Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly check whether your business meets Cyber Essentials requirements.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
2 hoursto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsNo price for a Cyber Essentials assessment is provided in the available tool data.
If this goes wrong: you mark a control as met because the written policy looks right while the live system is not configured that way.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 2 hours until you can act on the result.
How to actually do it
- Open the current Cyber Essentials requirements from the official certification source and save the exact version and scope that applies to your business.
- Gather your asset inventory, user and administrator lists, network diagram, cloud service list, security policies, patch records, malware protection settings, firewall settings, access control records and device configuration evidence.
- Remove passwords, private keys, personal data and unnecessary customer information, then paste the requirements and evidence into a chatbot using the prompt.
- Ask the chatbot to keep unknown items separate from items marked partly met, and to quote the evidence supporting every status.
- Compare every claim marked met with the corresponding live setting, device record or supplier evidence, asking your IT administrator or managed service provider to confirm anything you cannot inspect.
- Create a remediation list from the unknown and not met items, assign an owner and due date, then update the evidence after each change.
- Send the completed evidence pack and unresolved questions to an independent Cyber Essentials assessor before submitting any certification answers.
Prompt
Act as a Cyber Essentials readiness assessor, not a certifying body. Use only the current Cyber Essentials requirements and evidence I provide. Do not assume that a policy exists in practice, that a setting is enabled, or that an answer is compliant when the evidence is incomplete. For each requirement, create a table with: requirement, evidence supplied, status of met, partly met, not met or unknown, exact reason, missing evidence, a practical remediation action, and who should verify it. Separate written policy evidence from technical evidence. Flag anything that needs a live configuration check, vulnerability check, privileged access review, device inventory check or specialist judgement. Quote or reference the supplied requirement text so I can trace each conclusion. Do not invent system details, dates, products, versions or compliance claims. End with a list of unanswered questions and a short handover checklist for an independent Cyber Essentials assessor. Business context: [business type and size]. Scope: [devices, users, cloud services and networks in scope]. Current requirements: [paste the current official Cyber Essentials requirements]. Evidence: [paste policies, asset inventory, configuration exports, supplier statements and answers].
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot see unmanaged devices, forgotten accounts or settings that differ from the documents you upload.
- AI cannot prove that a supplier statement is current or that a cloud service is configured as described.
- AI cannot replace the live technical checks and judgement involved in deciding whether your evidence is sufficient.
- AI can turn an ambiguous answer into a confident-looking compliance status unless you require an unknown result.
- Your business remains accountable for inaccurate answers and for security incidents caused by gaps the assessment missed.
What caps this at PARTLY: verification cost, context depth and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT check if my business is Cyber Essentials compliant?
- Partly. It can map the current requirements against your policies and technical evidence, identify gaps and draft questions, but it cannot independently confirm that your live systems match the evidence.
- Can AI get me Cyber Essentials certified?
- No. AI can help you prepare, but it cannot take responsibility for your answers or replace the certification process. Use an independent Cyber Essentials assessor to check the final evidence and submission.
- What should I give AI to check Cyber Essentials?
- Give it the current requirements, your defined scope, asset inventory, user and administrator list, network and cloud service details, relevant policies and configuration evidence. Do not paste passwords, private keys or unnecessary personal data.
- Is an AI Cyber Essentials check safe?
- It is safe for organising redacted evidence and finding unanswered questions, provided you do not disclose secrets or treat the output as certification. Not professional advice: a serious compliance or security decision needs a qualified Cyber Essentials assessor or cybersecurity professional.
Nearby answers
- Can AI choose cybersecurity software for my business?PARTLY
- Can AI detect phishing emails for my business?PARTLY
- Can AI help me report a data breach to the ICO?PARTLY
- Can AI help me choose and secure a VPN for my business?PARTLY
- Can AI help me set up multi-factor authentication for my business?PARTLY
- Can AI check my business firewall rules?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.