Cyber Essentials FAQ

Straight answers to the questions UK organisations actually ask about Cyber Essentials, updated for the Danzell (v3.3) question set that took effect on 27 April 2026, and written by security practitioners rather than a marketing team.

RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Until launch, this FAQ is our contribution to getting UK businesses ready for the tougher 2026 rules.

Can’t find your question? Ask us directly, the form on this page reaches our security team, not a call centre.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Ask Us Anything

Send your Cyber Essentials question and our security team will reply, and we’ll notify you when our certification service launches.

You’ll get our Danzell readiness checklist by reply, and one email when we launch. No mailing lists, ever.

Launching Soon RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Register your interest for priority assessment slots at launch and our free Danzell readiness checklist now.
Updated for Danzell v3.3 · Practitioner-written answers · Official IASME fees quoted · No sales fluff · Ask-us-directly form
Who this is for

This page is for you if you’re..

1
Researching certification
Anyone evaluating whether, when and how to certify under the 2026 scheme rules.
2
Mid-application
Teams partway through the question set hitting scope or interpretation questions.
3
Renewing under new rules
Willow-era certificate holders working out what Danzell changes for them.

Cyber Essentials in One Box

Last reviewed: 2026-07-21
What
UK Government-backed certification of five technical controls, owned by NCSC, delivered by IASME
Current rules
Requirements v3.3, assessed via the Danzell question set, in force since 27 April 2026
Cost
Micro (0–9 staff) £320 + VAT · Small (10–49) £440 + VAT · Medium (50–249) £500 + VAT · Large (250+) £600 + VAT
Time
Days if ready; weeks if remediating; 6 months allowed from purchase to submission
Validity
12 months; annual reassessment against the then-current question set
Tiers
Cyber Essentials (verified self-assessment) and Cyber Essentials Plus (adds independent technical audit within 3 months of the CE pass)
13
Detailed answers below
v3.3
Requirements version covered
27 Apr 2026
Date the current rules took effect
£320–£600
Official fee range + VAT

The five controls, in plain English

Everything in Cyber Essentials hangs off five controls. Firewalls: something stands between your devices and the internet, a boundary firewall or, for remote workers, the software firewall on the device, configured deliberately. Secure configuration: default passwords changed, unused accounts and services removed, autorun disabled, devices locked when idle. Security update management: supported software only, updates applied promptly, with high and critical fixes installed within 14 days. User access control: individual accounts, access granted on need, admin rights separated from daily-use accounts, and MFA on cloud services. Malware protection: anti-malware active and current on in-scope devices, or equivalent approved mechanisms.

The scheme's insight is that these five, done consistently, defeat the commodity attacks behind the overwhelming majority of SME breaches. The 2026 update didn't change the five, it made two of them (updates and MFA) automatic failures when absent.

Fast facts people are surprised by:
Your certificate is public: the NCSC maintains a searchable register of certified organisations
BYOD phones checking work email are in scope, and always were
You get 6 months from purchase to submit, no need to rush the portal
A board member or equivalent must personally sign the declaration
The insurance included with certification is real: £25k cover for eligible organisations
The question set is downloadable free in advance, prepare before you pay

The full question-by-question detail lives in our preparation guide; the answers below cover the decisions and edge cases that generate the most confusion.

Where confusion actually comes from

Most Cyber Essentials confusion traces to three sources. First, stale information: the scheme changes every April, and advice written for Montpellier or Willow can now be actively wrong, anything not mentioning Danzell or v3.3 should be treated as historical. Second, scope wishful thinking: the rules about BYOD, remote workers and cloud services are stricter than people hope, and the 2026 wording deliberately closed the loopholes. Third, conflating the tiers: what's true of the self-assessment isn't true of Plus, and contract clauses rarely say which they mean.

When in doubt, two habits solve most problems: read the current Requirements for IT Infrastructure document itself rather than summaries of it, and check which question set (and version) any advice refers to.

The misconceptions we correct most often:
“Our IT provider handles security, so we're out of scope decisions”, the declaration is yours to sign
“Cloud services are the provider's responsibility”, configuration and MFA are yours
“We passed last year so renewal is a formality”, the rules changed underneath you
“Personal devices don't count”, they do the moment they touch work data
“CE covers our product's security”, it covers your organisation, not your codebase
“Any certificate satisfies the contract”, CE and CE Plus are distinct requirements

Every misconception above has caused a real failed submission or a lost contract. The detailed answers below exist so yours isn’t next.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

A Question We Haven’t Answered?

