Cyber Essentials Common Failures and How to Fix Them
Published 1 June 2026
Why this list is short
We review submissions every week. The fails cluster. It's almost never an exotic technical issue – it's the same handful of practical gaps that would be obvious if someone outside the team looked. Below are the ones that come up over and over, with the fix for each.
1. One device past end-of-support
Usually it's a Windows 10 machine without the Extended Security Update licence, or an old iPad on a major version Apple no longer patches. One device is enough to fail the whole submission.
Fix: run an inventory pass before you submit. Anything past vendor support either gets upgraded, replaced, or formally removed from scope (network-segmented, not just "we don't really use it").
2. MFA missing on one cloud account
The classic gap is the founder's "convenience" admin in Microsoft 365, or a third-party SaaS that nobody remembered – Xero, Mailchimp, a CRM. Under the current Danzell question set, MFA must be on every cloud user account, not just admins.
Fix: list every cloud service the business uses (it'll be more than you think), open each one, and check MFA enforcement. See our MFA requirements guide for the exact wording.
3. Asset list is out of date
A spreadsheet from last quarter doesn't pass. Assessors look for evidence that you have a method – something that catches a new starter's laptop or a replaced phone within days, not months.
Fix: reconcile your asset list against M365/Google Workspace device sign-ins, MDM (Intune, Jamf, Kandji) and HR's leavers list. Keep it in one place and date-stamp it.
4. Patching is slower than 14 days
High and critical vendor patches must be applied within 14 days. Plenty of organisations technically have auto-update on, but can't show the actual patch state of every in-scope device when asked.
Fix: use whatever you've got – Intune compliance reports, Jamf inventory, even a quick screen-share – to evidence the current state across a sample of devices. If you can't show it, fix the visibility, not just the policy.
5. Inconsistent answers across the question set
You say BYOD isn't allowed in section 2, then mention personal phones for email in section 5. You list 10 staff in one place, 14 in another. Assessors flag contradictions immediately.
Fix: have one person own the submission and read it back end-to-end before you click submit. If two people answer different sections, get them in a room for an hour.
The lower-frequency ones still worth checking
- Default admin password still set on a router or firewall.
- Old leaver accounts active in M365 or a SaaS app.
- Software firewall disabled on a "build" laptop or a developer's machine.
- No anti-malware on a Mac (yes, it still needs to be there or another approved approach in place).
- Browser extensions that bypass corporate controls.
The pre-check is the cheapest insurance
A pre-submission review by an assessor surfaces the points above before they become a fail. We include one on every Cyber Essentials engagement. For the broader playbook see How to Pass Cyber Essentials First Time and the readiness checklist.
