Cyber Essentials evidence checklist: exactly what you need to submit
To achieve Cyber Essentials you must submit a defined set of evidence. The evidence consists of documented policies, configuration screenshots, test results and a signed declaration. You will need to provide these items for each of the five technical controls covered by the scheme.
What the Cyber Essentials scheme expects
The Cyber Essentials programme looks at five core areas: secure configuration, boundary firewalls and internet gateways, access control, patch management and malware protection. For each area the assessor requires proof that you have put the required controls in place and that they are being maintained. The evidence is not a full audit; it is a snapshot that shows the controls are working today.
Core evidence categories
All evidence falls into one of four categories. Knowing the category helps you collect the right artefacts without chasing unnecessary paperwork.
- Policy documents-written statements that describe how you manage a particular control. Examples include an Acceptable Use Policy, a Password Policy and a Patch Management Procedure.
- Configuration evidence-screenshots or exported settings that demonstrate the technical configuration of devices and services. This covers firewall rule sets, router configurations, anti‑malware settings and user account permissions.
- Test and verification reports-results from vulnerability scans, port scans or penetration tests that prove the controls are effective. A simple Nessus or OpenVAS scan report for internet‑facing services is sufficient.
- Signed declaration-a statement signed by a senior manager confirming that the information supplied is accurate and that the organisation complies with the Cyber Essentials requirements.
How to gather each piece of evidence
Collecting the right files can feel like a chore, but a systematic approach keeps it quick.
1. Policies and procedures
Start with the documents you already have. Most small businesses maintain at least a basic Acceptable Use Policy and a Password Policy. If a formal Patch Management Procedure is missing, draft a one‑page outline that covers:
- How often you check for updates (e.g., Microsoft Patch Tuesday)
- Who is responsible for applying patches
- What testing you perform before rollout
Save each document as a PDF and name it clearly, for example Password_Policy.pdf. The assessor will open the file and look for the key clauses listed in the Cyber Essentials guidance.
2. Configuration screenshots
Log into each device that forms part of your perimeter and internal security. For a typical small office you will have a router, a firewall appliance or a cloud‑based gateway, and a Windows or Linux server.
- Firewall-capture the rule set that blocks inbound traffic except for the ports you need (usually 80, 443 and 22). Use the router’s web UI or
show runon a Cisco device and paste the output into a text file or screenshot. - Secure configuration-on Windows, run
gpresult /h gpresult.htmlto export the applied Group Policy settings. On Linux, runsudo lynis audit systemand capture the summary. - Anti‑malware-open the dashboard of your endpoint protection product (e.g., Windows Defender, ESET, Sophos) and take a screenshot that shows real‑time protection is enabled and the last definition update date.
Label each file with the device name and date, for example Router_Firewall_Rules_2024-09-15.png. The assessor checks the date to confirm the evidence is recent.
3. Test and verification reports
Run a basic external scan against any public IP addresses you own. Free tools such as Qualys FreeScan or Nessus Essentials will produce a PDF report. The report should include:
- Open ports and services detected
- Any high‑severity vulnerabilities
- Confirmation that no unnecessary services are exposed
If the scan shows a vulnerability, fix it first, then re‑run the scan and keep the clean report. The assessor expects to see a clear “no critical findings” result for the external test.
4. Signed declaration
The final piece is a one‑page statement signed by a director or senior manager. The wording is provided in the Cyber Essentials application portal; you simply need to add the name, title and signature. Print, sign and scan the page, or use a digital signature if your organisation accepts it.
Common pitfalls to avoid
Even with the right evidence, small mistakes can cause a rejection.
- Out‑of‑date screenshots-the assessor checks the date stamp. If a screenshot is older than three months, they will ask for a fresh one.
- Missing policy clauses-a Password Policy that does not mention minimum length or change frequency will be flagged. Use the Cyber Essentials guidance as a checklist.
- Unclear file names-generic names like
document1.pdfmake it hard for the assessor to locate the right evidence. Descriptive names save time. - Over‑loading the submission-only submit what is asked for. Extra logs or full system backups add noise and can delay the review.
Using Solvbeat to simplify the process
Solvbeat offers a free website scanner that checks many of the technical controls covered by Cyber Essentials. The scan highlights missing patches, insecure headers and open ports, giving you a clear starting point for your evidence collection. While Solvbeat is not an accredited certification body, the reports it generates align closely with the evidence the assessor expects.
Running the scan also produces a PDF summary you can attach to your application as supplementary proof of your current security posture. Pair that with the policy documents and screenshots you have prepared, and you will have a complete, tidy package ready for submission.
Ready to see what you need to fix before you start gathering evidence? Run a free scan →