The details that bounce an application before anyone looks at your security
Plenty of Cyber Essentials submissions come back not because a control failed, but because the organisation's own name or address did not match the record. Here is what to get exactly right on the form.
Most guidance on Cyber Essentials concentrates on the five controls, which is reasonable — that is what the certification is for. But a submission has to clear an administrative gate before the security answers matter at all, and that gate has become less forgiving.
Certificates now list every legal entity covered. That transparency is welcome for the people reading your certificate, and it means the identity details on your application have to be right rather than approximately right. An organisation that has always described itself loosely will discover exactly how loosely at submission.
The company name must match the register
Use the full registered name, exactly as it appears at Companies House or on the relevant register — including punctuation, brackets, and the suffix. Ltd and Limited are not interchangeable if the register says one of them.
The organisations that trip here are the ones with a trading name they use daily and a registered name they barely think about. If you trade as one thing and are registered as another, the certificate belongs to the registered entity. Your trading name may be able to appear alongside it, but the legal entity is what is being certified.
Open your Companies House record in another tab and copy the name from there. Do not type it from memory, and do not copy it from your own letterhead — letterheads are exactly where informal versions of a company name settle in.
The address must be the registered office
This is the single most common mismatch. Organisations with a registered office at their accountant's or formation agent's address, and a trading address where the work actually happens, routinely enter the one they think of as "our address" — the trading one.
The application wants the registered office as it appears on the register. If your registered office is at an agent in one town and your business operates from a farm or unit in another, it is the agent's address that goes on the form.
The trading address is still relevant, because the assessment scope describes where the work and the devices actually are. Put the registered office where the form asks for the organisation's registered details, and describe the operating locations in the scope. The two are answering different questions.
Group structures and multiple entities
If several companies are involved, decide before you start which entities are being certified. A parent company certificate does not automatically cover subsidiaries, and a certificate naming one entity does not let a related company claim it.
Since the certificate names the entities covered, a customer checking it will see precisely which company holds it. If your contract is with a subsidiary and the certificate names the parent, expect that to be queried by the customer even if it passed assessment.
The scope description
Whole-organisation certification is the default and the cleanest. Where you are certifying a subset, the scope has to be described clearly and — under the current requirements — the reason for excluding anything has to be justified to the assessor rather than simply asserted.
A scope description that says "head office IT" tells an assessor almost nothing. One that names the entity, the locations, the categories of device and the cloud services included, and states plainly what is excluded and why, is what gets accepted. Remember also that cloud services are now formally defined and cannot be excluded at all.
The person signing
The declaration has to be made by someone with the authority to make it — a board-level person or equivalent for your organisation type. For a small company that is a director; for a charity a trustee or the chief executive; for a parish council typically the clerk as proper officer with the council's authorisation, and worth minuting.
The declaration requirement was strengthened alongside the current question set. The signatory is confirming the answers are accurate, which in practice means they need to have satisfied themselves rather than simply trusting whoever filled the form in.
Contact details and the renewal trap
Use an address that will still be monitored in twelve months and that more than one person can reach. Assessor queries land there, and so do renewal reminders.
Applications stall every year because the query went to a personal address belonging to someone who has since left, or to an unmonitored generic mailbox. A shared mailbox that two people watch — with individual logins and MFA, since it is in scope — is the right answer.
A five-minute pre-submission check
- Name — copied from the register, not typed from memory.
- Address — the registered office, not the trading address.
- Entities — every one you need covered is named.
- Scope — entity, locations, devices and cloud services stated; exclusions justified.
- Signatory — has the authority, and has actually checked.
- Contact — monitored by more than one person, and will still exist next year.
None of this is difficult. It is simply the part that no one thinks to check, because it feels like the easy bit at the top of the form — and it is the reason a submission comes back untouched while the deadline you were working to carries on approaching.
We check the boring bits too
Scoping, entity details and the declaration are part of the job, not an afterthought — because a submission that bounces on an address costs you the same fortnight as one that fails on a control.
Take the free readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Scheme requirements are set by the NCSC and IASME and are reviewed periodically. Confirm the requirements applying to your own assessment before you begin.