What Is the Cyber Essentials Questionnaire — and Why Does It Matter in 2026?
Cyber Essentials is the UK government-backed certification scheme designed to help businesses defend against the most common cyber threats. For SMEs in particular, achieving certification sends a clear signal to clients, partners, and insurers that your organisation takes security seriously.
Beyond reputation, certification is increasingly a commercial necessity. Many public sector contracts now require it as standard, and a growing number of enterprise clients are asking suppliers to demonstrate compliance before onboarding. If passing Cyber Essentials is on your agenda for 2026, understanding exactly what the questionnaire demands — before you sit down to complete it — will save you considerable time, money, and frustration.
Understanding the Five Control Areas
The Cyber Essentials self-assessment questionnaire is structured around five technical control themes. Every question maps back to one of these areas, so knowing them inside out is your starting point.
Get a Free IT Consultation
Our London-based IT experts are ready to help your business. Free 30-minute consultation, no obligation.
1. Firewalls and Boundary Devices
Your internet-facing devices must be protected by a properly configured firewall. Default passwords must be changed, unnecessary services disabled, and rules documented. This applies to cloud-based firewalls too — the 2024 scheme update made clear that software firewalls on individual devices count, provided they are enabled and centrally managed.
2. Secure Configuration
All devices in scope — laptops, desktops, servers, mobile phones, tablets — must have unnecessary software removed, default accounts disabled, and auto-run features switched off. Assessors are looking for evidence that you've actively hardened your devices, not simply accepted factory settings.
3. User Access Control
Only authorised users should have access to your systems, and only to the data they need. Administrator accounts must be used exclusively for admin tasks — not for browsing the web or reading email. Multi-factor authentication (MFA) is now mandatory for cloud services and remote access under the updated 2026 requirements.
4. Malware Protection
Every device in scope must have active malware protection — either a reputable anti-malware product or, where applicable, application allow-listing. Ensure your solution is set to update automatically and that real-time scanning is enabled.
5. Patch Management
All software on in-scope devices — operating systems, applications, firmware — must be kept up to date. High and critical patches must be applied within 14 days of release. Unsupported software (anything no longer receiving security updates) is an automatic fail, so if you're still running Windows 10 on any devices past its October 2025 end-of-life date, you'll need to address this before applying.
Cyber Essentials Requirements 2026: What's Changed
The NCSC and IASME regularly refine the scheme. For 2026 assessments, the areas receiving greatest scrutiny include:
- Cloud services: Any cloud platform — Microsoft 365, Google Workspace, hosted CRM tools — is now firmly in scope if your staff use it to handle business data. You must demonstrate MFA is enforced and that administrative access is appropriately restricted.
- Home and remote working: Devices used to access company data from home are in scope. If staff use personal devices (BYOD), you need a clear, enforced policy — and in many cases, it's simpler to bring those devices under company management.
- Thin clients and virtual desktops: These are now treated the same as physical devices for scoping purposes.
If you're unsure whether a particular system or device falls within your scope, err on the side of inclusion. Assessors will ask, and discovering a gap after submission is both costly and time-consuming.
Practical Cyber Essentials Self-Assessment Tips
Here's where many SMEs come unstuck — not because their security is poor, but because they haven't prepared their evidence or understood the wording of specific questions.
Read the question carefully. The questionnaire uses precise language. "All" means all — not most, not the majority. If a single unpatched device exists within scope, that's a fail.
Audit your asset inventory first. You cannot answer questions about your devices accurately if you don't have a current, complete list. Before touching the questionnaire, document every in-scope device: make, model, OS version, and patch status.
Check your software versions. Open your devices and manually verify that operating systems and key applications are on supported, up-to-date versions. Don't assume — confirm.
Review your admin accounts. Run a check on who holds administrator privileges across your systems. It's common to find long-forgotten admin accounts, ex-employees still in the directory, or staff using admin accounts for everyday tasks. Clean this up before you submit.
Test MFA across all cloud services. Log in to every cloud platform your business uses and verify that MFA is active — not just enabled in settings, but actually enforced for all users. Conditional access policies in Microsoft 365, for example, need to be correctly configured, not merely switched on.
At Coreitech, we recommend that SMEs complete an internal technical audit at least two to three weeks before submitting their questionnaire. This gives time to identify and remediate any gaps without rushing — a common cause of first-time failures.
Common Reasons SMEs Fail the First Time
- Running end-of-life operating systems (Windows 10 without Extended Security Updates, older macOS versions)
- MFA not enforced on all cloud service user accounts
- Default credentials still present on network devices or routers
- Incomplete asset inventory leading to unscoped devices being overlooked
- Anti-malware not configured for automatic updates
- Administrator accounts used for routine tasks
Each of these is entirely avoidable with proper preparation.
Should You Go for Cyber Essentials or Cyber Essentials Plus?
The standard Cyber Essentials involves a verified self-assessment — you answer the questions and a certifying body reviews your responses. Cyber Essentials Plus includes an independent technical audit of your systems, carried out by an accredited assessor.
For most SMEs pursuing certification for the first time, standard Cyber Essentials is the appropriate starting point. If you work in the public sector, defence supply chain, or handle sensitive personal data at scale, Cyber Essentials Plus provides stronger assurance — and may be contractually required.
Get Expert Help Before You Submit
The Cyber Essentials questionnaire is not designed to catch businesses out — it's designed to improve baseline security. But answering it accurately requires a solid understanding of your own IT environment, and many SMEs simply don't have the internal resource to conduct a thorough audit unaided.
If you want to pass Cyber Essentials first time and avoid the cost of resubmission, speaking to an experienced IT support partner before you begin is the most practical step you can take.
Coreitech works with SMEs across London and the UK to prepare for Cyber Essentials certification — from initial scoping and gap analysis through to remediation support and questionnaire review. We know what assessors look for, and we help businesses get there without unnecessary complexity.
To find out how we can support your certification, call us on 0203 834 9728 or email sales@coreitech.co.uk. We're happy to have a straightforward conversation about where your business stands and what it would take to get certified.
