by Cyber Essentials. The scan highlights missing patches, insecure headers and open ports, giving you a clear starting point for your evidence collection. While Solvbeat is not an accredited certification body, the reports it generates align closely with the evidence the assessor expects.

Running the scan also produces a PDF summary you can attach to your application as supplementary proof of your current security posture. Pair that with the policy documents and screenshots you have prepared, and you will have a complete, tidy package ready for submission.

Ready to see what you need to fix before you start gathering evidence? Run a free scan →

See your website the way a hacker does.
Free scan — no login, no card — a clear report in under a minute.
Run a free scan →