How to Pass Cyber Essentials First Time

Cyber Essentials is the UK Government-backed certification that proves your business has the basics of cyber security covered. Most failures aren't caused by clever attacks — they're caused by simple, fixable gaps. This guide walks you through exactly what's tested and how to close those gaps before your assessment.

What the assessment actually checks

Cyber Essentials tests five technical controls. As of 2025 the scheme was updated to a simpler, outcome-driven scope, but the core is unchanged:

The five most common reasons businesses fail

  1. Shared or default passwords — one shared login across the team is an automatic fail.
  2. No two-factor authentication — on email and cloud admin accounts especially.
  3. Old operating systems — end-of-life versions of Windows or macOS are a hard fail.
  4. Unmanaged personal devices — staff using unpatched phones or laptops for work.
  5. No record of what's installed — you can't secure what you can't account for.

Passing first time: the week-before plan

Run a full self-assessment against the five controls, fix the gaps, then verify with a second pass. The key is being honest about every device — including the MD's iPad and the freelancer's laptop — because the assessor will ask.

Cyber Essentials Gap Assessment Workbook

A 49-question, control-by-control workbook that shows you exactly where you'd fail today and what to fix — so you walk into assessment ready instead of hoping.

Get it now

Once the basics are covered, organisations taking the next step often move to Cyber Essentials Plus, which adds a hands-on technical verification.