How to pass Cyber Essentials first time
- security
- cyber-essentials
- audit
- windows
The basic Cyber Essentials assessment costs a micro business £320 plus VAT, paid to IASME before anybody looks at a single answer. Fail it, and IASME’s own FAQ gives you two working days to fix things, update your answers and resubmit at no extra charge. Fail again after that and you reapply and pay the fee a second time.
Two working days is enough to change a setting. It is not enough to replace a laptop, and it is nowhere near enough to find out that your bookkeeper’s Xero login never had a second factor on it.
That is what I mean when I say on the service page that going in unprepared is how people fail it twice. The questions are published. The things that fail people are predictable. Most of what fails could have been found in a week, before you paid.
Download the questions before you buy anything
IASME publishes the self-assessment question set for free. The current one is called Danzell, it went live on 26 April 2026, and it sits on top of version 3.3 of the NCSC’s Requirements for IT Infrastructure. Read the whole thing before you open an account. Once you have paid you get six months to submit, and after that the account can be closed and you pay again anyway.
Filling it in takes about an hour if you have the answers ready. Getting the answers ready is the real work.
Two questions now fail you on their own
IASME’s note on the April 2026 changes is blunt about this. There are now answers that fail the whole assessment, however good everything else is.
The first is multi-factor authentication on cloud services. The requirements document says authentication to cloud services “must always use MFA”, and IASME says that if a service offers MFA and you have not turned it on, you automatically fail. Not most services. All of them, for administrators and for everybody else.
The second is patching. Security updates rated critical or high by the vendor, or scoring 7 or above on CVSS v3, have to be installed within 14 days of release. Where the vendor gives no severity at all, the same 14 days applies. Get either of those questions wrong and the assessor does not weigh it against your strengths.
I would add a warning on the patching one from my own server. Installed is not the same as running. My Linux box once reported itself fully patched while three kernels behind, because a kernel sitting on disk does nothing until something reboots into it. Windows does its own version of this with a pending restart that nobody accepts for three weeks.
Your scope is bigger than you think
This is where honest answers go wrong without anybody lying.
Version 3.3 is clear that every device used for the business is in scope, and that includes staff’s own phones if they read work email on them. Home workers’ laptops are in. A router you gave somebody to take home is in. Any cloud service holding your data is in, and you cannot write it out of scope.
So make a list of everything the business logs into. Microsoft 365 is the one everybody remembers. Then the accounts package, the file sharing, the CRM, the payroll site, the domain registrar and the website’s control panel. Every one of those needs MFA switched on if it offers it. In my experience the list is always longer than the first answer, and the service at the bottom of it is the one with a shared login and no second factor.
The one old machine
Everything in scope has to be licensed and still supported by its vendor. Windows 10 lost support on 14 October 2025, so a machine still running it needs to be on Microsoft’s paid Extended Security Updates or it is unsupported software sitting inside your boundary.
The usual culprit is one PC in the back office running one application that never got updated for Windows 11. It works. Nobody wants to touch it. And it fails the assessment unless it is taken off the internet entirely, which the requirements allow by putting it in a sub-set that blocks all traffic to or from the internet. Either way the fix is a purchase or a small project, and you cannot do either in two working days. Find this machine first.
The answers people get wrong in good faith
A handful of questions catch people who think they are compliant.
Administrator accounts have to be separate from the account you do your day’s work in. No email, no browsing on the admin account. If the director who set up Microsoft 365 reads his email as a global admin, that is a fail, and it is very common.
Passwords have three routes through: 12 characters minimum, or 8 characters with a block on common passwords, or MFA. Devices have to lock after no more than 10 wrong attempts, or slow the guesses down to no more than 10 in five minutes. And here is the one that surprises people: the scheme tells you not to force regular password expiry and not to force complexity rules. A policy that makes everybody change their password every 60 days is the old advice, and version 3.3 lists it under things not to do.
Where my audit fits, and where it stops
The audit I sell is read-only and runs against 17 checks on Windows machines. It changes nothing, and every finding carries the value it was read from, so you or your IT provider can verify it without me. I wrote about why it only reads separately. Each finding is mapped to the Cyber Essentials control it relates to.
It is good at a specific slice. Missing Windows updates, end-of-life software, whether the host firewall is on, whether Defender is running and up to date, local accounts, the password and lockout policy actually in force on the machine. That is real evidence against three of the five controls.
It cannot see your cloud services. It has no idea whether MFA is on in Microsoft 365 or anywhere else, and that is the single most likely thing to fail you. It does not look at phones or Macs. It cannot tell you who has left the company and still has a login. My honest estimate is that on a typical small business it answers about a third of the question set, and it is the easier third. The rest is a list and a conversation, and I will go through it with you, but I am not going to pretend a scan does it.
I cannot certify you, either. Only an IASME-licensed certification body can, and I do not hold the certificate myself. What I can tell you is where you stand before you pay the assessor.
What I would do in the week before applying
Download the Danzell questions and read them all. Write down every cloud service the business uses, and check MFA on each one for every user, not just yours. Find the oldest operating system anywhere in the business, phones included. Separate the admin accounts. Run the audit, or something like it, on the Windows machines, fix what it finds and run it again, because a re-audit is the only way I know to tell a fix from a closed ticket.
Then apply. If the assessor still comes back with something, it should be small enough to sort out in two days.
The audit is a fixed price based on how many machines are in scope, the re-audit costs less, and there is no retainer or obligation to have me fix anything. If you have been sent a supplier questionnaire as well, most of its technical questions are the same five controls, so one piece of preparation covers both.
