Cyber Essentials failure is almost never caused by a sophisticated security gap. It is caused by an end-of-life laptop nobody logged, a cloud service that was quietly left out of the scope statement, or a director who has been using an administrator account to read email for four years. The controls themselves are deliberately basic. What catches organisations out is the gap between how their estate actually looks and how they believed it looked when they started filling in the question set.

That gap is expensive because the scheme gives you very little room to close it. Certification is pass or fail, there is no partial credit, and the free correction window after a failed submission is two working days. Miss it and you reapply and pay the fee again. For anyone bidding for public sector work, sitting inside a supply chain, or renewing an insurance policy, a slipped certificate is not just an administrative annoyance — it is a live commercial problem. Our guide to Cyber Essentials as a supply chain trust signal covers why buyers ask for it in the first place.

This article works through the Cyber Essentials failure reasons that genuinely cost organisations their certificate, control by control, against the current requirements: version 3.3 of the Requirements for IT Infrastructure, effective from 27 April 2026. For each one you get what the assessor is looking at, why the answer usually falls apart, and the fix that prevents it. It finishes with a 60-day readiness plan and what to do if you have already had a result you did not want.

Why Cyber Essentials Failure Is More Common Than Buyers Assume

cyber essentials failure reasons how to avoid b transparent cube blocks plinth

Plenty of well-run organisations fail on the first attempt, and the reasons behind a Cyber Essentials failure are rarely flattering to anybody’s security posture — they are usually about record-keeping. Understanding the shape of the assessment explains most of it.

The scheme is pass or fail, with no scoring

There is no mark out of a hundred and no “mostly compliant” outcome. IASME is explicit that you must be compliant in nearly every question to pass, and that certain answers end the assessment outright. Treating the question set like a maturity questionnaire, where a partial answer earns partial credit, is the single most common mindset behind a Cyber Essentials failure.

Two working days is the entire safety net

If your submission is marked non-compliant, you get two working days to examine the assessor’s feedback, correct simple issues and resubmit — at no extra charge. The assessor then remarks it. If you still fail after that window, you reapply and pay the assessment fee again. Two days is enough to rewrite a vague answer. It is not enough to replace a server, migrate off unsupported software or roll out multi-factor authentication across the business.

Most failures are administrative, not technical

The controls map onto things most organisations already do. What they usually cannot do is prove it consistently across every device and every cloud service on the day of assessment. A Cyber Essentials failure normally traces back to an incomplete asset list rather than a missing security product, which is why disciplined IT asset management is the highest-leverage preparation work available.

The declaration raises the stakes

A board-level officer signs a declaration that every answer is true. That signature converts a sloppy self-assessment from a technical problem into a governance one, and it turns a Cyber Essentials failure into a board-level conversation rather than an IT one. It is also why assessors push back hard on answers that sound aspirational rather than descriptive.

Where first-time applicants lose the assessment (indicative model of 100 non-compliant answers, based on assessor-reported patterns)
Unsupported software still inside the scope 26%
Updates applied outside the 14-day window 22%
Scope drawn to exclude something it cannot 18%
MFA missing on at least one cloud service 15%
Administrator accounts used for daily work 11%
Firewall rules undocumented or unapproved 8%

The Five Controls Where Cyber Essentials Failure Actually Happens

cyber essentials failure reasons how to avoid c sphere tile patches plinth

Every question traces back to one of five technical control themes. Knowing which theme a question belongs to tells you what evidence the assessor expects, and it is the fastest way to predict where a Cyber Essentials failure will come from in your own estate.

Firewalls

Every in-scope device must sit behind a correctly configured firewall or a network device with firewall functionality. Default administrative passwords must be changed or remote administration disabled, unauthenticated inbound connections blocked by default, and every inbound rule approved, documented with a business need, and removed when it is no longer needed.

Secure configuration

Unnecessary accounts and software must be removed or disabled, default and guessable passwords changed, auto-run disabled, and device locking applied where physical presence unlocks a device. Unlock credentials need at least six characters, with brute-force protection set to no more than ten guesses in five minutes or a lockout after ten failed attempts.

Security update management

All in-scope software must be licensed and supported, set to update automatically where possible, and patched within 14 days for anything the vendor calls critical or high risk, anything scoring CVSS v3 base 7.0 or above, and anything where the vendor gives no severity at all. That last clause causes a Cyber Essentials failure somewhere every single year.

