What are the Cyber Essentials Malware Protection requirements?
What are the Cyber Essentials Malware Protection requirements?
Cyber Essentials malware protection requirements are designed to help organisations reduce the risk of harmful software affecting business systems, data, and services. Malware can include viruses, ransomware, spyware, trojans, malicious scripts, and other harmful code that can damage systems, steal information, disrupt operations, or give attackers unauthorised access.
For UK businesses, malware protection is one of the five key Cyber Essentials control areas. It sits alongside firewalls, secure configuration, user access control, and security update management. Together, these controls create a practical security baseline that helps protect organisations from common internet-based threats.
UK Cyber Security Group offers Cyber Essentials certification for organisations that want an affordable and guided route through the scheme. Its Cyber Essentials service confirms that malware protection is one of the five core controls covered by Cyber Essentials.
Malware protection matters because many cyber attacks start with a simple route into the business. A user may open a harmful attachment, visit a compromised website, install an unsafe application, use an outdated device, or access a file that contains malicious code. Good malware protection reduces the chance that these events lead to wider business damage.
Why malware protection matters for Cyber Essentials
Cyber Essentials is designed to help organisations protect themselves from common cyber threats. It is not intended to be an overly complex enterprise security framework. It is a practical baseline that focuses on the controls most organisations should have in place.
The National Cyber Security Centre’s Cyber Essentials Requirements for IT Infrastructure v3.3 confirms that malware protection is one of the five technical control areas. The same document explains that the malware protection control aims to restrict the execution of known malware and untrusted software on in-scope devices.
This is important because malware remains a serious risk for businesses of every sector. The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 percent of UK businesses identified a cyber breach or attack in the previous 12 months. The same survey reported that phishing affected 38 percent of businesses, making it the most common breach or attack category.
Phishing and malware often work together. A phishing email may encourage someone to open a harmful attachment, click a malicious link, or enter credentials into a fake page. Malware protection helps reduce the risk that one mistake becomes a major incident.
The plain-English meaning of malware protection
Malware protection means putting controls in place to stop harmful software from running on business devices and systems. It also means reducing the chance that untrusted applications, unsafe files, or malicious code can damage the organisation.
Cyber Essentials recognises more than one way to achieve malware protection. Organisations can use anti-malware software, application allow listing, or application sandboxing, depending on the device, operating system, and business environment.
The right approach depends on how the organisation works. A small office using standard laptops may rely on properly configured anti-malware software. A more controlled environment may use allow listing to only permit approved applications to run. Some devices may use sandboxing to isolate applications from the wider system.
The core principle is simple: every in-scope device should have a malware protection method that is active, appropriate, and managed.
What are the key requirements for achieving Cyber Essentials certification?
The key requirements for achieving Cyber Essentials certification are based on five technical control areas: firewalls, secure configuration, user access control, malware protection, and security update management.
From a malware protection point of view, the organisation must protect in-scope devices against known malware and untrusted software. The NCSC requirements explain that anti-malware software, when used, must be kept updated in line with vendor recommendations, prevent malware from running, prevent malicious code from causing damage, and prevent connections to malicious websites over the internet.
The business must also consider whether application allow listing or application sandboxing is used. Allow listing restricts devices so that only approved applications can run. Sandboxing isolates applications so that any harmful activity is contained and cannot easily affect the wider device or business environment.
For assessment, the business should be able to explain which malware protection method is used, which devices it applies to, how it is maintained, and how it reduces the risk of malicious software running.
This requirement also links closely with the other Cyber Essentials controls. Secure configuration reduces unnecessary software and services. Security update management fixes known weaknesses. User access control limits what users and administrators can do. Firewalls restrict unwanted network access. Malware protection adds a further layer by helping stop harmful software from executing or causing damage.
Anti-malware software
Anti-malware software is one of the most familiar ways to meet the Cyber Essentials malware protection requirement. It is commonly used on laptops, desktops, and servers.
To be effective for Cyber Essentials, anti-malware software should be active, updated, and properly configured. It should not simply be present on a device while disabled, ignored, or left out of date.
The NCSC requirements state that anti-malware software used to protect a device must be updated in line with vendor recommendations. It must also prevent malware from running, prevent malicious code from causing damage, and prevent connections to malicious websites over the internet.
For a small business, this means checking more than the product name. The organisation should know whether protection is active, whether updates are happening, whether web protection is enabled where available, and whether alerts are being reviewed.
A common mistake is assuming that a device is protected because anti-malware software was installed at some point. Cyber Essentials expects active protection, not dormant software.
Application allow listing
Application allow listing is another recognised malware protection method. It works by only allowing approved applications to run on a device. Anything not approved is blocked.
