Everything in Cyber Essentials hangs off five controls. Firewalls: something stands between your devices and the internet, a boundary firewall or, for remote workers, the software firewall on the device, configured deliberately. Secure configuration: default passwords changed, unused accounts and services removed, autorun disabled, devices locked when idle. Security update management: supported software only, updates applied promptly, with high and critical fixes installed within 14 days. User access control: individual accounts, access granted on need, admin rights separated from daily-use accounts, and MFA on cloud services. Malware protection: anti-malware active and current on in-scope devices, or equivalent approved mechanisms.
The scheme's insight is that these five, done consistently, defeat the commodity attacks behind the overwhelming majority of SME breaches. The 2026 update didn't change the five, it made two of them (updates and MFA) automatic failures when absent.
The full question-by-question detail lives in our preparation guide; the answers below cover the decisions and edge cases that generate the most confusion.
Most Cyber Essentials confusion traces to three sources. First, stale information: the scheme changes every April, and advice written for Montpellier or Willow can now be actively wrong, anything not mentioning Danzell or v3.3 should be treated as historical. Second, scope wishful thinking: the rules about BYOD, remote workers and cloud services are stricter than people hope, and the 2026 wording deliberately closed the loopholes. Third, conflating the tiers: what's true of the self-assessment isn't true of Plus, and contract clauses rarely say which they mean.
When in doubt, two habits solve most problems: read the current Requirements for IT Infrastructure document itself rather than summaries of it, and check which question set (and version) any advice refers to.
Every misconception above has caused a real failed submission or a lost contract. The detailed answers below exist so yours isn’t next.
Send it over, our security team answers directly. And register your interest to be first in line when our certification service launches.