User access control

Accounts are created through an approval process, authenticated with unique credentials, and removed when no longer required. Administrative activity happens in separate accounts used for nothing else. Access to cloud services must always use multi-factor authentication. Special privileges come off when someone changes role.

Malware protection

Every in-scope device needs an active mechanism: anti-malware software configured to update, block execution of malicious code and prevent connections to malicious sites, or application allow listing restricted by code signing with a maintained list of approved applications.

Control themeWhat the assessor checksMost common failureThe fix
FirewallsDefault credentials, inbound rules, exposed admin interfacesRules with no documented business needA one-page rule register with owner and justification
Secure configurationUnused accounts, default passwords, device lockingDormant local admin and guest accountsDisable at build; audit quarterly
Security update managementSupported software, automatic updates, the 14-day ruleUnsupported software anywhere in scopeA dated end-of-life column on the asset register
User access controlJoiners and leavers, admin separation, MFA on cloudAdmin accounts used for email and browsingSeparate named admin accounts, no mailbox
Malware protectionActive protection or signed allow listing on every devicePersonal phones with nothing configuredEnrol devices or remove them from scope properly
Scope (applies to all five)Boundary, sub-sets, cloud services, end user devicesA boundary that omits something mandatoryAgree the scope with the certification body first

Scope Mistakes: The Most Expensive Cyber Essentials Failure

cyber essentials failure reasons how to avoid d padlock two keyholes plinth

Scope is decided before a single technical question is answered, and it quietly determines whether the rest of your answers can be true. Every other Cyber Essentials failure in this article gets worse when the boundary is wrong, because a bad boundary hides the assets that break the controls.

Whole organisation is the default position

Your assessment should cover the whole of the IT infrastructure used to run the business, or a well-defined and separately managed sub-set. If you exclude part of the estate, you must justify that partial scope to your assessor and define the boundary precisely: the business unit that manages it, the network boundary and the physical location. Scope has to be agreed with the certification body before assessment begins, not asserted afterwards, and a boundary invented at submission time is the quickest route to a Cyber Essentials failure.

Cloud services cannot be excluded any more

Version 3.3 removed the ambiguity entirely with a definitive statement that cloud services hosting your data or services must be in scope. Software as a service, platform as a service and infrastructure as a service all count, and while the provider may implement some controls, user access control is always yours. Where a provider implements a control for you, you need contractual clauses or referenced security statements confirming it; an unevidenced assumption there is a Cyber Essentials failure in waiting.

A sub-set has to be genuinely segregated

A sub-set is part of the organisation whose network is segregated from the rest by a firewall or VLAN. For Cyber Essentials Plus the assessor verifies that segregation by technical means. Drawing a line on an architecture diagram around the systems you are confident about, while the finance PCs share the same flat network, is a Cyber Essentials failure waiting to be discovered during testing.

A scope without end user devices is not acceptable

The requirements state this plainly, and it closes the most popular loophole: certifying “the server environment” while leaving every laptop and phone outside. Good device management is what makes a whole-organisation scope survivable rather than terrifying.

AssetIn scope?Why
Microsoft 365, Google Workspace, DropboxYesCloud services holding organisational data cannot be excluded
Personal phone with work emailYesBYOD accessing organisational data or services is in scope
Personal phone used only for an MFA appNoNative voice, native text and MFA-only use are excluded
Router you supplied to a home workerYesOrganisation-supplied home routers are in scope
The home worker’s own ISP routerNoOut of scope, so apply a software firewall on the device
Company laptop loaned to a contractorYesAll organisation-owned devices loaned out are in scope
Contractor’s own laptopNoThird-party owned contractor devices sit outside
Account your MSP uses to administer your systemsYesAll accounts your organisation owns are in scope

Unsupported Software: The Automatic Cyber Essentials Failure

cyber essentials failure reasons how to avoid e clipboard blank rows plinth

IASME names this one directly as an automatic fail: any organisation using unsupported software within the scope of the assessment will not achieve certification. There is no mitigation argument, no compensating control and no discussion. It is the cleanest Cyber Essentials failure in the scheme and also the most predictable.

