Why Cyber Essentials applications fail
Under the current question set, two answers fail the entire assessment on their own — no matter how good everything else is. Knowing which two, and what else commonly goes wrong, is most of the battle.
Cyber Essentials is a self-assessment, marked by a qualified assessor against a published question set. That combination catches people out. Because it is self-assessed, organisations assume it is a paperwork exercise; because it is marked by an assessor, every answer has to be defensible against a specific technical requirement.
Since the Danzell question set came in, the marking is stricter in one significant way. It used to be possible to pick up a couple of major non-compliances and still scrape a pass. Two areas are now automatic failures: get either wrong and the assessment fails outright, regardless of everything else on the form.
Automatic failure 1: MFA missing on a cloud service that offers it
Multi-factor authentication was previously expected. It is now mandatory on every cloud service where it is available, for all users — not just administrators. If a service offers MFA and it has not been turned on, the assessment fails.
The part that surprises people: it makes no difference whether MFA is free, bundled into your plan, provided via another service, or only available as a paid add-on. Availability is the test, not convenience or cost.
Most switch MFA on for email and banking and stop there. The forgotten services are the accounting package, the CRM, file storage, the website content management system, the payroll system, the fundraising or booking platform — and the domain registrar, which is worth singling out because whoever controls it controls your email.
List every cloud service the organisation uses, check each one for an MFA option, and enable it everywhere it exists. Any service where it is available and switched off is a failed assessment.
Automatic failure 2: high-risk updates not applied within 14 days
Security updates rated critical or high risk must be installed within 14 days of release. Miss that and, again, the whole assessment fails.
This covers more than Windows updates. Operating systems, applications, and — the one most often overlooked — network devices and firmware: routers, firewalls, wireless access points. A firewall that has not had a firmware update in two years is a problem even if every laptop is immaculate.
Note also that automatic updates being available is not the same as automatic updates being enabled and verified. The requirement is that the updates are actually installed, within the window.
Pick a device at random and find out when it last installed updates. Then do the same for the router. If you cannot establish it quickly, an assessor will not be able to either — and that lack of visibility is itself the thing to fix, because it is what makes the 14-day rule unprovable.
3. Software the vendor no longer supports
Everything in scope must still be receiving security updates from its vendor. Anything past end of support is a fail — logically enough, since unsupported software cannot meet a 14-day patching rule when no patches exist.
The usual suspects: an old Windows machine kept because it runs one piece of equipment, an Android phone that stopped receiving updates two years ago, an unsupported macOS version on an older Mac, and network hardware supplied by an internet provider a decade ago.
Where something genuinely cannot be upgraded, the options are to replace it or to segregate it properly from the rest of the network so it falls outside the scope — and segregation has to be real, not aspirational.
4. Scope that does not match reality
Scoping is where the most expensive mistakes happen, because an error discovered by the assessor means rework across every answer.
Cloud services are now formally defined and cannot be excluded. That closed a route some organisations previously used. Whatever the organisation uses, it is in scope.
Partial scoping of networks is still permitted, but it is no longer something you can do quietly — where a network is excluded, the reason has to be justified to the assessor. "We only certify the office computers" is not a justification.
And the rule that catches small organisations hardest: any device used to access organisational data or services is in scope, including personally owned ones. If a trustee or director reads work email on their own phone, that phone is in scope and has to meet the requirements. Home working does not remove a device either — a laptop used at home is in scope, and the requirement attaches to the device's own firewall rather than the domestic router.
Either bring personal devices up to standard and include them, or remove the need for them — organisation-provided equipment for the roles that handle data, or access restricted to browser-based services with nothing stored locally. Both are legitimate. What fails is leaving the question open and hoping it is not asked.
5. Accounts and administrative privilege
Three related findings live here. Shared logins fail, because access has to be traceable to an individual. Everyday work carried out from an account with administrative rights fails; administrators need a separate standard account for ordinary use. And accounts belonging to people who have left, or to a former supplier, must be removed rather than merely unused.
Behind all three sits a documented process for granting and revoking access. Assessors ask how you know your account list is current, and "we would remember" is not a process.
6. Default credentials still in place
Anything with a factory-set password must have been changed — routers, wireless access points, printers, network storage, cameras, and any admin interface configured by a contractor. Printers and cameras are the forgotten ones, because nobody thinks of them as computers, and both are routinely reachable from the internet when badly configured.
7. Answers that describe intentions
The question set asks what is in place, not what is planned. Answers phrased as "we are in the process of", "we intend to" or "generally we" are read as the control not being in place. Either it is implemented at the point of submission or it is not — there is no partial credit, and softening the language does not help.
8. Answers inconsistent with each other
Assessors read the whole submission. A device count that does not match the numbers given elsewhere, a cloud service mentioned in one answer but missing from the list, mobile devices excluded in one place and referenced in another — each generates a query, and queries cost time. Read the completed set through as a whole before submitting, checking every number and list agrees.
Which rules apply to you
The Danzell question set and version 3.3 of the requirements apply to assessment accounts created from late April 2026, with transitional arrangements for accounts created before that. An existing certificate is not invalidated by the change — but your next assessment will be marked under the current rules, which is the thing to plan for at renewal rather than discover at submission.
Certification bodies generally allow a window in which to correct issues and resubmit, though the specifics vary. The real cost of failing is rarely the fee; it is the time, and the awkwardness of having told a customer or funder that certification was in hand.
The pattern underneath all of it
Almost every failure above traces to the same root: the organisation did not have an accurate picture of its own devices, accounts and cloud services before it started answering. Build that inventory first — every device, every operating system version, every cloud service, every person with access — and most of the question set answers itself. Skip it, and you are guessing on exactly the questions where guessing now costs you the whole assessment.
Find out what would fail before it does
Our free readiness check runs through the requirements in a few minutes and tells you where you currently stand — no sign-up needed to see the result.
If you would rather not do it yourself, we scope the assessment, tell you plainly what would fail, fix it, and take you through certification.
Take the readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Requirements are set by the NCSC and IASME and are reviewed periodically. This guide reflects the Danzell question set and version 3.3 of the Requirements for IT Infrastructure. Always confirm the requirements applying to your own assessment, as question sets and marking criteria change between scheme years.