You may already have several of the required security measures in place, so a useful starting point is understanding where you stand and what, if anything, needs attention.
By working through that before you submit, you’ll give yourself time to resolve any gaps and improve your chances of passing first time, with less pressure to make last-minute changes.
In this guide, we’ll explain what assessors look for and where organisations can run into difficulty, with practical advice to help you prepare for a successful assessment.
What does it mean to pass Cyber Essentials?
Cyber Essentials is a UK Government-backed scheme that helps organisations protect themselves against common cyber threats. It focuses on five technical controls, which are the security measures you’ll need to have in place to achieve certification.
If you’re applying for Cyber Essentials, you’ll complete a verified self-assessment questionnaire describing how your organisation meets those requirements. Your answers are signed off by a board member or equivalent and reviewed by a qualified assessor, who’ll confirm whether they meet the standard.
With Cyber Essentials Plus, the requirements are the same, although an assessor will also carry out independent technical testing to check that the controls are working in practice. That testing isn’t part of the standard Cyber Essentials assessment.
Before you get too far into preparing, it’s worth checking which level you need. If certification is linked to a contract or tender, the procurement documents may specify Cyber Essentials or Cyber Essentials Plus, along with a deadline. Where that isn’t clear, asking the customer to confirm their requirements before you book will help you allow enough time for any additional assessment.
Start with a clear picture of what’s in scope
Your assessment scope sets out which parts of your organisation’s IT are covered by certification. Although it might sound like an admin detail, it affects the answers you’ll give throughout the questionnaire.
We’d suggest starting with a review of the devices and software your people use, including when they’re working away from the office. Employee-owned devices that access business data or services are generally included, though there are exceptions. A personal phone used only for an authentication app, for instance, is out of scope.
Cloud services also need to be considered as part of reviewing your IT infrastructure, including business email, file storage and other online tools.
Alongside your IT records, it can help to ask colleagues which online tools they use. A subscription bought by an individual department could otherwise be missed, particularly if it was set up without involving IT.
If you’re hoping to certify only part of the organisation, it’s best to discuss that with your certification body early. A limited scope may be possible, provided it’s clearly defined and meets the scheme’s rules.
Understanding the five technical controls
You don’t need to become a security specialist to coordinate certification. What helps is knowing who can answer the technical questions, then giving them enough time to check how each requirement is being met.
Firewalls
A firewall helps control traffic between your systems and the internet, so it’s an important part of preventing unauthorised access. For the assessment, you’ll need to understand how that protection is configured and why any incoming connections have been allowed.
As you review your firewall arrangements, it’s worth asking whether access enabled for an old project is still needed. You’ll also want to check how laptops are protected when people work away from the office, where the network arrangements may be different.
Secure configuration
When a new device or application arrives, its default settings won’t necessarily be right for your business. There may be features you don’t use, or accounts that were included during setup but aren’t needed.
Secure configuration involves reviewing those settings, removing or disabling anything unnecessary, and making sure access to devices is protected. If you already follow a consistent setup process for new equipment, that can help, although older devices are worth reviewing too, as their settings may have changed.
Security update management
Software can carry on working after its security support has ended, making it an area that’s easy to overlook. For Cyber Essentials, the software you use needs to remain supported and receive the required security fixes, including updates for applications and the firmware running your routers and firewalls.
High-risk and critical fixes need to be applied within 14 days of release. The same deadline applies where the vendor hasn’t provided details of the vulnerabilities being addressed. As our guide to operating systems and Cyber Essentials explains, a monthly update routine may therefore leave you outside the required timescale.
If your IT provider handles updates, ask how they check that installations have completed successfully. An update might have downloaded but still be waiting for a restart, while some fixes require a configuration change as well as a patch.
User access control
Access granted for an old project or previous role can stay in place long after it’s needed. Reviewing access when someone changes jobs internally, as well as when they join or leave, can help you keep track.
Administrator accounts need particular care because they allow more significant changes to your systems. For Cyber Essentials, they need to be kept separate from accounts used for everyday email and browsing, so someone who manages IT will still need a standard account for their routine work. Our guidance on account separation explains how this applies.
It’s also advisable to check multi-factor authentication (MFA) early, as it adds another means of verifying someone’s identity when they sign in. For cloud services where MFA is available, it must be used, even if it’s only offered through a paid option. Failing to implement it will result in an automatic assessment failure.
Malware protection
Malware protection helps stop harmful software from running on your devices. Depending on the device, this can involve anti-malware software or controls that allow only approved, signed applications to run.
Although you may already have protection installed, it’s sensible to check that it’s active and correctly configured across the devices it needs to cover. A licence tells you what you’ve bought, but you’ll also need to know how it’s being used. Our overview of Cyber Essentials and its five controls explains how malware protection fits into the scheme.
Why do organisations fail Cyber Essentials?
