Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly check whether your business meets Cyber Essentials requirements.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

2 hoursto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita professional

What the alternative costsNo price for a Cyber Essentials assessment is provided in the available tool data.

If this goes wrong: you mark a control as met because the written policy looks right while the live system is not configured that way.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 2 hours until you can act on the result.

    How to actually do it

    1. Open the current Cyber Essentials requirements from the official certification source and save the exact version and scope that applies to your business.
    2. Gather your asset inventory, user and administrator lists, network diagram, cloud service list, security policies, patch records, malware protection settings, firewall settings, access control records and device configuration evidence.
    3. Remove passwords, private keys, personal data and unnecessary customer information, then paste the requirements and evidence into a chatbot using the prompt.
    4. Ask the chatbot to keep unknown items separate from items marked partly met, and to quote the evidence supporting every status.
    5. Compare every claim marked met with the corresponding live setting, device record or supplier evidence, asking your IT administrator or managed service provider to confirm anything you cannot inspect.
    6. Create a remediation list from the unknown and not met items, assign an owner and due date, then update the evidence after each change.
    7. Send the completed evidence pack and unresolved questions to an independent Cyber Essentials assessor before submitting any certification answers.

    Prompt

    Act as a Cyber Essentials readiness assessor, not a certifying body. Use only the current Cyber Essentials requirements and evidence I provide. Do not assume that a policy exists in practice, that a setting is enabled, or that an answer is compliant when the evidence is incomplete. For each requirement, create a table with: requirement, evidence supplied, status of met, partly met, not met or unknown, exact reason, missing evidence, a practical remediation action, and who should verify it. Separate written policy evidence from technical evidence. Flag anything that needs a live configuration check, vulnerability check, privileged access review, device inventory check or specialist judgement. Quote or reference the supplied requirement text so I can trace each conclusion. Do not invent system details, dates, products, versions or compliance claims. End with a list of unanswered questions and a short handover checklist for an independent Cyber Essentials assessor. Business context: [business type and size]. Scope: [devices, users, cloud services and networks in scope]. Current requirements: [paste the current official Cyber Essentials requirements]. Evidence: [paste policies, asset inventory, configuration exports, supplier statements and answers].

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot see unmanaged devices, forgotten accounts or settings that differ from the documents you upload.
  • AI cannot prove that a supplier statement is current or that a cloud service is configured as described.
  • AI cannot replace the live technical checks and judgement involved in deciding whether your evidence is sufficient.
  • AI can turn an ambiguous answer into a confident-looking compliance status unless you require an unknown result.
  • Your business remains accountable for inaccurate answers and for security incidents caused by gaps the assessment missed.

What caps this at PARTLY: verification cost, context depth and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output1
Inputs1
Verification1
Liability1
Effort delta2
Total6 / 10

FAQ

Can ChatGPT check if my business is Cyber Essentials compliant?
Partly. It can map the current requirements against your policies and technical evidence, identify gaps and draft questions, but it cannot independently confirm that your live systems match the evidence.
Can AI get me Cyber Essentials certified?
No. AI can help you prepare, but it cannot take responsibility for your answers or replace the certification process. Use an independent Cyber Essentials assessor to check the final evidence and submission.
What should I give AI to check Cyber Essentials?
Give it the current requirements, your defined scope, asset inventory, user and administrator list, network and cloud service details, relevant policies and configuration evidence. Do not paste passwords, private keys or unnecessary personal data.
Is an AI Cyber Essentials check safe?
It is safe for organising redacted evidence and finding unanswered questions, provided you do not disclose secrets or treat the output as certification. Not professional advice: a serious compliance or security decision needs a qualified Cyber Essentials assessor or cybersecurity professional.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.