Cyber Essentials: A Prep Checklist for Broxburn SMEs

What the assessor actually checks — and the recurring items that trip up first-time applicants across Broxburn, Uphall and Livingston.

24 July 2026 8 min read Business IT Alex M.
Cyber Essentials: A Prep Checklist for Broxburn SMEs

More Broxburn businesses are being asked for Cyber Essentials than ever — usually by a public-sector client, a professional-services insurer, or an English customer whose procurement team ticks it as a supplier requirement. If you've just been told you need it and don't know where to start, this guide walks through what the scheme actually is, what the assessor looks at, and the recurring items we see fail on first attempt across Broxburn, Uphall and Livingston small businesses.

If your team is already stretched, we run pre-audits and remediation as part of our business IT support for SMEs across West Lothian, so you're not learning the scheme from scratch in the fortnight before your renewal.

What Cyber Essentials Actually Is

Cyber Essentials is a UK government-backed cybersecurity scheme run by the National Cyber Security Centre and administered by IASME. It is designed for small and medium organisations and focuses on five basic technical controls that, when set up properly, block the vast majority of routine internet attacks. It is not ISO 27001. It is not a long consultancy engagement. It is a targeted checklist you attest to, and — for the Plus variant — an external assessor verifies.

For most Broxburn SMEs it's asked for as evidence of "reasonable" cyber hygiene: enough to satisfy a public-sector procurement gate, a client's supplier questionnaire, or a cyber-insurance underwriter. A current certificate also entitles UK-based organisations under a certain turnover to the cyber liability insurance bundled with the scheme.

The Two Levels: Cyber Essentials vs Cyber Essentials Plus

The basic level is a self-assessment. You complete a set of questions covering the same five controls, an internal signatory attests to the answers, and an IASME-appointed assessor marks them. The certificate lasts 12 months. Most SMEs start here.

Cyber Essentials Plus is the same scope, but an external assessor independently verifies your answers — a technical audit involving a vulnerability scan of your internet-facing services and a sample of your end-user devices, plus a test of your email and web filtering against a set of simulated malware payloads. Plus is what a growing number of NHS Scotland, MOD-adjacent, and larger private-sector contracts insist on. If your Broxburn business bids for that work, do the basic level first, use the audit findings to fix everything, then upgrade to Plus at renewal.

The Five Technical Controls the Assessor Looks At

Every question on the self-assessment maps back to one of these five areas:

  • Firewalls. Every device that connects to the internet must be behind a correctly configured firewall — usually your business router at the office and Windows Defender Firewall on each machine. Default admin passwords on the router are an automatic fail.
  • Secure configuration. Devices and software must be set up to reduce their attack surface: default accounts renamed or disabled, unnecessary services turned off, auto-play disabled, and any pre-installed software that isn't used removed.
  • User access control. Every user has their own account, administrator rights are separated from day-to-day logins, and access is removed promptly when someone leaves. Multi-factor authentication is now mandatory on all cloud services — see our guide on rolling out two-factor login for a small business for the practical side.
  • Malware protection. Every in-scope device runs a supported anti-malware product with signatures under 24 hours old, or has application allow-listing configured. On Windows, Microsoft Defender with tamper protection on is accepted.
  • Security update management. Operating systems and applications must be receiving security updates from the vendor, and high-risk updates must be applied within 14 days of release. Anything out of vendor support is out of scope — and in-scope kit running it is a fail.

Where Broxburn SMEs Usually Fail on First Attempt

We ran a pre-audit earlier this year for a small chartered-surveyors firm on the Uphall side of Broxburn — eight staff, two directors, one office and a mix of laptops. On paper they thought they were fine. The self-assessment they'd started said "yes" to everything. On the walk-around we found the five items below, and they are the same five we find almost everywhere:

  • Default admin credentials still on the router or NAS. Nobody had ever logged into the office router's admin page. The NAS still had "admin / admin". Both are automatic fails and both took ten minutes to fix.
  • One PC still on Windows 10 post end-of-life. A back-office machine used for scanning had never been upgraded. Since October 2025 it has been out of vendor support, which fails the update-management control on its own. It went into the queue for a Windows 11 in-place upgrade after a compatibility check.
  • Personal phones on the business email without MDM. Three staff had the company Microsoft 365 mailbox on their own iPhone with no PIN policy or remote-wipe capability enrolled — those devices are in scope for Cyber Essentials and must meet the same access-control rules as the laptops.
  • Auto-updates disabled on line-of-business software. Sage and one browser plugin had been pinned to old versions to avoid a compatibility hiccup a year earlier. That's a straight update-management fail — either move to current versions or remove the software from the machine.
  • A shared "reception" login used by three people. Convenient, but user access control specifically requires one account per person. The remediation is three named accounts with the same permissions, not one shared password.