One end-of-life product ends the assessment

Supported means the vendor has committed to providing regular vulnerability fixes and has published the date those fixes will stop. A single Windows build past its servicing date, an old SQL Server instance, an unsupported PHP runtime on a web server or an abandoned line-of-business application is enough. The assessment does not weigh it against everything you did right, and no other Cyber Essentials failure arrives this abruptly.

Firmware and appliances count as software

The definition of software includes operating systems, off-the-shelf applications, extensions, interpreters, scripts, libraries, network software, and firewall and router firmware. The forgotten devices are almost always network devices: an end-of-life firewall at a branch office, a NAS the vendor stopped patching, an old wireless controller. These rarely appear on the asset list that the IT team compiles from the laptop fleet, which is how a Cyber Essentials failure arrives from a cupboard nobody has opened in two years.

There are exactly two legitimate routes out

Remove the software from the device, or remove it from scope using a defined sub-set that prevents all traffic to and from the internet. The second route is real but genuinely restrictive — it means an air-gapped or fully isolated segment, verified as segregated, not a VLAN with an outbound rule for updates.

Virtual patching will not rescue a legacy system

The Cyber Essentials Plus test specification states that virtual patching is not an acceptable long-term mitigation for vulnerabilities in legacy unsupported operating systems and will not be recognised as a mechanism for compliance. If your plan for an ageing platform is a wrapper of network controls, plan a migration instead. A structured vulnerability assessment will find these systems before an assessor does.

Patching Delays That Trigger Cyber Essentials Failure

cyber essentials failure reasons how to avoid f staircase four blocks plinth

Patching is where organisations with good intentions get caught, because the requirement is a deadline rather than a process. You either applied the update inside the window or you did not, and this is the second-largest source of Cyber Essentials failure after unsupported software.

The 14-day clock starts at release, not at discovery

Updates must be applied within 14 days of release where the vendor describes the vulnerability as critical or high risk. Not 14 days from when your monitoring flagged it, or from when the change advisory board met. If your patch cycle is monthly with a testing soak, you are already outside the window for anything released early in the cycle, and that is a Cyber Essentials failure the moment an assessor samples a device.

CVSS 7.0 and the “no severity stated” trap

Three conditions each trigger the 14-day rule: a vendor label of critical or high risk, a CVSS v3 base score of 7.0 or above, and — the one that catches people — updates where the vendor provides no detail about the severity at all. Plenty of smaller vendors ship release notes that say nothing useful, and by default those updates are in scope for the deadline.

Browsers, plugins and the software nobody owns

Bundled updates matter too: where a vendor rolls several fixes of differing severity into one package and any of them is critical or high risk, the whole update must go on within 14 days. The practical risk sits with software installed by users — browsers, PDF readers, meeting clients, developer tooling — none of which appears in a server patch report and any of which can produce a Cyber Essentials failure.

Mobile devices drift fastest

Phones and tablets update on the user’s schedule unless you enforce otherwise, and an unattended device sitting several OS versions behind is a straightforward finding. Enrolment and update enforcement are the only reliable answer, which is why bringing mobiles into managed IT services before certifying is usually cheaper than remediating afterwards.

Admin Account Mistakes Behind Many Cyber Essentials Failures

User access control produces more awkward conversations than any other theme, because the fixes touch how senior people work day to day. It is also the theme where a Cyber Essentials failure is most often self-inflicted through convenience.

Separate accounts for administrative work only

The requirement is unambiguous: use separate accounts to perform administrative activities only, with no emailing, web browsing or other standard user activity that could expose those privileges. The requirements document illustrates it with ransomware executing at administrator privilege because the user was logged in as an administrator when they opened a malicious attachment.

The leavers list is the evidence assessors ask for

Accounts must be removed or disabled when no longer required — when someone leaves, or after a defined period of inactivity. Assessors ask how you know, and “the manager tells IT” is a weak answer when the last three leavers still have active mailboxes. A documented joiners, movers and leavers process with dated records is what turns this from an assertion into evidence, and it removes one of the easiest Cyber Essentials failure findings to avoid.

Third-party and MSP accounts are your responsibility

Every account your organisation owns is in scope even when a supplier, contractor or managed service provider uses it. If you use externally managed services such as remote administration, you must be able to confirm the controls are met and demonstrate it in your answers. Contracts are the practical mechanism, and our guide to Cyber Essentials for suppliers sets out the wording that makes it enforceable.

