BOOK A CALL BACK
Have a question? Fill in the form below to book a call
About:
Full Name*
Business Email*
Contact Number*
Booking Date*
Menu
REMOTE SUPPORT
 NETWORK STATUS
020 7471 3277
Book a call
ALL BLOGS

Free Cyber Essentials audit: is your certificate hiding a compliance gap?

TL;DR: A Cyber Essentials certificate means nothing if the controls behind it aren’t real.

  • We regularly audit new clients who hold valid Cyber Essentials certificates but whose environments fall well short of the actual requirements.
  • Certification is a point-in-time assessment — the director who signs the declaration is confirming ongoing compliance, not a one-off snapshot.
  • A breach at a non-compliant certified business can cascade to every supplier and customer relying on that certificate, with contractual and regulatory consequences.
  • We’re offering new clients a free, no-obligation surface audit of their Cyber Essentials setup.

Cyber Essentials has become the price of entry for doing business in the UK — no certificate, no contract. That pressure has created a market for quick, cheap certification, and we’re seeing the results of it. When we audit a new client who already holds Cyber Essentials, we frequently find an environment that would not survive ten minutes of proper scrutiny.

Why does a valid certificate not mean you’re compliant?

Cyber Essentials is a verified self-assessment. Someone answers the question set, a director signs a declaration, and an assessor marks the responses. If the answers don’t reflect reality, the certificate still gets issued — the paperwork was correct even though the infrastructure wasn’t.

That gap is where the risk lives. We’ve picked up clients with MFA missing on cloud services, patching running weeks behind, unsupported operating systems still in production, and local admin rights handed out across the business — all sitting behind a certificate that says otherwise.

Where does it usually go wrong?

Almost always, it comes down to who filled in the assessment. Cyber Essentials looks deceptively simple — five technical controls, a set of questions — so it often gets handed to a general IT provider or an internal person who has never worked through a real scope with an assessor.

They answer what they believe to be true rather than what they’ve verified. Nobody checks whether every device in scope is actually patched. Nobody confirms MFA is enforced on every cloud service rather than just Microsoft 365. Nobody questions whether the scope excludes half the estate. The certificate arrives, everyone moves on, and the organisation carries a false sense of security for the next 12 months.

What happens if you’re breached while technically non-compliant?

This is the part that gets underestimated. After an incident, the certificate becomes evidence. Insurers, regulators, and — increasingly — your customers’ legal teams will want to know what you declared and whether it was accurate.

If your organisation certified against controls it never actually had in place, you’re no longer dealing with a straightforward breach. You’re dealing with a breach plus a signed declaration that doesn’t match reality. Cyber insurance policies routinely require you to maintain the controls you claimed. A rejected claim on top of an incident is a very expensive combination.

Your suppliers and customers are exposed too

Most businesses pursue Cyber Essentials because a customer or supply chain partner demands it. That certificate is the assurance those organisations are relying on when they connect systems, share data, or grant you access to their environment.

If you’re breached and the attacker moves laterally into a client’s network, the fallout doesn’t stop at your front door. Contracts get terminated, relationships end, and under UK GDPR the ICO can issue fines of up to £17.5 million or 4% of global annual turnover for serious failures to protect personal data. The reputational damage of being the weak link in someone else’s supply chain tends to outlast the financial hit.

What changed with Cyber Essentials in April 2026?

The scheme itself has tightened considerably — largely because IASME and the NCSC identified exactly this problem through their own audits. From 27 April 2026, assessments run against Requirements for IT Infrastructure v3.3 and the new Danzell question set, and the marking is far less forgiving.

“Non-compliance with either of these questions will result in an automatic failure of the assessment, regardless of performance in other areas.” — IASME, Changes to Cyber Essentials for April 2026

MFA is now mandatory on every cloud service that offers it — free, bundled, or paid — and missing it is an automatic fail. High-risk and critical updates must be installed within 14 days across the full scope, and failing that is an automatic fail too. Cloud services have a formal definition and can no longer be excluded from scope.

IASME also closed a loophole where organisations patched only the sample devices tested during a Cyber Essentials Plus audit. Retests now include a fresh random sample, and a second failure revokes the self-assessment certificate outright. The director’s declaration has been updated to explicitly acknowledge responsibility for maintaining compliance throughout the certification period — not just on the day.

What does doing it properly actually look like?

Proper certification starts with a gap assessment, not a questionnaire. You establish the true scope, audit every device and cloud service against the five controls, remediate what’s failing, and only then complete the assessment — with evidence behind every answer.

Then you need protocols to hold it. Patching within 14 days doesn’t happen by accident; it needs monitored, enforced update management. MFA coverage needs reviewing every time a new cloud service is adopted. Joiners and leavers need a documented process so access control doesn’t drift. Our fully managed Cyber Essentials certification service covers the full cycle — gap assessment through to submission and sign-off — and our managed cyber security service keeps the controls in place between renewals.

Not sure your certification would hold up?

We’re offering new clients a free surface-level audit of their Cyber Essentials setup. No obligation, no commitment — we take a look at how your environment is configured against what the scheme actually requires, and tell you plainly whether there are gaps worth worrying about.

It doesn’t take long to spot the obvious problems. Missing MFA, patching gaps, unsupported systems, and scoping errors show up quickly, and knowing about them now is considerably cheaper than discovering them during an incident. Sylvester, our security specialist, is happy to run through it with you.

If you hold Cyber Essentials and you’ve never independently verified that your setup matches what was declared, that’s worth an hour of someone’s time. Request your free Cyber Essentials audit or call us on 020 7471 3270 — no strings attached.

Need IT Support? Speak to me, Sylvester
Book a call
Click to dial me
Moving to Knowall is simple Moving over to us is quick, simple and hands-free.