Guide

Passing Cyber Essentials first time: common failures checklist

Updated

The scheme is designed to be passable by any well-run organisation, and most failures come from the same short list of oversights. Work through it before you submit and the fee usually only needs paying once.

The failures assessors see most

  • Unsupported software still in use: an old Windows version on one forgotten laptop, an out-of-support server, a legacy application. Everything in scope must be supported and updated; one machine can fail the assessment.
  • No MFA on cloud services: the requirement applies to accounts on cloud services, and admin accounts especially. Microsoft 365 or Google Workspace without MFA enforced is a routine failure.
  • Everyone is an administrator: day-to-day work on admin accounts fails user access control. Separate accounts, grant admin rights sparingly, review them.
  • BYOD not declared or not controlled: personal phones and home machines accessing work email are in scope and must meet the controls.
  • High-risk updates older than 14 days: patching monthly is not enough when a critical fix lands mid-cycle; auto-update where you can.
  • Default router or firewall passwords unchanged, and management interfaces exposed to the internet.
  • Vague or wrong scope: answers that do not match reality fail at Plus, where the auditor actually looks.

Pre-submission checklist

  1. Build the inventory first: every laptop, desktop, phone, server and cloud service that touches organisational data, with operating system versions. Every later answer depends on it.
  2. Fix the software estate: remove or replace anything unsupported; turn on automatic updates wherever possible.
  3. Fix accounts: unique logins, separate admin accounts, MFA on cloud services, leavers removed.
  4. Fix devices: firewalls on, defaults changed, device-unlock rules set, anti-malware active on everything in scope.
  5. Dry-run the official question set (free from IASME) with the person who will sign it off, then submit, or have a certification body review your answers first.

If you fail, and how long it all takes

A failed self-assessment comes back with feedback identifying the failing answers, and arrangements for resubmission (including any time window or extra fee) vary by certification body, so ask before you buy. For timing: a small organisation with tidy IT can typically prepare in one to two weeks and receive a certificate within days of a successful submission (typical experience, not a scheme guarantee). Cyber Essentials Plus adds audit scheduling, so allow several weeks and remember the audit must follow the self-assessment within the scheme's time window. Deadline pressure is worth mentioning in the form: providers can often prioritise contract-driven applications.

Independent guide: the authoritative requirements, question sets and current rules are published by the NCSC and IASME, and they change over time; where this page and the current official documents differ, the official documents win.

Questions, answered directly

What happens if I fail Cyber Essentials?

You receive feedback identifying which answers failed, and you can fix the issues and resubmit. Whether resubmission carries an extra fee, and how long you have, varies by certification body, so ask about their retake terms before you buy. Most failures trace to unsupported software, missing MFA or admin-account hygiene, all fixable.

How long does Cyber Essentials take?

For a small organisation with reasonably tidy IT, typically one to two weeks of preparation, then a certificate within days of a successful self-assessment (typical experience; not guaranteed). Cyber Essentials Plus adds an audit that must be scheduled and completed within the scheme's window after the self-assessment, so allow several weeks for the pair.

Get your actual price, not a range.

Two minutes of questions; Cyber Essentials certification bodies and consultants quote you directly. Free, no obligation.

Get Cyber Essentials quotes