IT security audit checklist for UK SMEs

What to check, what evidence to gather, and what a reasonable standard looks like

IT security audit checklist for UK SMEs

Security audits tend to be failed on evidence rather than on controls. MFA enforcement, patch management and firewall configuration can all be working properly and still be impossible to demonstrate, because nobody captured the records at the time and the logs have since aged out of retention.

Closing that gap is usually cheaper and faster than improving the controls themselves, which is why it makes sense to do before a customer, insurer or auditor asks.

This checklist covers the areas a UK SME audit normally examines, with the evidence to check against each one and a realistic standard for a business of your size.

Audit readiness matters whether or not you want a certificate

Many SMEs will never pursue Cyber Essentials Plus or ISO 27001, and if no customer is asking for certification, that is a reasonable position to take.

The capability that is harder to do without is being able to substantiate your answers. The demand comes from outside more often than in, through client security questionnaires, insurance renewals that ask for proof of MFA enforcement rather than a declaration, and board-level questions about what the security budget achieved. All of these want evidence rather than assurance.

The purpose of an audit is to convert informal knowledge into records that are dated, specific and checkable by someone who was not involved in the original decision. That has value independently of certification.

Audit and governance are different things and often get confused. An audit describes a single point in time. Governance is the set of routines that keep that description accurate, including scheduled policy reviews, tested restores and access reviews triggered by role changes. Treating the audit as the start of a cycle rather than an isolated exercise makes each subsequent one shorter.

What a sensible scope covers

A useful review examines three layers together: the policies, the behaviour of the people subject to them, and the technical controls that enforce them. Reviews that have concentrated on the technical layer alone are easy for an assessor to identify, because the policy documentation underneath will not match current practice.

For most UK SMEs, the scope covers: identity and access, endpoints and patching, email and user behaviour, backups and incident response – with policies and supplier oversight underlying all of them. The findings that recur most frequently are access that was never revoked, backups that have never been restored, and policies that describe processes the business no longer uses.

Internal reviews and external assessments cover the same controls and differ in rigour. An external assessor has no reason to accept undocumented claims. Running an internal review first against the standard you expect to face externally is the most effective preparation available.

Scope the review to your actual risk profile. Work from the data you hold, the systems you depend on and the specific questions your customers are asking, rather than from a template built for a larger organisation.

Identity and access

Access control degrades as people join, change roles and leave without the corresponding account changes being completed.

What can you do about it?

Check MFA enforcement across all services rather than administrative accounts and email alone.

  • Establish whether the password policy is technically enforced or only documented.
  • Confirm that administrative rights are assigned to named individuals rather than shared accounts.
  • Review the leaver process in detail, specifically whether access removal happens on the leaving date or at some later point when IT has capacity.

The baseline has changed.

The NCSC published updates to the Cyber Essentials Requirements for IT Infrastructure in November 2025, and the resulting version 3.3 applies to assessment accounts created from the end of April 2026, assessed through the Danzell question set.

It introduces auto-fail conditions, which means a cloud service without MFA where MFA is available, or high-risk and critical updates applied later than fourteen days after release, will fail the assessment outright with no possibility of offsetting against other controls.

Cloud services can no longer be excluded from scope.

The scheme recognises FIDO2 authenticators and passkeys as MFA, and the NCSC accepts SMS while recommending stronger methods. Password length requirements depend on what else is in place, requiring eight characters alongside MFA, twelve without it, or eight combined with automatic blocking of common passwords.

For suppliers to central government, PPN 014 has required Cyber Essentials or demonstrated equivalent controls for procurements commencing on or after 24 February 2025.

Evidence for this area is generally available from existing systems: conditional access reports from Entra ID or equivalent, a privileged account list with review dates recorded, and offboarding records that can be matched against access removal timestamps.

A reasonable standard is universal MFA with no standing exceptions, plus access reviews triggered by role change rather than only by departure.

Endpoints, patching and vulnerabilities

Start with the device inventory rather than patch compliance, because compliance figures are only meaningful if the denominator is correct.
Inventories drift through reassignment, decommissioning and departmental purchasing that bypasses IT. Devices missing from the inventory are also missing from patch management and endpoint protection coverage, which is what makes inventory accuracy a security control in its own right rather than an administrative detail.

Then assess patch compliance, EDR coverage, disk encryption and vulnerability scanning cadence. Each needs its own evidence rather than a single assurance covering all of them, and coverage reports with timescales are more credible than a description of how patching normally works. Given the fourteen-day auto-fail condition, patch timeliness now needs to be measurable rather than approximate.

A reasonable standard is not zero outstanding vulnerabilities, and assessors will question that claim when it is made. It is full visibility of the estate combined with a repeatable remediation process. A dated remediation plan with a named owner is stronger evidence than a claim that nothing is outstanding.

Email and user behaviour

Email remains the most common initial access route for attacks on SMEs, which justifies more attention than the review time required.

Check filtering configuration, training coverage across the whole workforce rather than new starters only, and whether staff have a straightforward reporting route with visible follow-up. Check SPF, DKIM and DMARC individually, as these are commonly configured partially and then left unchanged.

On phishing simulation, a test that produces no negative results has probably been designed to produce that outcome. The more serious finding is a poor result that generated no remediation. Assessors give more credit to organisations that test, identify genuine weaknesses and address them than to organisations with nothing to report.

Backups and incident response

Backup testing evidence is among the most frequently requested items in insurance renewals and among the most frequently unavailable.
Assess whether backup coverage extends to every critical system, when a restore was last performed, who owns the response outside working hours, and whether the escalation path is documented somewhere a second person can access it.
Retain backup reports in a form a non-technical reader can interpret, retain restore test results with dates, and check the incident contact list against the current organisational structure, as contact details fall out of date faster than the documents containing them.
Remember that documentation carries as much weight as the underlying technology here. A well-designed backup platform without restore evidence and a poor one without restore evidence cannot be distinguished by an assessor, because the distinction exists only in the records.

Policies, suppliers and governance

Acceptable use and information security policies are the minimum, plus any sector-specific requirements, each with a recorded review date and a named owner. Supplier assessments now appear routinely in due diligence for any business handling customer data, and change control needs to be documented in a system rather than managed informally.

Signed policies are the expected artefact. The review schedule is the more informative one, because it is the only evidence that the policies have been maintained rather than written once. Policies that have not been reviewed for an extended period, or that describe superseded processes, undermine confidence in the rest of the documentation.

Making the evidence hold up

Organise evidence by control area, following the structure above, rather than leaving it distributed across email and successive ticketing systems. Each area should hold its supporting documents in one location.

It’s important to be specific about what is incomplete. A partial figure with a completion date and a named owner is more credible than a claim of full coverage that does not survive a follow-up question. Assessors are accustomed to overclaiming, and one inflated answer could cause the rest of the submission to be read more sceptically.

Where outside help is worth the cost

Most internal teams could complete this checklist. Fewer have the available capacity, particularly when existing support demand is already at or above what the team can absorb.

External help is most valuable at two points: defining the scope correctly at the start, and assembling evidence once gaps have been identified, since a realistic remediation plan depends on both. A managed security partner can also convert this from a one-off exercise into a maintained process, which reduces the effort required for each subsequent questionnaire or assessment.

The value of an audit is not limited to satisfying a contractual requirement. It provides an accurate assessment of where your security actually stands, and the evidence practices it establishes reduce the cost of every review that follows.

Where Utilize comes in

Take a look at what our IT security audit entails and get the ball rolling.

IT Security Audit