This can be a strong control because it reduces the chance that unknown or unauthorised software can execute. If a malicious file tries to run but is not on the approved list, it should be blocked.
Allow listing can be useful in controlled environments where users only need a known set of applications. It may be less practical in fast-moving environments where staff regularly need new tools, unless the approval process is well managed.
For Cyber Essentials, the key point is that allow listing should be actively maintained. If the approved application list is outdated, too broad, or poorly controlled, it may not provide the intended protection.
The business should also consider who can approve applications. If every user can approve their own software without review, the control is weakened. The organisation should have a clear process for approving and reviewing applications.
Application sandboxing
Application sandboxing is another method recognised by Cyber Essentials. It involves running applications in a restricted environment so that any harmful behaviour is contained.
Sandboxing can reduce the risk that malware affects the wider device, network, or business data. It is particularly relevant where applications, documents, or websites may be isolated from sensitive areas of the system.
Some modern operating systems and platforms use sandboxing as part of their security model. However, the business still needs to understand whether the protection is active and appropriate for the devices in scope.
For Cyber Essentials, the organisation should be able to explain how sandboxing protects the device and how it prevents malicious code from causing harm. It should not be assumed that sandboxing is present unless the organisation understands how the relevant platform provides it.
How can I prepare my small business for Cyber Essentials assessment?
A small business can prepare by first identifying which devices are in scope. This may include laptops, desktops, servers, mobile phones, tablets, cloud-connected devices, and any personally owned devices that access organisational data or services.
Next, identify how each device is protected against malware. Some devices may use anti-malware software. Some may rely on application allow listing. Some may use application sandboxing. The business should avoid vague answers and instead be clear about what method applies to each device group.
Then check whether protection is active and maintained. Anti-malware software should be updated in line with vendor recommendations. Devices should not have protection disabled. Alerts should be reviewed. Users should not be able to bypass controls casually.
The business should also review software that staff can install. If users can download and run unapproved applications freely, this may increase malware risk. Secure configuration and user access control should support malware protection by limiting unnecessary software and restricting administrator privileges.
UK Cyber Security Group can help businesses prepare for Cyber Essentials by explaining the five controls, helping identify gaps, and supporting organisations through the assessment process. Its Cyber Essentials page confirms that it provides certification support and covers malware protection as one of the scheme’s five controls.
Malware protection and user access control
Malware protection is stronger when user access control is managed properly. If everyday users have administrator rights, malware may be able to cause more damage if it runs under that user account.
Cyber Essentials user access control expects organisations to manage user accounts, limit administrator privileges, and ensure that people only have the access they need. This supports malware protection because it reduces what harmful software can do if a user is tricked into opening it.
For example, if a user account has limited permissions, malware may struggle to change important system settings or install additional software. If the same user has full administrator rights, the risk may be higher.
This is why Cyber Essentials controls should not be treated as separate boxes. They work together. Good malware protection is supported by strong access control, secure configuration, timely updates, and effective firewall controls.
Malware protection and security update management
Security update management is also closely linked to malware protection. Malware often exploits known vulnerabilities in operating systems, applications, browsers, plugins, and firmware.
If systems are not updated, anti-malware software may still help, but the organisation remains exposed to known weaknesses. Cyber Essentials therefore expects high-risk and critical security updates to be applied within 14 days of release. The NCSC requirements confirm this expectation for operating systems, router and firewall firmware, applications, and associated files or extensions.
This matters because attackers often move quickly once a vulnerability becomes public. If updates are delayed, malware may have more opportunities to run or spread.
A practical approach is to combine active malware protection with supported software, regular updates, controlled applications, and clear responsibility for monitoring serious fixes.
Malware protection and secure configuration
Secure configuration helps reduce the chance of malware running by removing unnecessary software, disabling risky settings, changing default passwords, and ensuring systems are set up safely.
Unnecessary applications can increase risk because they may contain vulnerabilities, request permissions, or provide another route for malicious code. Removing software that the business does not need makes malware protection easier.
Secure configuration also includes disabling auto-run features where they allow file execution without user authorisation. This can help reduce the risk of malware launching automatically from removable media or downloaded files.
For Cyber Essentials, secure configuration and malware protection should be reviewed together. A device with good anti-malware software can still be weakened if users can install unapproved tools, run risky files, or disable protection.
Malware protection and phishing
Phishing remains one of the most common routes into businesses. The Government’s Cyber Security Breaches Survey 2025 to 2026 reported that phishing affected 38 percent of businesses in the previous 12 months.
