Cyber Essentials is five controls. The questionnaire asks whether you have them. This is the working version of that question — what each control actually requires, where firms genuinely fail, and how to check before you submit rather than after.
Worth reading even if you certified last year, because the requirements changed in April 2026.
What changed in v3.3 (April 2026)
Four things, and the second one bites hardest:
- MFA is mandatory on cloud services. Not recommended. Required.
- 14-day patching is now an auto-fail condition. Miss it and you do not get a discussion about compensating controls.
- Cloud services are fully in scope. Everything your business runs on, not just the machines on desks.
- A director must sign a compliance declaration. The sign-off is personal.
If your last certificate predates April 2026, assume the bar moved.
Before the five controls: get scope right
Almost every failure starts here. In scope is every device and service that touches organisational data:
- [ ] Desktops and laptops, including home workers'
- [ ] Mobile phones used for work email — routinely missed
- [ ] Personally owned devices under any BYOD arrangement, if they access company data
- [ ] Servers, wherever they live
- [ ] All cloud services — Microsoft 365, Google Workspace, your CRM, file storage, anything holding company data
- [ ] Routers and firewalls, including home routers where staff work remotely
Scope honestly. Whittling scope to make the form easier produces a certificate that describes a company you do not run.
Control 1 — Firewalls
Every device that connects to the internet, and the network boundary itself, must sit behind a correctly configured firewall.
- [ ] Boundary firewall in place, with the default administrative password changed
- [ ] No unnecessary inbound ports open to the internet
- [ ] Any remote-access service either removed or protected by MFA
- [ ] Software firewall enabled on devices used outside the office
- [ ] Firewall admin interface not reachable from the internet
Where firms fail: an old port-forward opened years ago for something that no longer exists, and a firewall still on its factory password.
Control 2 — Secure configuration
Devices must provide only the functions they actually need.
- [ ] Default passwords changed on every device and application before use
- [ ] Unnecessary user accounts removed or disabled, including guest accounts
- [ ] Unused software and services removed
- [ ] Auto-run and auto-play disabled where they present a risk
- [ ] Device lock enabled — password, PIN, or biometric — on every machine and phone in scope
Where firms fail: printers, NAS boxes, and network kit installed by somebody who left, still holding whatever password came in the box.
Control 3 — User access control
The control that fails most often, by a distance.
- [ ] MFA on every cloud service — mandatory as of v3.3, and no longer just for admins
- [ ] Every user account belongs to a named individual — no shared logins
- [ ] Administrative rights granted only where required, not by default
- [ ] Admin accounts used only for admin work, with a separate standard account for everyday use
- [ ] A leaver process that actually disables accounts, promptly
- [ ] All accounts reviewed — ex-staff, contractors, old service accounts
Where firms fail: see below. This is the big one.
Control 4 — Malware protection
- [ ] Anti-malware active on every in-scope device, and updating automatically
- [ ] Protection cannot be disabled by standard users
- [ ] Where you rely on application allow-listing instead, it is genuinely enforced
- [ ] Mobile devices covered — not just laptops
Where firms fail: protection installed but silently expired, or turned off during a project and never restored.
Control 5 — Security update management
- [ ] All critical and high-severity updates applied within 14 days of vendor release — operating systems, applications, and firmware
- [ ] Automatic updates enabled wherever possible
- [ ] No unsupported software or operating systems anywhere in scope — end-of-life fails you outright
- [ ] Something actually reports patch status, rather than everyone assuming
- [ ] Firmware included — routers, firewalls, printers
Where firms fail: the 14-day window is now an auto-fail, and "we install updates when we notice" is not a patching process. Firmware is the forgotten half.
The four things behind most failures
Roughly 60% of UK Cyber Essentials failures come down to the same four issues, and all four sit in user access control:
- Missing MFA on a cloud admin account
- Ex-staff still active in Microsoft 365 or Google Workspace
- Shared logins — the "office@" account everyone uses
- Local admin rights granted to everyone by default
If you fix nothing else before submitting, fix those four. They are free, they take an afternoon, and they are the difference between passing and paying twice.
The pre-submission sanity check
- [ ] Every device that touches company data is listed, phones included
- [ ] Nothing in scope is running an operating system past end-of-life
- [ ] MFA is on across every cloud service, for everyone
- [ ] The user list matches the people who actually work here
- [ ] Patch status can be evidenced, not just asserted
- [ ] The director signing the declaration has seen the answers
Answer honestly. A certificate obtained on optimistic answers is worse than no certificate — it is a signed statement that will be read back to you after an incident.
Making it hold between certifications
Firms find recertification painful for one reason: the controls were assembled for the questionnaire rather than running continuously. Twelve months later, the patching drifted and three leavers still have accounts.
Telebyte Shield is built for that — managed security for small and regulated firms, running the same stack we use across our own estate: patching inside the 14-day window, device encryption, MFA, threat protection, and a compliance dashboard from £25 per user per month. The checklist stays true on its own.
Related reading: what Cyber Essentials actually costs in 2026 and what the Plus audit tests. If you are working through this and something does not fit your setup, tell us what you have and we will give you a straight answer.
Reflects the Cyber Essentials requirements as published at the time of writing, including the April 2026 v3.3 update. Confirm current requirements with your certification body before submitting.