Templates/Cyber Essentials Policies
Cyber Essentials · Free template

Cyber Essentials policy templates

Free, editable starting-point policies for all five Cyber Essentials control areas — firewalls, secure configuration, patch management, user access control, and malware protection.

This is a generic starting point, not certification advice. Cyber Essentials Plus verifies these controls against your actual systems — the policy only helps if what it describes is genuinely how your devices and accounts are configured.

The five Cyber Essentials control areas

Cyber Essentials is built around five technical control areas, and a written policy for each makes it far easier to answer the certification questionnaire consistently — and to prove during a CE+ technical audit that what you do matches what you say.

The template below covers all five in one document you can split apart if you prefer separate policies.

The template

Cyber Essentials Policies — [Company Name]

1. Firewalls & internet gateways

Purpose: to control network traffic in and out of [Company Name]'s systems and prevent unauthorised access.

All internet-facing devices are protected by a correctly configured firewall. Default administrative passwords on firewall devices are changed before use. Unnecessary services and open ports are disabled. Firewall rules are reviewed at least [every 6 months] and any rule no longer needed is removed.

Home working: staff working remotely use [the corporate VPN / a software firewall enabled on every device] rather than relying solely on their home router.

2. Secure configuration

Purpose: to ensure devices and software are configured to reduce vulnerabilities, not left on insecure defaults.

Unnecessary user accounts are removed or disabled. Default or guessable passwords are changed before a device is used. Auto-run features that launch software without user confirmation are disabled. Personal firewalls are enabled on all devices. Only necessary software and services are installed on each device.

[List your device build/configuration standard here, or reference where it's documented — e.g. an MDM baseline.]

3. Security update (patch) management

Purpose: to fix known vulnerabilities before they can be exploited.

All operating systems and applications are kept licensed and supported. Updates classified by the vendor as critical or high-risk are applied within [14 days] of release; other updates within [30 days]. Software that is no longer supported by its vendor is removed from all devices or replaced.

[Name who is responsible for tracking and applying updates, and how — e.g. automatic updates enabled, or a managed patching tool/schedule.]

4. User access control

Purpose: to ensure only authorised people have access to the accounts and data they need to do their job, and no more.

Access to accounts and systems is granted only after approval, based on what the role actually requires (least privilege). Administrator-level accounts are used only for administrative tasks, never for everyday work like email or browsing. Multi-factor authentication is required for all cloud services, and for all administrator accounts without exception. Access is removed promptly when someone leaves or changes role, and reviewed at least [every 6 months].

[List your approval process for granting access, and who owns removing it when someone leaves.]

5. Malware protection

Purpose: to protect devices from malicious software.

All devices run up-to-date anti-malware software [or an application allow-listing approach], configured to update automatically and scan files on access. Software can only be installed from an approved list, or by prior approval. Staff are told not to download or run software from untrusted sources.

[Name your endpoint protection product here, e.g. Microsoft Defender for Endpoint — this becomes the evidence assessors will ask about directly.]

6. Ownership and review

These five policies are owned by [Name/role] and reviewed at least [annually] or whenever a significant change is made to our IT environment. Last reviewed: [Date]. Next review due: [Date].

Common questions

Is there one single "Cyber Essentials policy" document?

No — Cyber Essentials assesses five separate control areas (firewalls, secure configuration, patch management, user access control, and malware protection), and most organisations document each as its own policy or as sections of one combined document, as here. There's no single required format — what matters is that each control area is genuinely covered and genuinely followed.

Do these policies get submitted as part of certification?

Cyber Essentials (self-assessed) is answered through IASME's online questionnaire, not by submitting documents — but having written policies makes it far easier to answer accurately and consistently. Cyber Essentials Plus adds a technical audit, where an assessor checks your actual systems against what you've stated, so the policy needs to reflect real practice, not aspiration.

Is this template enough for Cyber Essentials Plus?

It's a genuine starting point, but CE+ specifically tests whether these controls are actually implemented on real devices — an assessor will check patch levels, MFA enforcement, and malware protection directly. The gap between a written policy and verified practice is exactly what CE+ is designed to catch.

How often does Cyber Essentials need to be renewed?

Certification is valid for 12 months, and most organisations re-assess annually. Because the questionnaire asks about your current state, these policies (and, more importantly, the practices behind them) need to still be accurate at renewal time, not just when first written.

Want these tailored — and kept audit-ready?

Fortify's Policy Engine generates each of these policies tailored to your actual systems and scope, and our free readiness check shows exactly where your current setup would pass or fail a CE+ technical audit before you book one.