Guide
Passing Cyber Essentials first time: common failures checklist
Updated
The scheme is designed to be passable by any well-run organisation, and most failures come from the same short list of oversights. Work through it before you submit and the fee usually only needs paying once.
The failures assessors see most
- Unsupported software still in use: an old Windows version on one forgotten laptop, an out-of-support server, a legacy application. Everything in scope must be supported and updated; one machine can fail the assessment.
- No MFA on cloud services: the requirement applies to accounts on cloud services, and admin accounts especially. Microsoft 365 or Google Workspace without MFA enforced is a routine failure.
- Everyone is an administrator: day-to-day work on admin accounts fails user access control. Separate accounts, grant admin rights sparingly, review them.
- BYOD not declared or not controlled: personal phones and home machines accessing work email are in scope and must meet the controls.
- High-risk updates older than 14 days: patching monthly is not enough when a critical fix lands mid-cycle; auto-update where you can.
- Default router or firewall passwords unchanged, and management interfaces exposed to the internet.
- Vague or wrong scope: answers that do not match reality fail at Plus, where the auditor actually looks.
Pre-submission checklist
- Build the inventory first: every laptop, desktop, phone, server and cloud service that touches organisational data, with operating system versions. Every later answer depends on it.
- Fix the software estate: remove or replace anything unsupported; turn on automatic updates wherever possible.
- Fix accounts: unique logins, separate admin accounts, MFA on cloud services, leavers removed.
- Fix devices: firewalls on, defaults changed, device-unlock rules set, anti-malware active on everything in scope.
- Dry-run the official question set (free from IASME) with the person who will sign it off, then submit, or have a certification body review your answers first.
If you fail, and how long it all takes
A failed self-assessment comes back with feedback identifying the failing answers, and arrangements for resubmission (including any time window or extra fee) vary by certification body, so ask before you buy. For timing: a small organisation with tidy IT can typically prepare in one to two weeks and receive a certificate within days of a successful submission (typical experience, not a scheme guarantee). Cyber Essentials Plus adds audit scheduling, so allow several weeks and remember the audit must follow the self-assessment within the scheme's time window. Deadline pressure is worth mentioning in the form: providers can often prioritise contract-driven applications.
Independent guide: the authoritative requirements, question sets and current rules are published by the NCSC and IASME, and they change over time; where this page and the current official documents differ, the official documents win.