Password rules people still get wrong

The scheme now expects the opposite of the old orthodoxy, so a 90-day expiry policy is a Cyber Essentials failure rather than the good practice it once was. You must not enforce regular password expiry and must not enforce complexity requirements. Instead you pick a technical control that manages quality: multi-factor authentication, a 12-character minimum, or an 8-character minimum combined with automatic blocking of common passwords from a deny list.

Route you chooseMinimum password lengthAdditional requirement
Multi-factor authentication8 characters, no maximumA second factor: managed device, app, token or trusted account
Long passwords only12 characters, no maximumBrute-force protection on the account
Shorter passwords plus a deny list8 characters, no maximumAutomatic blocking of common passwords
Device unlock credential only6 characters or PINThrottling, or lockout after 10 failed attempts
Passwordless: passkeys and FIDO2Not applicableFIDO2 authenticators are treated as MFA
Any cloud service8 characters with MFAMFA is mandatory, not optional

Missing MFA: A Fast Route to Cyber Essentials Failure

Multi-factor authentication has moved from good practice to a hard requirement in the place most organisations are weakest, and partial deployment is where a confident applicant discovers an unexpected Cyber Essentials failure.

Cloud services must always use MFA

The wording in the requirements is that you must implement MFA where available, and that authentication to cloud services must always use MFA. “Always” leaves no room for the marketing platform that only supports it on paid tiers or the legacy portal that never got round to it. Every cloud service in scope needs it for every account, and a single exception is enough for a Cyber Essentials failure.

Partial rollout still fails

MFA enabled for the leadership team and the IT department, with a standing exemption group for people who found it inconvenient, does not satisfy the requirement. Neither does conditional access that skips the check on the office IP range for services reachable from anywhere. Assessors ask which accounts are exempt and why, and an exemption list is one of the fastest Cyber Essentials failure findings to write up.

The password inside MFA still has a floor

Where MFA protects an account, the password element must be at least 8 characters with no maximum length restriction. Turning on a second factor does not license a four-digit PIN behind it. Four additional factor types are recognised: a managed or enterprise device, an app on a trusted device, a physically separate token, and a known or trusted account.

SMS is weak but still counts

The NCSC is direct that SMS is not the most secure form of MFA while noting that any MFA is better than none. Use an authenticator app or a hardware key where you can, but do not delay certification arguing about factor quality when the alternative on a given service is no second factor at all.

Home Working, BYOD and Wireless Cyber Essentials Failure Traps

Distributed working turned a tidy office network into dozens of small ones, and the scope rules followed. This is where an otherwise well-prepared organisation finds a Cyber Essentials failure hiding in somebody’s spare room.

Routers you supplied are in scope

The default position is that all corporate and BYOD home or remote working devices used for business are in scope. If your organisation gave the home worker a router, that router is in scope too and needs the full firewall treatment: changed default administrative password, no internet-facing management interface without justification and protection, and documented inbound rules. A forgotten home router is a quiet Cyber Essentials failure that only surfaces during testing.

Everywhere else, the software firewall does the work

All other routers are out of scope, which means you must apply firewall controls on the user devices themselves. A software firewall configured and enabled on every laptop is the practical answer, and it is explicitly expected for devices used on untrusted networks such as public wifi. Where a corporate VPN is in use, the internet boundary moves to your company or cloud firewall.

BYOD exclusions are narrower than people hope

User-owned devices that access organisational data or services are in scope. The only carve-out covers mobile or remote devices used solely for native voice applications, native text applications or MFA applications. A personal iPad that opens SharePoint once a quarter is in scope; a personal phone that only receives authenticator prompts is not.

Wireless devices and the guest network

Wireless devices including access points are in scope if they can communicate with other devices via the internet, and out of scope where an attacker could only reach them from within signal range, or where they are part of an ISP router at a home location. Guest wifi that shares a subnet with staff devices is the recurring finding here.

Assets most often missed when the boundary is drawn (indicative model of 100 late scope additions)
Company-supplied home and branch routers 31%
Personal phones carrying work email 27%
Cloud apps bought outside IT 18%
Company laptops loaned to contractors 14%
Network appliances at satellite sites 10%

Firewalls, Routers and Default Credentials

The firewall theme looks like the easiest to pass and produces a steady stream of findings, because it asks for documentation rather than technology. Most organisations have the controls; fewer can evidence them, and evidence is what separates a pass from a Cyber Essentials failure on this theme.

