Cyber Essentials Self-Assessment Questionnaire (SAQ) Guide
Published 30 April 2026
What the SAQ covers
The questionnaire is organised by control area: scope, firewalls, secure configuration, user access, malware protection, and security update management. Every "yes" answer should be supported by evidence you can produce on request.
Section by section
A1 – Your organisation
Legal entity, headcount, registered office. Determines your IASME pricing tier.
A2 – Scope
What is in scope: which devices, which networks, which cloud services, BYOD policy. Get this wrong and the rest of the assessment is invalid. See our scope guide.
A3 – Insurance
Triggers the £25k cyber liability cover for eligible UK organisations under £20m turnover.
A4 – Firewalls
Default credentials changed, inbound services documented, software firewalls on every device.
A5 – Secure configuration
Auto-run disabled, unnecessary accounts removed, default passwords changed, hardening applied.
A6 – User access control
Account approval, separation of admin accounts, MFA on cloud, removal of leavers' accounts.
A7 – Malware protection
Anti-malware on every in-scope device, configured to update and scan automatically.
A8 – Security update management
14-day patching rule, no unsupported software in scope, patch evidence retained.
Download the official question set
You can download the full Danzell question set free from our Cyber Essentials hub. It is the same Excel file IASME provides to assessors.
Common SAQ mistakes
- Wrong scope – excluding cloud services that are in scope.
- Over-claiming MFA – ticking "yes, all users" when only admins are enforced.
- Patch claims without evidence – "we patch within 14 days" but no report to back it.
- Forgotten BYOD – staff using personal phones for work email without MDM or MFA.
- Unsupported software – Windows Server 2012, end-of-life macOS, old browsers.