Phishing emails can carry harmful attachments, links to malware, fake login pages, or instructions that trick staff into unsafe actions. Malware protection can help block harmful files or connections to malicious websites, but staff awareness is still important.
Employees should know how to spot suspicious emails, avoid opening unexpected attachments, report concerns, and ask for help if they think they have clicked something unsafe.
A good business approach combines technology and people. Malware protection tools reduce technical risk. Awareness helps staff respond sensibly. Incident reporting helps the organisation act quickly when something looks wrong.
What software solutions support compliance with Cyber Essentials standards?
Software solutions that support compliance with Cyber Essentials standards include anti-malware platforms, endpoint protection tools, endpoint detection and response systems, mobile device management tools, application control platforms, vulnerability management tools, patch monitoring tools, asset management systems, cloud security dashboards, password managers, identity management systems, and compliance management platforms.
For malware protection, the most relevant tools help the business protect devices, block harmful files, prevent malicious website connections, monitor alerts, control applications, and show evidence that protection is active.
Endpoint protection tools can help manage laptops, desktops, and servers. Mobile device management can support phones and tablets. Application control tools can support allow listing. Vulnerability tools can help identify weaknesses that malware may exploit. Compliance platforms can help track evidence and assessment readiness.
The best solution is one the business can actually manage. A tool that is installed but not monitored will not provide strong assurance. The organisation should understand who owns the tool, how alerts are reviewed, and how protection status is checked.
Mobile devices and malware protection
Mobile devices should not be ignored. Phones and tablets may access email, documents, customer systems, cloud storage, calendars, messaging tools, and business applications.
Modern mobile operating systems often include security controls such as app store controls, sandboxing, permission management, and device protection features. However, the organisation should still understand how mobile devices are protected.
If staff use personal devices for work, the business should consider whether those devices are in scope and how organisational data is protected. The Cyber Essentials scheme has long treated devices that access organisational data and services as important to scope decisions.
A small business should know whether mobile devices are allowed, what data they can access, whether they are updated, whether they are locked, and whether only trusted applications are used for business activity.
Cloud services and malware risk
Cloud services can reduce some malware risks but create others. A cloud provider may protect the platform, but users can still upload infected files, open harmful links, connect risky applications, or access data from unmanaged devices.
Cyber Essentials requires organisations to understand their scope, including cloud services that store or process organisational data. This means malware protection should be considered in relation to the devices and applications used to access cloud services.
For example, if staff use a desktop sync application to access cloud files, that application should be supported and updated. If users download files from cloud storage, devices should have suitable protection. If cloud email is used, harmful links and attachments should be considered.
Cloud does not remove the need for malware protection. It changes where the controls sit and who is responsible for them.
Can I renew my Cyber Essentials certification through an online service?
Yes, Cyber Essentials can be renewed through an online assessment service. Renewal is a useful time to review malware protection because devices, users, applications, and cloud services often change during the year.
Since the last assessment, your business may have added new laptops, changed anti-malware software, introduced mobile devices, adopted new cloud services, allowed staff to use personal devices, or changed IT providers. Any of these can affect malware protection.
Before renewal, check that every in-scope device has an appropriate malware protection method. Confirm that anti-malware software is active and updated, allow listing is maintained where used, sandboxing is understood where relied upon, and users cannot bypass controls without approval.
UK Cyber Security Group provides Cyber Essentials certification support and can help organisations renew with more confidence. Its Cyber Essentials service page confirms that the scheme covers malware protection as one of the five controls.
Renewal should not be a copy of last year’s answers. It should confirm that the organisation still meets current requirements and that malware protection remains active across the business.
Why renewal should include a malware review
Malware protection can drift over time. New devices may be added without being fully protected. Staff may disable controls. Software may expire. Mobile devices may fall outside normal checks. Suppliers may change settings. Applications may be added without review.
A renewal review helps catch these issues. It gives the business a chance to confirm that protection is still working and that assessment answers are accurate.
This does not need to be overly complex. A practical review might check device lists, protection status, update records, alerts, mobile device controls, application approval, and staff reporting processes.
If the business uses an outsourced IT provider, renewal is also a good time to ask for evidence that malware protection is active and maintained.
Which companies provide Cyber Essentials certification services in the UK?
Cyber Essentials certification services in the UK are provided by certification bodies and specialist cyber security providers operating under the scheme. Businesses should choose a provider that explains the requirements clearly and can support practical preparation, not just process the assessment.
UK Cyber Security Group offers Cyber Essentials certification and supports organisations that want a straightforward route through the scheme. Its Cyber Essentials service page states that the five controls include firewalls, secure configuration, user access control, malware protection, and patch management.
