Certification
Five reasons Cyber Essentials applications fail, and how to pass first time
Most Cyber Essentials failures come from the same five gaps: unsupported software, late patches, missing multi-factor authentication, an incomplete scope and admin rights used for everyday work. What each one means, how to find it before the assessor does, and how to write answers that pass.
Cyber Essentials is the UK government-backed baseline for cyber security, and for many organisations it is now a condition of winning or keeping contracts. The questions are not difficult, but applications still fail, and nearly always for the same handful of reasons.
Here are the five that come up most often, how to find each one before you submit, and the non-technical reason that catches people out. For the requirements themselves, see our Cyber Essentials service.
1. Unsupported software is still in scope
Every operating system, application and piece of firmware in scope must be licensed and still receiving security updates from its vendor. One old laptop, an out-of-date PDF reader or a server on an end-of-life operating system is enough to fail.
Windows 10 reached end of support in October 2025, so this is now the most common example. Devices still running it need to be upgraded, replaced or removed from scope, unless they are still receiving security updates through a paid extended support programme, which you should confirm with your certification body before relying on it.
Find it first: build a device and software inventory, check each item against its vendor's support dates, and retire or isolate anything that no longer gets updates.
2. Security updates are applied too slowly
Critical and high-risk security updates must be installed within 14 days of release. Operating systems often update automatically, but the gaps tend to be elsewhere: browsers and browser plug-ins, video-calling and PDF tools, laptops that rarely connect to the network, and the firmware on firewalls and routers.
Find it first: turn on automatic updates wherever possible, then check the stragglers. A device that has been in a drawer for a month is a common failure.
3. Multi-factor authentication isn't on everywhere
Multi-factor authentication (MFA) is required on every cloud service that offers it, for every user, not just the main email platform or the administrators. The usual failure is a second system nobody thought about: the accounting package, the HR platform, a file-sharing tool or an old admin account.
Passkeys and security keys now count as MFA, which can make full coverage easier.
Find it first: list every cloud service the organisation uses, including the ones bought on a credit card by a single team, and check MFA is enforced for every account on each.
4. The scope leaves things out
Scope is where applications most often go wrong without anyone noticing until the assessor asks. Under the current requirements:
- Cloud services that hold your organisation's data cannot be excluded.
- Home workers' devices are in scope if they access organisational data, and need their own firewall turned on, because the home router is not yours to control.
- Personal devices used for work email or files are in scope too.
A scope that quietly leaves these out may be rejected, and one that is accepted but inaccurate leaves you holding a certificate that does not describe how you actually work.
Find it first: start from where your data lives and who can reach it, not from the office network.
5. Everyday accounts have admin rights, and defaults are left in place
Staff should use standard accounts for day-to-day work, with separate administrator accounts used only for admin tasks. Applications fail when everyone is a local administrator "to save time", when default passwords on routers, printers or new devices were never changed, or when unused accounts and software have not been removed.
Find it first: review who has admin rights and why, change every default password, and remove accounts for people who have left.
The non-technical reason: answers that don't say how
The assessor can only approve what you write. Answers fail when they are vague ("yes, we do this"), contradict each other (MFA "on everything" in one answer, but a service without it in another), or describe what the policy says rather than what actually happens.
Good answers say how: which tool enforces updates, how MFA is applied, what happens when someone leaves. A board-level or equivalent senior person must then approve the answers and declare them accurate, so they should be able to stand behind every one.
Before you submit
- Every device and application in scope is supported and receiving updates.
- Critical and high-risk updates are applied within 14 days, including firmware.
- MFA is enforced for every user on every cloud service that offers it.
- The scope includes cloud services, home workers' devices and personal devices used for work.
- Everyday accounts are not administrators, and default passwords are changed.
- Each answer says how the control is met, and the answers agree with each other.
Where Threat Protect fits
The quickest first step is our free Cyber Essentials checker, which walks through the controls and shows where you stand. If you want help, our Cyber Essentials service scopes the assessment, closes the gaps before you submit and keeps the controls current through the year, so renewal is routine. Certification itself is delivered through certified assessment partners.
If a client contract needs certification quickly, read Cyber Essentials for supply chain contracts, or book a call and we will tell you what stands between you and the certificate. If you are already thinking about the next step, see what the Cyber Essentials Plus audit checks.
Further reading
- Cyber Essentials overview, NCSC
- Cyber Essentials scheme, IASME
Frequently asked
Questions readers ask before getting in touch.
- Unsupported software and missing security updates between them account for a large share of failures. Any operating system or application in scope that no longer receives security updates fails the requirement, and critical or high-risk updates must be applied within 14 days of release. An accurate device and software inventory is the quickest way to find both.
- Yes, if they access organisational data or services. That includes personal devices used for work email or files. Home routers are not in scope because they are not yours to control, so each home worker's device needs its own firewall turned on instead.
- No. Under the current requirements, cloud services that hold your organisation's data cannot be excluded from the assessment. Each one needs to meet the controls, including multi-factor authentication for every user where the service offers it.
- A board-level or equivalent senior person must approve the answers and declare that they are accurate. That is a real responsibility: the certificate is only as good as the answers behind it, and clients and contracts rely on it.
- It is the right baseline for many smaller organisations and a common requirement in supply chain contracts. Organisations with larger estates, regulated clients or more demanding contracts often go on to Cyber Essentials Plus, which adds an independent technical test, or to ISO 27001.
Talk to us
Want to talk through how this applies to your company?
A 30-minute call with a senior advisor. No pitch. We will read your situation against what is in this piece and tell you the smallest sensible next step.