Default administrative passwords

For every firewall or network device with firewall functionality, you must change the default administrative password to a strong and unique one, or disable remote administrative access entirely. Branch office kit, old access points and anything installed by a departed contractor are the usual offenders, and they are trivially discoverable during a Plus assessment.

Management interfaces reachable from the internet

Access to the administrative interface from the internet must be prevented unless there is a clear, documented business need and the interface is protected by multi-factor authentication or an IP allow list limited to a small range of trusted addresses with properly managed password authentication. An exposed management portal with a decent password alone does not satisfy this.

Inbound rules nobody approved

Unauthenticated inbound connections must be blocked by default, and every inbound rule must be approved and documented by an authorised person with the business need recorded. The finding here is rarely a dangerous rule — it is a reasonable rule that nobody can explain, which reads to an assessor as an unmanaged firewall.

Rules that outlived their purpose

You must remove or disable firewall rules when they are no longer needed. A port forward opened for a supplier’s remote support tool three years ago, still live, is exactly the kind of thing an external vulnerability scan surfaces. Reviewing the rule base quarterly turns this control into a formality, and it feeds directly into wider cybersecurity hygiene.

Cyber Essentials Plus: Where the Audit Catches You Out

Cyber Essentials Plus tests the same five controls, but a third party verifies them on real systems. Claims that survived a self-assessment do not always survive a scan, and this is where a paper-only Cyber Essentials failure becomes visible.

Five test cases and a single verdict

The test specification defines five test cases: a remote vulnerability assessment, a check of patching by authenticated vulnerability scan, a malware protection check, a multi-factor authentication configuration check, and an account separation check. Any single fail marks the parent test case and the overall assessment as a fail, unless a stated exception applies. That is harsher arithmetic than the self-assessment, where a Cyber Essentials failure at least buys you two working days.

The sample is not yours to choose

Testing covers a representative sample of end user devices, all internet gateways and all servers with services accessible to unauthenticated internet users, with the sample size calculated by a method the delivery partner sets. Cloud services are tested with at least one normal and one administrative user account each. The device nobody wanted tested is exactly the device that gets picked.

Malware protection is tested by email and browser

Assessors check defences against malware delivered by email and by browser download using test files, with manual checks where allow listing is used instead of anti-malware software. Filtering that works on the corporate mail flow but not on a personal webmail tab open on the same laptop tends to show up here.

There is a narrow tolerance and a three-month window

Where failures come from a small number of minor issues, the delivery partner may still allow a pass at their discretion — the guidance frames this as marginal deviation in under 5% of tests with no sign of a wider process failure. Separately, if you achieved the self-assessment certificate less than three months before certifying to Plus, you do not repeat the question set stage.

DimensionCyber EssentialsCyber Essentials Plus
Controls assessedThe same five themesThe same five themes
How it is verifiedVerified self-assessment, marked by an assessorIndependent technical audit
Vulnerability scanningNoneExternal scan plus authenticated device scan
Malware testingDeclared, not testedTested by email and browser delivery
Sign-offBoard-level declaration of truthAssessor report against every test case
Indicative costFrom £320 + VAT for a micro organisation, up to £600 + VAT for 250+ staffQuoted individually by size and complexity
Correction windowTwo working days to resubmit free of chargeAssessor discretion on minor issues only
Best suited toBaseline assurance and most supplier requirementsHigh-access suppliers and regulated contracts

How to Avoid Cyber Essentials Failure in 60 Days

Two months is enough for most small and medium organisations if the work is sequenced so the slow items start first. The plan below front-loads the discovery that determines everything else, and it is built to prevent a Cyber Essentials failure rather than to react to one.

Days 1 to 14: inventory and scope

Build one authoritative list of devices, servers, network equipment and cloud services with an owner and a vendor end-of-life date against each. Decide whether you are certifying whole organisation or a sub-set, and agree the boundary with your certification body. Download the question set and read it before you answer anything, because most Cyber Essentials failure risk is already visible at this stage.