Organisations can fail Cyber Essentials when required controls are missing, aren’t applied consistently across the assessment scope, or haven’t been clearly explained in their questionnaire answers. When you’re reviewing your controls, a useful question to keep coming back to is whether the answer applies everywhere within your scope.
Your update process might work well for office laptops, for example, while missing equipment that’s only switched on occasionally. Similarly, MFA could be protecting your main email platform while a separate cloud application still allows people to sign in with a password alone.
Alongside those checks, it’s important to pay attention to a few other areas, including:
- Unsupported software. If an older application is still doing its job, there may have been little reason to question it. However, once security support ends, keeping it in scope can prevent certification, so it helps to check support dates as well as installed versions.
- Administrator accounts used for everyday work. Even where separate accounts exist, it’s worth confirming that people use them appropriately, including those who look after IT.
- Responsibilities that haven’t been fully agreed. Where a provider manages a control, ask them to explain what they cover and whether anything still needs to be handled by your team.
- Answers based on what’s supposed to happen. A policy may say that updates are installed promptly, although you’ll need to check whether that’s happening across your systems before relying on it in your assessment.
Missing the required deadlines for high-risk and critical security updates will result in an automatic failure. Because these requirements can determine the outcome even when other controls are in place, they deserve attention before you submit.
How to prepare your questionnaire answers
You can download the questions before purchasing certification, which gives you a chance to work through them without immediately committing to the assessment timetable. Reading them alongside the requirements document should help you identify where you’re ready and where you need more information.
Just make sure you’re working from the versions that apply to your assessment. IASME’s assessment preparation page brings together the question sets, requirements documents and Cyber Essentials Plus test specifications. Your certification body can confirm which versions you’ll need if you’re unsure.
As you prepare your answers, try to explain how things work in your organisation. If a question asks how a control is managed, saying “our IT provider handles this” may leave the assessor needing more detail, even if the provider is doing everything correctly.
Keeping supporting information together can make this easier. For example, device lists and update reports can help you check your answers and respond if the assessor asks for clarification. You don’t need to treat this as a fixed evidence pack that every standard assessment requires, but having the information to hand can save time.
Before submitting, we’d recommend allowing your IT contact and the person signing the declaration time to review the answers. If something’s still uncertain, your certification body can help you understand the question before you commit to an answer.
Preparing for Cyber Essentials Plus
If you’re working towards Plus, it makes sense to prepare for the technical assessment while you’re completing the self-assessment. The Plus audit needs to be completed within three months of the underlying Cyber Essentials certification, so leaving all the preparation until afterwards can make the timetable tighter than you’d like.
The assessment includes vulnerability scanning and checks on a representative set of user devices, alongside internet gateways and internet-facing servers. Your certification body can talk you through the assessment coverage and explain which people need to be available, as well as what access the assessor will need.
Pre-assessment checks can be helpful here, particularly if fixing an issue is likely to take time. Where a problem affects several devices, it needs to be addressed across the affected environment, rather than only on the devices selected for testing.
That wider coverage is important during retesting, too. An update-management retest includes an additional random sample of devices to check that the improvements have been applied broadly.
What happens if you don’t pass first time?
If your assessment isn’t successful, you’ll receive feedback explaining which answers or controls haven’t met the requirements. Although that can be frustrating when you’re working towards a deadline, it gives you something specific to address with your IT team or provider.
Sometimes, an assessor simply needs more information before they can reach a decision. It’s a good idea to check whether they’re asking you to clarify an answer or make a change to your systems, because the next steps will be different.
There’s typically a limited window to resubmit following an unsuccessful standard assessment, so speak to your certification body promptly about the deadline. Further attempts can also call for a new application and fee, which is why we’d suggest leaving some contingency before a tender or contract deadline, even if you feel well prepared.
After passing: your certificate and Cyber Essentials logo
Once you’ve passed, you can use the official Cyber Essentials badge to show customers that your organisation has achieved certification. Adding it to your website or email signature makes your certification easier for prospective customers to recognise when they’re considering doing business with you.
Your certification body can provide the approved artwork and branding guidance, which explains how it can be used on your website and marketing materials. You’ll need to use the mark for the level you’ve achieved, while making sure any accompanying claims reflect the scope you’ve certified.
The badge can only be used while your certificate is valid, in line with the scheme’s terms and conditions. Since certification lasts 12 months, it’s sensible to plan your annual renewal before expiry.
In the meantime, keeping an eye on your controls as people join and systems change will help you maintain the work you’ve put in, so there’s less to revisit when renewal comes around.
Get support with your Cyber Essentials preparation
You don’t need to have every technical answer before speaking to someone. If you’re unsure what belongs in scope, or how a question relates to the way your business works, an early conversation can help you work out what needs attention.
Cyber Tec Security offers guided and managed certification options, with support to help you understand the questions and prepare your submission. While you’ll still need to put the required controls in place, you’ll have experienced people available to explain what’s needed and help you work through anything you’re unsure about.
Talk to Cyber Tec Security about preparing for your assessment.

