TL;DR: A Cyber Essentials certificate means nothing if the controls behind it aren’t real.
Cyber Essentials has become the price of entry for doing business in the UK — no certificate, no contract. That pressure has created a market for quick, cheap certification, and we’re seeing the results of it. When we audit a new client who already holds Cyber Essentials, we frequently find an environment that would not survive ten minutes of proper scrutiny.
Cyber Essentials is a verified self-assessment. Someone answers the question set, a director signs a declaration, and an assessor marks the responses. If the answers don’t reflect reality, the certificate still gets issued — the paperwork was correct even though the infrastructure wasn’t.
That gap is where the risk lives. We’ve picked up clients with MFA missing on cloud services, patching running weeks behind, unsupported operating systems still in production, and local admin rights handed out across the business — all sitting behind a certificate that says otherwise.
Almost always, it comes down to who filled in the assessment. Cyber Essentials looks deceptively simple — five technical controls, a set of questions — so it often gets handed to a general IT provider or an internal person who has never worked through a real scope with an assessor.
They answer what they believe to be true rather than what they’ve verified. Nobody checks whether every device in scope is actually patched. Nobody confirms MFA is enforced on every cloud service rather than just Microsoft 365. Nobody questions whether the scope excludes half the estate. The certificate arrives, everyone moves on, and the organisation carries a false sense of security for the next 12 months.
This is the part that gets underestimated. After an incident, the certificate becomes evidence. Insurers, regulators, and — increasingly — your customers’ legal teams will want to know what you declared and whether it was accurate.
If your organisation certified against controls it never actually had in place, you’re no longer dealing with a straightforward breach. You’re dealing with a breach plus a signed declaration that doesn’t match reality. Cyber insurance policies routinely require you to maintain the controls you claimed. A rejected claim on top of an incident is a very expensive combination.
Most businesses pursue Cyber Essentials because a customer or supply chain partner demands it. That certificate is the assurance those organisations are relying on when they connect systems, share data, or grant you access to their environment.
If you’re breached and the attacker moves laterally into a client’s network, the fallout doesn’t stop at your front door. Contracts get terminated, relationships end, and under UK GDPR the ICO can issue fines of up to £17.5 million or 4% of global annual turnover for serious failures to protect personal data. The reputational damage of being the weak link in someone else’s supply chain tends to outlast the financial hit.
The scheme itself has tightened considerably — largely because IASME and the NCSC identified exactly this problem through their own audits. From 27 April 2026, assessments run against Requirements for IT Infrastructure v3.3 and the new Danzell question set, and the marking is far less forgiving.
“Non-compliance with either of these questions will result in an automatic failure of the assessment, regardless of performance in other areas.” — IASME, Changes to Cyber Essentials for April 2026
MFA is now mandatory on every cloud service that offers it — free, bundled, or paid — and missing it is an automatic fail. High-risk and critical updates must be installed within 14 days across the full scope, and failing that is an automatic fail too. Cloud services have a formal definition and can no longer be excluded from scope.
IASME also closed a loophole where organisations patched only the sample devices tested during a Cyber Essentials Plus audit. Retests now include a fresh random sample, and a second failure revokes the self-assessment certificate outright. The director’s declaration has been updated to explicitly acknowledge responsibility for maintaining compliance throughout the certification period — not just on the day.
Proper certification starts with a gap assessment, not a questionnaire. You establish the true scope, audit every device and cloud service against the five controls, remediate what’s failing, and only then complete the assessment — with evidence behind every answer.
Then you need protocols to hold it. Patching within 14 days doesn’t happen by accident; it needs monitored, enforced update management. MFA coverage needs reviewing every time a new cloud service is adopted. Joiners and leavers need a documented process so access control doesn’t drift. Our fully managed Cyber Essentials certification service covers the full cycle — gap assessment through to submission and sign-off — and our managed cyber security service keeps the controls in place between renewals.
We’re offering new clients a free surface-level audit of their Cyber Essentials setup. No obligation, no commitment — we take a look at how your environment is configured against what the scheme actually requires, and tell you plainly whether there are gaps worth worrying about.
It doesn’t take long to spot the obvious problems. Missing MFA, patching gaps, unsupported systems, and scoping errors show up quickly, and knowing about them now is considerably cheaper than discovering them during an incident. Sylvester, our security specialist, is happy to run through it with you.
If you hold Cyber Essentials and you’ve never independently verified that your setup matches what was declared, that’s worth an hour of someone’s time. Request your free Cyber Essentials audit or call us on 020 7471 3270 — no strings attached.