Send it over, our security team answers directly. And register your interest to be first in line when our certification service launches.

Frequently Asked Questions

Requirements v3.3 and the Danzell question set replaced Willow for applications from 27 April 2026. Headlines: MFA is mandatory on all cloud services where available (automatic failure), high/critical updates must be applied within 14 days (automatic failure), the definition of cloud services was clarified and broadened, scoping for remote workers and BYOD was tightened, and the CE+ methodology gained anti-gaming measures. Legacy Willow accounts must be finalised by 26 October 2026.

Contractually: suppliers to UK central government handling certain data, much of the MOD supply chain, and any organisation whose customer contracts or frameworks name it. Practically: any UK organisation that wants a recognised, verified security baseline, it's the closest thing the UK has to a universal minimum standard.

Preparation is the variable: organisations with controls in place complete the questionnaire in days, and assessments are typically reviewed within a few working days of submission. First-timers usually spend 2–8 weeks remediating. You have 6 months from purchase to submit, and Plus must follow within 3 months of the CE pass.

The IASME-set assessment fee: £320 + VAT (0–9 employees), £440 (10–49), £500 (50–249), £600 (250+). Cyber Essentials Plus is priced by the Certification Body, typically £1,400–£4,000+ VAT for SMEs. Remediation and optional support are extra and estate-dependent, see our full cost guide.

Yes, any personally owned device used to access organisational data or services, work email, files, chat, is in scope and must meet the controls: supported OS, updates, screen lock, malware protection. Devices used only for calls/texts or purely personal use are out. The 2026 wording removed the ambiguity people previously relied on.

Remote workers are fully in scope. Their devices must meet all controls, and the firewall requirement is satisfied by the device's software firewall properly configured, home routers are generally out of scope unless supplied by the organisation. Untrusted networks (cafes, hotels) are exactly what the controls are designed to make safe.

Under the 2026 definition: services you subscribe to where organisational data or services live, Microsoft 365, Google Workspace, CRM, accounting, storage, code repositories, admin consoles, and explicitly including business social media accounts (LinkedIn, Facebook, Instagram, X). Each belongs on your asset list with individual logins, and MFA must be enabled wherever the service offers it. Missing MFA on any in-scope cloud service is an automatic failure.

UK-domiciled organisations under £20m annual turnover that certify their whole organisation receive cyber liability insurance (£25,000 indemnity) included with certification, no extra cost, opt-out possible. It's real cover with real conditions; read the policy summary, and treat it as a floor, not a substitute for proper cyber insurance.

Yes, and under the 2026 marking, missing MFA on cloud services, unsupported software in scope, or patching outside 14 days are automatic failures. Minor issues may be clarified within the assessment window; substantive failures mean remediating and reapplying (new fee). A pre-submission review is the cheap insurance against this.

No, but it helps. The five controls are strong evidence of UK GDPR Article 32 'appropriate technical measures', and the ICO views certification favourably as a baseline. GDPR's broader duties, lawful basis, rights, records, DPIAs, are untouched by CE. The two overlap usefully, but neither replaces the other.

Read your contracts first: if any says Plus, that decides it. Otherwise: CE for baseline credibility, insurance eligibility and most public-sector requirements; Plus when buyers demand independent verification, common in MOD, NHS and enterprise supply chains, or when you want your controls genuinely tested. Plus requires CE first, within a 3-month window.

The scheme separates roles: the assessor verifying your submission must be independent of the answers' preparation in the ways the scheme rules define. In practice, providers (including us, once launched) offer readiness support, gap analysis, remediation guidance, pre-submission review, while the formal assessment is conducted under IASME's independence and quality rules. You can also buy readiness help and certification from different providers entirely.

The certificate is identical everywhere: every IASME-licensed body assesses against the same NCSC requirements, charges the same IASME-set fee for the basic assessment, and lists you on the same public register. Bodies differ on the things around the assessment, readiness support, turnaround time, sector expertise, and CE Plus pricing (which each body sets itself). Choose on support quality and fit, not on the certificate, which doesn't vary.
📞 Call us Book a call