Have you changed all default administrative passwords on your routers and firewalls?
Default passwords are published online and widely exploited. If you do not have an external firewall and rely on built-in laptop firewalls, you can answer yes.Check your Cyber Essentials readiness
What the Cyber Essentials self-assessment is
Cyber Essentials is a UK government-backed certification scheme. It is run by the IASME Consortium, the organisation the National Cyber Security Centre appoints to deliver it, and administered by certification bodies such as Forensic Control. The basic level is a self-assessment: you complete a questionnaire about your security controls and an assessor reviews it. Cyber Essentials Plus is the same five controls, verified by a hands-on technical audit rather than self-declared.
One term worth knowing early is scope: the set of devices and services your certificate covers. Part of getting ready is being clear about what is in it, because some things, cloud services in particular, can no longer be left out.
The questionnaire changed on 27 April 2026. The previous question set, called Willow, was replaced by a new set called Danzell, which reflects the tightened requirements in version 3.3 of the scheme. Anyone applying now completes the Danzell set. The five controls keep their names, but several of the things they require have changed.
What it costs and how long it takes
From £450 + VAT
a year for Cyber Essentials, renewed annually. Cyber Essentials Plus starts from £1,350.
1 to 3 working days
typical time to certify once your answers meet the standard.
No charge to resubmit
if something needs fixing, you correct it and resubmit at no extra cost.
Where the gaps usually are
The self-assessment covers five technical controls. Here is what each one checks, and the gap we see most often when we assess against it.
Firewalls
You confirm that default administrative passwords on routers and firewalls have been changed, and that firewall rules have been reviewed and documented within the last year.
Common gap: The usual miss is the review: rules get added over time and rarely removed.
Secure configuration
You confirm that unused accounts, software and services have been removed, and that every device locks automatically behind a PIN, password or biometric.
Common gap: Dormant accounts left behind by former staff and pre-installed software nobody uses are the common gaps.
Security update management
Operating system, firmware and application updates that fix serious vulnerabilities must be applied within fourteen days.
Common gap: Third-party applications, browsers, messaging clients and VPN clients are where most organisations slip.
User access control
Administrator accounts must be used only when needed, every account must have unique credentials, and multi-factor authentication must be enabled on all cloud services.
Common gap: MFA not being rolled out to everyone is the v3.3 blocker most likely to fail an assessment.
Malware protection
Every device must run up-to-date anti-malware software or enforced application allow-listing, and jailbroken or rooted mobile devices must be kept away from business data.
Common gap: Mobile devices are often left out, or antivirus is assumed to be active when it is not enforced or updating.
The three v3.3 changes most likely to affect you
MFA is now an automatic fail
If a cloud service offers multi-factor authentication and you have not enabled it for every user, the assessment fails automatically. There is no remediation within that assessment cycle.
Patching covers more than patches
The fourteen-day deadline now applies to any vendor-recommended fix for a serious vulnerability, including configuration changes and scripts, not only downloadable updates.
Cloud services cannot be excluded
Any cloud tool that stores or processes your business data is in scope, regardless of who manages it.
For a fuller breakdown, see our guide to what the April 2026 Cyber Essentials update means.
