Guide

Cyber Essentials for schools: what you actually need

A plain-English guide for school IT staff and business managers. Last checked against the NCSC's guidance on 4 October 2026 (requirements version 3.3).

Cyber Essentials is the UK government's basic cyber security certificate. For schools it comes up in a few places: the DfE's cyber security standards for schools point to it, insurers and trusts increasingly ask about it, and it is a sensible baseline whether or not anyone asks. It is deliberately basic — five technical controls that stop most common attacks — but “basic” across every device in a school is a lot of devices.

Cyber Essentials or Cyber Essentials Plus?

Both cover the same five controls. Cyber Essentials is a self-assessment questionnaire, checked by a certification body. Cyber Essentials Plus adds an independent technical test: an assessor checks a sample of your devices to see that the controls really work. Most schools start with the first; Plus is the stronger evidence. Either way the certificate lasts a year, so the work is ongoing rather than a one-off.

The five controls, in school terms

1. Firewalls

What it asks. A firewall between your network and the internet, set up properly (default admin passwords changed, no unnecessary open ports), and the firewall switched on on every device that leaves the building — staff laptops especially.

Where schools trip up. Laptops taken home with the Windows firewall turned off “temporarily” years ago; a firewall admin page reachable from the internet.

2. Secure configuration

What it asks. Devices set up securely rather than left as they came: default passwords changed, software and accounts that are not needed removed or disabled, auto-run switched off, and a screen lock or sign-in on every device.

Where schools trip up. Old local accounts left on imaging, shared generic logins, kiosk and display machines nobody looks at.

3. Security update management

What it asks. Operating systems, firmware and applications kept supported and updated: high-risk and critical updates installed within 14 days of release, and nothing in use that no longer gets updates.

Where schools trip up. Machines that download updates but never restart; the one classroom PC still on an unsupported version of Windows; network devices (switches, firewalls) that never get firmware updates.

4. User access control

What it asks. Accounts only for people who need them, removed when people leave; admin rights only for the people and tasks that need them, used through separate admin accounts; strong passwords; and multi-factor authentication on cloud services wherever it is available — Microsoft 365 and Google Workspace included.

Where schools trip up. Leavers' accounts still active; everyone in IT signing in as an admin all day; MFA on staff but not on the admin accounts that matter most.

5. Malware protection

What it asks. Anti-malware switched on and kept up to date on every device that can run it (Microsoft Defender counts), or apps limited to an approved list.

Where schools trip up. Defender quietly disabled by an old product's installer; signatures out of date on machines that are rarely switched on.

What “in scope” means

Every device that can reach the internet and handles school data is in scope: staff and pupil computers, laptops and tablets, servers, the network equipment, and the cloud services you use. A pupil's own phone on a guest network usually is not; a staff phone that gets school email usually is. Your certification body can help you draw the line — write down where you drew it.

Getting started

  1. Read the official requirements (linked below) and list your devices, accounts and cloud services.
  2. Go through the five controls and note what is not yet true — the gaps are usually a handful of machines.
  3. Fix those, keep a dated note of what you checked, and book the assessment with a certification body.
  4. Put next year's renewal date in the calendar now.

Where Groundskeeper helps — and where it does not

Groundskeeper is IT monitoring for schools, not a certification body: it cannot certify you, and passing its checks does not mean you will pass. What it does do is show, every day, the parts of Cyber Essentials it can measure on your Windows machines (those running its agent), so the gaps are visible before the assessor finds them:

It does not check your router or firewall's own settings, multi-factor authentication on cloud services, admin accounts and leavers, or devices without its agent — those you still check yourself. Its Cyber Essentials page gives each control a red, amber or green status and exports a PDF you can keep as part of your evidence.

Groundskeeper is free for schools to use.

Find out more about Groundskeeper

More guides: The DfE filtering and monitoring standards, explained · The RPA cyber cover conditions, checked.

The official guidance: Cyber Essentials overview (NCSC) and the requirements documents (NCSC). This guide is a summary to help you find your way around them; where they differ, the official requirements are what count.