Skip to main content
    NixInfinity-AI
    2026 Updates

    Cyber Essentials Auto-Fail Criteria: What Now Fails Immediately

    Published 14 July 2026

    What "auto-fail" actually means

    IASME assessors are instructed to stop marking a submission as soon as a hard-fail answer is recorded. You do not get a partial result – you get a fail and a 30-day window to resubmit. The fee is not refunded. Auto-fail items are the answers that trigger this rule.

    The auto-fail triggers under Danzell

    1. MFA missing on a cloud account in scope

    MFA is now mandatory on every cloud user account, not just admins. A single answer of "no" or "where available" against a known cloud service is a hard fail. See our MFA requirements guide.

    2. Unsupported software still in use

    Windows 10 (post-Oct 2025), unsupported macOS versions, unsupported iOS/Android, end-of-life server OS or browsers that no longer receive security updates trigger an immediate fail. See our secure configuration guide.

    3. High/critical CVEs unpatched beyond 14 days

    The 14-day rule for CVSS v3 7.0+ vulnerabilities is rigid. If you cannot evidence patching within 14 days of vendor release, the answer is no. See the 14-day patching guide.

    4. Default admin passwords still in place

    Routers, switches, firewalls or applications still using vendor-default credentials – even on a single device – are a hard fail.

    5. Cloud admin without MFA

    The "every admin account, every time" rule is non-negotiable. A break-glass account with MFA waived must be documented, isolated and monitored to avoid the fail.

    6. Account separation missing

    Day-to-day work performed from a domain or tenant admin account is an immediate fail. Standard users for daily work, separate admin accounts for elevation only.

    7. Out-of-scope answers that contradict your scope statement

    If you declare a sub-set scope but then describe controls that prove the rest of the business is in the same environment, assessors will reject the scope and the submission.

    Pre-submission self-check

    • List every cloud service – is MFA on for every user, not just admins?
    • List every device OS and version – any past end-of-life?
    • Pull a patch report – any high/critical CVE older than 14 days?
    • List every admin account – does anyone use it for daily work?
    • Walk every firewall, router and switch – any vendor defaults?

    Director responsibilities

    The signatory directors are liable for accuracy of every answer. A false declaration that surfaces during a CE Plus audit or insurance claim can void the certificate and the free £25,000 cyber insurance. Get the pre-submission read-through into your governance routine.

    If you have already failed

    See what happens if you fail Cyber Essentials. You have 30 days to remediate and resubmit under the same fee. Use the time to fix the root cause, not just the answer.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions