Readiness checklist
Danzell auto-fail checklist
Five high-impact checks to complete before starting a Cyber Essentials v3.3 assessment.
4 min read
Why automatic failures deserve attention first
A strong score elsewhere cannot cancel an automatic failure. That makes these checks the sensible starting point for any readiness exercise: resolve them before spending time polishing lower-priority answers.
1. Confirm every operating system is supported
Review desktops, laptops, servers, phones, tablets, thin clients, routers and firewalls. Record the exact version and its vendor support status. If extended support is required, confirm that the subscription is active for every affected device.
2. Prove operating systems and firmware are patched promptly
Document how high-risk updates are detected, deployed and verified within the required period. Firmware is easy to overlook, so give routers and firewalls an explicit owner and review cadence.
3. Prove applications are patched promptly
Include browsers, office software, extensions and specialist applications. Automatic updates help, but you still need a process for products that require manual intervention.
4–5. Enforce MFA for cloud administrators and users
Check every cloud service, not only Microsoft 365. MFA being available or encouraged is not the same as it being enforced. Test both administrator accounts and ordinary user accounts, and record any service that genuinely provides no MFA path.
For Microsoft estates, review Conditional Access or Security Defaults, legacy authentication and emergency access arrangements. For other services, check native MFA or a federated sign-in route.
Keep the evidence together
A short register showing the system, owner, control and last verification date is more useful than scattered screenshots. Kelvane Comply will help organise these checks and surface the highest-priority action first.