How to Pass Cyber Essentials First Time
Published 18 May 2026
Why first-time pass matters
A first-time pass means you keep your tender deadline, avoid resubmission stress, and protect the £25,000 cyber insurance benefit from day one. A failed submission is not the end of the world – you get one free resubmission within 48 hours – but it costs time and shakes confidence with whoever is waiting on your certificate.
The eight pre-submission checks
1. MFA on every cloud account (admin and user)
Under the Danzell question set, in force since 27 April 2026, MFA must be enabled on all cloud user accounts – not just admins. Audit every cloud service: Microsoft 365, Google Workspace, AWS, Azure, Salesforce, Xero. Document any service account exemptions.
2. No unsupported operating systems
Windows 10 ESU status, macOS major version, mobile OS minimums all matter. Anything past vendor end-of-support is an automatic fail unless removed from scope or covered by a paid extended-support arrangement.
3. Complete asset inventory
You need a documented list of every device that touches business data – laptops, desktops, mobiles, tablets, BYOD. The list must be current, not last quarter's spreadsheet. Assessors look for evidence of an inventory method, not just a snapshot.
4. Patching evidence (the 14-day rule)
High and critical vendor patches must be applied within 14 days. You need to demonstrate a process – not just a screenshot of one device. Show update settings on Windows, macOS, mobiles, browsers and any business-critical applications.
5. Account inventory and leavers process
Every active account must belong to an active person. Old leaver accounts and unused service accounts are an immediate red flag. Document a written leavers process – who disables what, on what timescale.
6. Firewall and router configuration
Default admin passwords changed. No unrequested inbound services exposed. Software firewalls enabled on all in-scope devices. For home workers, the home router counts – the rule is "default password changed and no unrequested inbound services".
7. Malware protection on every device
Active anti-malware on every laptop and desktop, configured to scan downloads and update automatically. Mobile devices need either an approved app store policy or a managed AV.
8. Consistent answers across the question set
Assessors flag contradictions – e.g. answering "we have BYOD" in one section and "no personal devices" in another. Have one person own the submission and review every answer in one sitting before you submit.
The pre-submission rehearsal
Read every answer back as if you were the assessor. Ask: "If I had to evidence this in 60 seconds, could I?" If the answer is no, the answer in your submission is probably overconfident. Pull it back to what you can actually prove.
Common failure patterns we see
- One Windows 10 device past end-of-support that nobody noticed
- MFA missing on the founder's "convenience" admin account
- BYOD denied in the submission, but the assessor sees it in screenshots
- Asset list missing the warehouse tablet or the meeting-room PC
- Password policy on paper but not actually enforced in M365
Use a pre-check
A pre-submission review by an assessor catches the points above before you submit. It's the single highest-leverage thing you can do for a first-time pass. NixInfinity-AI includes a pre-check on every Cyber Essentials engagement at no extra cost.
For a deeper walkthrough see our Cyber Essentials readiness checklist and the five controls breakdown.
