How to Pass the Cyber Essentials Questionnaire: A 2026 UK SME Guide
Back to Blog
Cyber Security6 min read

How to Pass the Cyber Essentials Questionnaire: A 2026 UK SME Guide

Coreitech Team
16 September 2026
#how to pass cyber essentials#cyber essentials questionnaire guide#cyber essentials self-assessment tips#cyber essentials requirements 2026#UK SME cyber security certification#cyber essentials assessment help#passing cyber essentials first time
Quick Answer

Struggling with the Cyber Essentials questionnaire? Follow our 2026 guide to understand the technical controls and pass your UK SME certification first time.

What Is the Cyber Essentials Questionnaire — and Why Does It Matter in 2026?

Cyber Essentials is the UK government-backed certification scheme designed to help businesses defend against the most common cyber threats. For SMEs in particular, achieving certification sends a clear signal to clients, partners, and insurers that your organisation takes security seriously.

Beyond reputation, certification is increasingly a commercial necessity. Many public sector contracts now require it as standard, and a growing number of enterprise clients are asking suppliers to demonstrate compliance before onboarding. If passing Cyber Essentials is on your agenda for 2026, understanding exactly what the questionnaire demands — before you sit down to complete it — will save you considerable time, money, and frustration.


Understanding the Five Control Areas

The Cyber Essentials self-assessment questionnaire is structured around five technical control themes. Every question maps back to one of these areas, so knowing them inside out is your starting point.

— Need Expert IT Help?

Get a Free IT Consultation

Our London-based IT experts are ready to help your business. Free 30-minute consultation, no obligation.

Free 30-min consultation No obligation London-based team

1. Firewalls and Boundary Devices

Your internet-facing devices must be protected by a properly configured firewall. Default passwords must be changed, unnecessary services disabled, and rules documented. This applies to cloud-based firewalls too — the 2024 scheme update made clear that software firewalls on individual devices count, provided they are enabled and centrally managed.

2. Secure Configuration

All devices in scope — laptops, desktops, servers, mobile phones, tablets — must have unnecessary software removed, default accounts disabled, and auto-run features switched off. Assessors are looking for evidence that you've actively hardened your devices, not simply accepted factory settings.

3. User Access Control

Only authorised users should have access to your systems, and only to the data they need. Administrator accounts must be used exclusively for admin tasks — not for browsing the web or reading email. Multi-factor authentication (MFA) is now mandatory for cloud services and remote access under the updated 2026 requirements.

4. Malware Protection

Every device in scope must have active malware protection — either a reputable anti-malware product or, where applicable, application allow-listing. Ensure your solution is set to update automatically and that real-time scanning is enabled.

5. Patch Management

All software on in-scope devices — operating systems, applications, firmware — must be kept up to date. High and critical patches must be applied within 14 days of release. Unsupported software (anything no longer receiving security updates) is an automatic fail, so if you're still running Windows 10 on any devices past its October 2025 end-of-life date, you'll need to address this before applying.


Cyber Essentials Requirements 2026: What's Changed

The NCSC and IASME regularly refine the scheme. For 2026 assessments, the areas receiving greatest scrutiny include:

  • Cloud services: Any cloud platform — Microsoft 365, Google Workspace, hosted CRM tools — is now firmly in scope if your staff use it to handle business data. You must demonstrate MFA is enforced and that administrative access is appropriately restricted.
  • Home and remote working: Devices used to access company data from home are in scope. If staff use personal devices (BYOD), you need a clear, enforced policy — and in many cases, it's simpler to bring those devices under company management.
  • Thin clients and virtual desktops: These are now treated the same as physical devices for scoping purposes.

If you're unsure whether a particular system or device falls within your scope, err on the side of inclusion. Assessors will ask, and discovering a gap after submission is both costly and time-consuming.


Practical Cyber Essentials Self-Assessment Tips

Here's where many SMEs come unstuck — not because their security is poor, but because they haven't prepared their evidence or understood the wording of specific questions.

Read the question carefully. The questionnaire uses precise language. "All" means all — not most, not the majority. If a single unpatched device exists within scope, that's a fail.

Audit your asset inventory first. You cannot answer questions about your devices accurately if you don't have a current, complete list. Before touching the questionnaire, document every in-scope device: make, model, OS version, and patch status.

Check your software versions. Open your devices and manually verify that operating systems and key applications are on supported, up-to-date versions. Don't assume — confirm.

Review your admin accounts. Run a check on who holds administrator privileges across your systems. It's common to find long-forgotten admin accounts, ex-employees still in the directory, or staff using admin accounts for everyday tasks. Clean this up before you submit.

Test MFA across all cloud services. Log in to every cloud platform your business uses and verify that MFA is active — not just enabled in settings, but actually enforced for all users. Conditional access policies in Microsoft 365, for example, need to be correctly configured, not merely switched on.

At Coreitech, we recommend that SMEs complete an internal technical audit at least two to three weeks before submitting their questionnaire. This gives time to identify and remediate any gaps without rushing — a common cause of first-time failures.


Common Reasons SMEs Fail the First Time

  • Running end-of-life operating systems (Windows 10 without Extended Security Updates, older macOS versions)
  • MFA not enforced on all cloud service user accounts
  • Default credentials still present on network devices or routers
  • Incomplete asset inventory leading to unscoped devices being overlooked
  • Anti-malware not configured for automatic updates
  • Administrator accounts used for routine tasks

Each of these is entirely avoidable with proper preparation.


Should You Go for Cyber Essentials or Cyber Essentials Plus?

The standard Cyber Essentials involves a verified self-assessment — you answer the questions and a certifying body reviews your responses. Cyber Essentials Plus includes an independent technical audit of your systems, carried out by an accredited assessor.

For most SMEs pursuing certification for the first time, standard Cyber Essentials is the appropriate starting point. If you work in the public sector, defence supply chain, or handle sensitive personal data at scale, Cyber Essentials Plus provides stronger assurance — and may be contractually required.


Get Expert Help Before You Submit

The Cyber Essentials questionnaire is not designed to catch businesses out — it's designed to improve baseline security. But answering it accurately requires a solid understanding of your own IT environment, and many SMEs simply don't have the internal resource to conduct a thorough audit unaided.

If you want to pass Cyber Essentials first time and avoid the cost of resubmission, speaking to an experienced IT support partner before you begin is the most practical step you can take.

Coreitech works with SMEs across London and the UK to prepare for Cyber Essentials certification — from initial scoping and gap analysis through to remediation support and questionnaire review. We know what assessors look for, and we help businesses get there without unnecessary complexity.

To find out how we can support your certification, call us on 0203 834 9728 or email sales@coreitech.co.uk. We're happy to have a straightforward conversation about where your business stands and what it would take to get certified.

— Cyber Security Services

Is your business protected against cyber threats?

Coreitech delivers enterprise-grade cyber security for UK SMEs — NextGen EDR, email security, dark web monitoring, SOC, and Cyber Essentials certification. Free security assessment.

4.9★ rated — 112+ reviews15-min critical SLAFrom £25/user/month
— Coreitech

Need IT support for your business?

Coreitech is a London-based managed IT support company helping UK SMEs with cyber security, Microsoft 365, cloud infrastructure, and expert helpdesk support. Based at London Bridge, SE1 — serving businesses across London and the UK.

Free IT audit with no obligation. Typically takes 30–45 minutes.