None of these are difficult. All five are quick to remediate. But they are the reason first-time applicants get a "further work required" response and lose a fortnight of momentum.

A Sensible Order to Fix Things Before You Apply

Work through it in the order the assessor thinks in, not the order the questionnaire is laid out:

  1. Draw an accurate scope. List every laptop, desktop, phone, tablet, server, and cloud service that touches company data. Anything out of scope needs a defensible boundary, not a hand-wave.
  2. Deal with anything unsupported. Retire it, upgrade it, or take it out of scope with a proper network boundary.
  3. Change every default password on network kit, and enable MFA on every cloud login that offers it — email, accounting, file storage, remote-access tools.
  4. Separate admin accounts from daily accounts on every Windows and macOS device, and make sure Defender or your chosen AV is on with tamper protection enabled.
  5. Only then start the self-assessment questionnaire. You will finish it in a fraction of the time and you will not be re-answering questions after fixes.

Our remote support team can run the pre-audit and most of the remediation without a site visit, which keeps the process quick and low-friction for a small West Lothian office.

How Long Certification Takes and How Long It Lasts

Once your environment is actually ready, the basic self-assessment is usually returned within a working day or two of submission. Cyber Essentials Plus adds an external audit, which for a typical Broxburn SME is a single day of assessor time plus a small remediation window if anything is flagged. Both certificates are valid for 12 months and both need re-doing annually — the questionnaire is refreshed each year, so you cannot just resubmit last year's answers.

If getting to that state has surfaced a lot of small problems, it's usually a sign the business has outgrown its informal IT arrangements — the same tipping point covered in when a small business outgrows DIY IT. Cyber Essentials tends to accelerate that conversation, not start it. A working backup plan for the same size of business is a natural next piece to put in place while you're already thinking about it. And on the phishing-and-scams side, our post on how to spot tech support scams is worth circulating to the whole team as part of a first Cyber Essentials rollout — user awareness sits outside the scheme but is what actually stops the incidents it's designed to prevent.

Getting Cyber Essentials Certified in Broxburn

If your Broxburn or West Lothian business has been asked for Cyber Essentials and you'd rather not learn the scheme by trial and error, we handle the whole thing — scoping, remediation, and the questionnaire itself. Book a callback via our booking page, or drop us a line through the contact page with a rough headcount and how many sites you operate, and we'll come back with a shortlist of the specific items to fix first. Business callouts to Broxburn, Uphall, Livingston and Bathgate are part of our regular route, and urgent same-day work is covered by our Broxburn malware and virus removal service if the audit turns up something already active.

Last updated: 24 July 2026

Frequently Asked Questions

Common questions Broxburn and West Lothian businesses ask us about Cyber Essentials.

For most Broxburn SMEs the basic self-assessment is enough — it satisfies the majority of supplier questionnaires and public-sector procurement gates. Plus is only mandatory for specific contracts, most commonly larger NHS Scotland tenders, MOD-adjacent work, and some central government frameworks. We usually recommend doing the basic level first, using the assessor feedback to tighten anything weak, and only upgrading to Plus at renewal if a real contract asks for it. Getting Plus without a business reason to hold it is expense for the sake of a badge.

Yes. Any device — personal or company — that accesses company data is in scope, and email counts. That means a personal iPhone with the office Outlook account on it needs a device PIN or biometric lock, an up-to-date operating system, and a way for the business to remove the mailbox if the phone is lost or the person leaves. Microsoft 365 Business Standard and above includes exactly the controls you need for this, which is why we usually enrol staff devices via Intune during the Cyber Essentials prep rather than fight the question later.

Every 12 months. The questionnaire is refreshed each year — you cannot just resubmit last year's answers and any change in scope needs to be reflected. In practice, most of the work in year two is much lighter than year one, because the underlying controls are already in place. The bit that surprises people is that the certificate lapses immediately on the anniversary; there is no grace period. If a contract requires you hold Cyber Essentials continuously, put a diary reminder eight weeks before the expiry date and start the renewal then.

Yes — we do this regularly. Some incumbent IT providers are excellent at day-to-day support but have never taken a client through certification, so we bolt on for the audit and remediation phase and hand back to them once the certificate is issued. Others prefer we take over the compliance piece permanently. Either arrangement is fine. What we do not do is a "tick the boxes" pass that ignores real issues — the whole point of Cyber Essentials is that the underlying controls actually work, so if we find something serious we will flag it whether it slows down the certification or not.

Need Cyber Essentials in Broxburn?

We handle the scoping, remediation and self-assessment for small businesses across Broxburn, Uphall, Livingston and West Lothian.