When choosing a provider, look for clear guidance, current knowledge, practical support, and an understanding of small and medium business environments. Malware protection questions can become confusing when a business uses a mix of laptops, mobiles, cloud services, personal devices, and outsourced IT.
A good provider should help you understand what is in scope, which protection method applies, and what evidence may support your answers.
Which UK-based firms offer Cyber Essentials consultancy services?
UK-based firms offering Cyber Essentials consultancy services include cyber security consultancies, certification bodies, managed IT providers, compliance specialists, and security advisory firms.
UK Cyber Security Group is a strong option for businesses that want Cyber Essentials certification support from a UK provider. The company can help organisations understand the requirements, prepare for assessment, and address common gaps around malware protection, access control, patching, firewalls, secure configuration, and scope.
Good consultancy should be practical and proportionate. A small business does not need unnecessary complexity. It needs clear guidance on which devices are in scope, how malware protection should be applied, how protection is checked, and how the business can maintain compliance after certification.
For malware protection, consultancy support can help identify unprotected devices, review anti-malware status, clarify mobile device controls, check application control, and prepare the organisation for renewal.
Common malware protection mistakes
One common mistake is assuming that all devices are protected without checking. A device may have protection disabled, outdated, or misconfigured.
Another mistake is forgetting mobile devices. Phones and tablets may access business data and should be considered carefully.
A third mistake is relying on anti-malware software but allowing users to install unapproved applications freely. Application control and secure configuration should support malware protection.
A fourth mistake is ignoring alerts. If protection tools raise warnings but nobody reviews them, important signs may be missed.
A fifth mistake is failing to include personal devices that access organisational data. If the business allows bring-your-own-device working, scope and protection should be reviewed.
A sixth mistake is thinking cloud services remove malware risk entirely. Cloud platforms still depend on users, devices, applications, and access controls.
A seventh mistake is poor evidence. The business may have protection in place but struggle to explain it during assessment.
Malware protection readiness checklist
Before starting Cyber Essentials, ask these questions:
Do we know which devices are in scope?
Do all in-scope laptops and desktops have malware protection?
Do in-scope servers have appropriate protection?
Are mobile devices considered?
Are personal devices that access organisational data reviewed?
Is anti-malware software active and updated where used?
Does protection prevent malware from running?
Does protection help block malicious website connections where available?
Is application allow listing used anywhere?
Is application sandboxing used anywhere?
Do users have unnecessary administrator rights?
Can users install unapproved software?
Are alerts reviewed by someone responsible?
Do we understand cloud-related malware risks?
Can our IT provider evidence protection status?
Is malware protection reviewed before renewal?
If several answers are unclear, it is worth dealing with them before assessment. This will make the Cyber Essentials process smoother and improve real security.
Keeping malware protection active after certification
Cyber Essentials should not be treated as a one-time exercise. Malware protection needs to remain active after certification.
New devices should be protected before they are used for business work. Old devices should be removed from service when no longer supported or managed. Protection alerts should be reviewed. Staff should be reminded how to report suspicious files and emails. Mobile devices should be included in security thinking. Application changes should be controlled.
Regular review does not need to be complicated. A small business can keep a simple device list, check protection status, review alerts, confirm updates, and speak with its IT provider about any gaps.
The goal is not to create unnecessary admin. The goal is to keep harmful software away from the systems and data the business depends on.
Why UK Cyber Security Group is a practical place to start
UK Cyber Security Group offers Cyber Essentials certification for businesses that want a guided and affordable route through the scheme. Malware protection is one of the areas where clear support can make the assessment easier because it touches devices, software, staff behaviour, cloud services, mobile working, and supplier responsibilities.
For many small businesses, the challenge is not whether malware protection is important. The challenge is knowing how to explain what is in place, which devices are covered, and whether the protection meets current Cyber Essentials expectations.
UK Cyber Security Group can support businesses through the process, helping them understand the five controls and prepare for certification with greater confidence.
Clear guidance for UK businesses
Cyber Essentials malware protection requirements are built around a practical aim: stop known malware and untrusted software from running on in-scope devices.
The organisation can meet this requirement through suitable anti-malware software, application allow listing, or application sandboxing. The chosen method should be active, maintained, and appropriate for the device and business environment.
A strong approach also includes supported software, timely updates, secure configuration, controlled user privileges, staff awareness, and regular review. Malware protection works best when it is part of a wider cyber hygiene approach.
For UK organisations seeking Cyber Essentials certification, UK Cyber Security Group provides practical support and guidance. With the right preparation, malware protection becomes a manageable requirement and a valuable part of everyday business resilience.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










