CyFun Assessment Requirements Guide for UK Firms

CyFun Assessment Requirements Guide for UK Firms

A CyFun assessment should not begin with a scramble for policies the week before submission. The most reliable route is to understand what is in scope, compare current practice with the required outcomes, assign clear owners and collect evidence as work is completed. This CyFun assessment requirements guide sets out how to do that in a way that improves security as well as supporting certification.

Start with the assessment scope

Assessment requirements only make sense when the boundaries are clear. Before answering any questions, define the organisation, people, devices, cloud services, networks and third parties covered by the assessment. A small business may have a straightforward boundary. A business with remote staff, multiple offices, subsidiaries or a managed IT provider may need a more deliberate decision.

This is where many otherwise capable organisations lose time. They assess the office network but overlook home-working devices, Microsoft 365 accounts, cloud storage, mobile phones or an externally managed firewall. If a system handles business information or provides access to it, it is likely to matter.

Document exclusions too. An exclusion should be specific, justified and understood by the people responsible for the assessment. It should not be used to avoid a difficult gap. If a service sits outside the agreed boundary but can still affect the security of the systems inside it, explain the relationship and the controls around it.

CyFun requirements can vary according to the assessment level and the current scheme documentation. Use the official assessment questions and guidance as the source of truth, rather than relying on an old spreadsheet or a previous year’s answers. Certification requirements evolve, and a control that was adequate previously may need fresher evidence or a clearer explanation this time.

CyFun assessment requirements in practical terms

The assessment is not simply asking whether a policy exists. It is looking for whether sensible cyber security measures are operating, whether people know their responsibilities and whether the organisation can substantiate its answers.

In practice, the requirements tend to connect governance with day-to-day technical control. Leadership needs visibility of cyber risk and agreed responsibilities. Staff need appropriate awareness and access. Devices, applications, identities, networks and data need to be managed with security in mind. Incidents, backups and recovery arrangements also need to be more than assumptions.

For each question, work through three tests:

  1. Understand what the question is seeking to reduce. For example, a question about privileged access is concerned with preventing unauthorised changes and limiting the impact of a compromised account.
  2. Improve the control where the answer is incomplete, inconsistent or unsupported. The best next action may be a configuration change, an approval process, staff guidance or a formal review.
  3. Prove the answer with current, relevant evidence. A statement that a control is in place is weaker than a record showing it is configured, reviewed and owned.

This approach keeps the assessment tied to risk reduction. It also prevents a common mistake: producing extensive documentation that does not reflect how the business actually operates.

Evidence should reflect reality

Good evidence is clear enough for someone independent to understand what is in place without guessing. It should be current, attributable and relevant to the scope. A policy dated three years ago, with no review record or operational evidence, rarely gives the confidence that an assessment needs.

Useful evidence will differ between organisations, but commonly includes:

  • approved policies, procedures and review records;
  • asset and software inventories, including ownership and support status;
  • configuration records or screenshots for identity, endpoint, network and cloud controls;
  • reports showing patching, backups, security monitoring or vulnerability management activity; and
  • training records, access reviews, incident exercises and supplier assurance information.

Do not collect evidence for its own sake. A screenshot may show that multi-factor authentication is enabled, but it may not show whether all relevant users are covered, whether exclusions are controlled or who reviews the setting. Pair technical evidence with a short explanation where context matters.

Evidence also needs care. Redact credentials, personal data and sensitive customer information before sharing material. The goal is to demonstrate control, not create a new exposure through the assessment process.

Turn requirements into owned actions

A CyFun assessment often exposes a less technical problem than expected: nobody owns the action. IT may manage the technology, HR may own induction and leaver processes, finance may handle supplier contracts, and senior leaders may accept risk. When responsibilities are unclear, remediation remains on a list without moving forward.

Give every identified gap a named owner, a realistic target date and a definition of done. “Improve patching” is not an actionable task. “Enable automatic security updates on supported laptops, investigate exceptions weekly and retain the monthly compliance report” is much clearer.

Prioritisation matters. Address weaknesses that create the greatest practical exposure first, particularly unsupported software, weak identity controls, unprotected administrator accounts, unreliable backups and internet-facing systems with uncertain configuration. Some improvements will require budget or supplier involvement, while others can be completed quickly. Both should be visible to management.

Avoid treating a compensating measure as a permanent substitute for a missing control without recording the decision. There are legitimate cases where a standard control cannot be applied, perhaps because of an operational system or contractual constraint. In that case, document the risk, the alternative safeguards, the accountable decision-maker and the review date.

Involve suppliers without handing over accountability

Managed service providers and software suppliers often hold essential evidence. They may administer backups, endpoint protection, Microsoft 365, Entra ID, firewall rules or vulnerability remediation. Their input can make assessment preparation faster, but the organisation seeking assessment remains responsible for understanding and standing behind its answers.

Set expectations early. Ask suppliers what services they manage, which controls they operate, what reporting they can provide and how incidents are escalated. Check that their evidence relates to your environment rather than being a generic service description.

For MSPs supporting several customers, a repeatable assessment process is particularly valuable. Use consistent scoping questions, evidence requests, gap categories and reporting, but do not assume one customer’s configuration or risk appetite applies to another. Standardisation should reduce administration, not remove judgement.

Prepare for review, not just submission

Before submission, ask someone who did not write the responses to review them. They should be able to follow the logic from requirement to implementation to evidence. Look for contradictions between policies and technical settings, unsupported claims, expired reports and ambiguous ownership.

Pay particular attention to answers based on “usually”, “where possible” or “the provider handles that”. These phrases may be true, but they need a defined process behind them. Who checks? How often? What happens when the expected control fails? What record is retained?

A short internal readiness review can also reveal changes since evidence was gathered. New starters, replacement devices, a migration to a cloud platform or a change of supplier can alter the assessment position quickly. Treat evidence as a live record of your cyber posture, not a one-off attachment set.

Keep improving after the assessment

Certification or a completed assessment is a useful milestone, but it is not proof that risk has stopped changing. New vulnerabilities, staff changes, supplier changes and technology decisions can weaken controls between assessment cycles.

Create a regular rhythm for reviewing evidence, outstanding actions and key technical measures. The right frequency depends on the size and complexity of the organisation. A smaller business may hold a focused monthly check and a quarterly leadership review. A larger or higher-risk organisation may need more frequent operational monitoring.

Cyber Fundamentals AI can help bring assessment responses, supporting evidence, remediation actions and ownership into one workspace, so progress remains visible after the formal assessment. Its value is not in replacing judgement. AI can help explain findings and suggest priorities; people still decide what is appropriate for their business.

The practical aim is simple: make each CyFun assessment easier because the work is already happening. When responsibilities are clear, evidence is current and improvement actions have owners, you are not merely preparing for a requirement. You are building a clearer, more defensible view of cyber resilience.

Help shape Cyber Fundamentals AI.

Join early access to use the platform first, work directly with our team, and help shape the roadmap around what SMEs actually need.

Assess. Evidence. Continuous improvement.

We use your details only to contact you about early access.

Cyber Fundamentals AI

© 2026 NexGen Cyber Ireland Ltd · 12 South Mall, Cork, T12 RD43 · Registration No. 745548 · VAT No. 4188566SH