Days 15 to 30: unsupported software and patching

Work the end-of-life column first, because replacing a platform is the only task in this plan that can take longer than the window allows. In parallel, move patching onto automatic where possible and prove that critical and high-risk updates land inside 14 days on a sample of devices, including mobiles.

Days 31 to 45: accounts, MFA and separation

Reconcile the account list against the payroll list and disable what is left over. Split administrative privileges into separate accounts with no mailbox. Enable MFA on every cloud service for every account, and remove the exemption groups. Document your joiners, movers and leavers process while you are in it.

Days 46 to 60: dry run and submit

Answer the question set honestly against the evidence you have gathered, and have somebody who did not do the remediation challenge each answer. Use the free IASME readiness tool to find gaps, fix what it surfaces, then submit. Organisations that treat this fortnight as a rehearsal rarely need the two-day correction window at all.

Typical remediation effort by finding type (indicative working days for a 40-person organisation)
Replacing unsupported software or hardware 18 days
Building a complete asset and scope register 10 days
Rolling out MFA across every cloud service 9 days
Bringing patching inside the 14-day window 7 days
Separating administrative accounts 4 days
Documenting and pruning firewall rules 2 days

What to Do After a Cyber Essentials Failure

A non-compliant result is recoverable, and handled well it costs two days rather than a second fee. Handled badly it becomes a three-month delay with a customer waiting on the certificate. The response matters more than the result.

Read the assessor feedback as a work list

Every applicant receives a report containing their answers and the assessor’s comments against anything judged non-compliant. Sort those comments into two piles: answers that were badly written, and controls that are genuinely absent. The first pile is what the two-day window is for.

Fix what is fixable inside the window

Vague answers, missing detail, undocumented firewall rules and a handful of dormant accounts can all be resolved and resubmitted at no extra charge. Do not spend the window arguing about scope or attempting a platform migration — if the finding is unsupported software or an absent MFA rollout, accept that you will reapply and use the time to fix it properly.

Know when to reapply rather than rush

Reapplying costs the assessment fee again, which for most organisations is smaller than the cost of a rushed answer that a Plus audit later contradicts. Certificates are visible to customers and insurers, and a clean pass built on real controls is worth more than a fast one that papers over the Cyber Essentials failure underneath. Where certification is a contractual condition, tell the customer early with a dated remediation plan.

Treat the root cause, not the finding

Almost every Cyber Essentials failure traces back to not knowing what you own. Fixing the specific finding gets you certified this year; fixing the asset register, the joiners and leavers process and the patch reporting gets you certified every year without the scramble, and it makes wider compliance work considerably cheaper.

Frequently Asked Questions About Cyber Essentials Failure

What is the most common cause of Cyber Essentials failure?

Unsupported software inside the assessment scope, closely followed by security updates applied outside the 14-day window. IASME names unsupported software as an automatic fail, so a single end-of-life operating system, application or piece of network firmware ends the assessment regardless of how strong everything else is.

Do I have to pay again if I fail?

Not immediately. You get two working days to review the assessor’s feedback, correct simple issues and resubmit at no extra charge. If the resubmission still fails, you reapply and pay the assessment fee again, which starts from £320 plus VAT for a micro organisation and rises with headcount.

Can I leave a problem system out of scope?

Only if it sits in a genuinely segregated sub-set with the boundary defined and agreed with your certification body, and you can justify the partial scope. Cloud services holding your data cannot be excluded at all under version 3.3, and a scope that omits end user devices is not acceptable.

How long does certification actually take?

You have six months to complete an assessment once you have paid, but with prepared answers the self-assessment itself can take about an hour. Assessors aim to return results within three days. The real timeline is the remediation work beforehand, which is why the 60-day plan above starts with discovery.

Is Cyber Essentials Plus harder to pass?

The controls are identical; the assurance level is not. Plus adds an external vulnerability scan, an authenticated scan of sampled devices, live malware tests and checks on MFA and account separation. Anything you overstated in the self-assessment surfaces there, so an honest first submission is the best insurance against a Cyber Essentials failure at the audit stage.

Does certification expire?

Yes. Certificates run for twelve months and reflect the estate as assessed on the day, which is why buyers increasingly write renewal obligations into contracts rather than accepting a one-off certificate at tender. If you are on the buying side, our ISO 27001 certification cost guide explains when to ask for something heavier instead.

References and Further Reading