Cyber Essentials Preparation Guide

Passing Cyber Essentials in 2026 is a preparation exercise: the Danzell question set is downloadable free before you spend a pound, and every automatic-failure condition can be checked, and fixed, before submission. This guide is the sequence we’ll use with our own clients.

Written by the RedSecLabs security team as we prepare to launch our Cyber Essentials certification service. It reflects the Requirements for IT Infrastructure v3.3, in force since 27 April 2026.

Work through the eight steps below in order, scope first, evidence last, and the assessment itself becomes the easiest part of the process.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Want the Checklist Version?

Register your interest and we’ll send the downloadable Danzell readiness checklist, and notify you when our certification service launches.

You’ll get our Danzell readiness checklist by reply, and one email when we launch. No mailing lists, ever.

Launching Soon RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Register your interest for priority assessment slots at launch and our free Danzell readiness checklist now.
Danzell (v3.3) specific · Auto-fail conditions flagged · Free question set linked · Practitioner-sequenced · Checklist available on request
Who this is for

This page is for you if you’re..

1
Preparing a first submission
Teams working toward their first certification who want to pass on the first attempt.
2
Renewing from Willow
Certificate holders whose next renewal lands under the stricter Danzell rules.
3
IT providers
MSPs and IT support firms preparing client environments for certification.

Preparation at a Glance

Last reviewed: 2026-07-21
Start here
Download the current (Danzell) question set free from the IASME website and read it before touching your environment
Time to allow
1–2 weeks if controls exist; 4–8 weeks for typical first-timers; 6 months permitted from purchase to submission
The two auto-fails
MFA missing on any in-scope cloud service; high/critical updates older than 14 days (or unsupported software in scope)
Hardest step
Honest scoping: BYOD, remote workers and the full cloud service list under the 2026 definitions
Who signs
A board member or equivalent must personally sign the declaration, brief them early
Cost while preparing
£0, preparation requires no purchase; the fee applies when you're ready to be assessed
8
Steps from zero to submission-ready
2
Automatic-failure conditions to clear first
14 days
The patching window you must evidence
Free
The question set, before you spend anything

Before the steps: understand the marking

Danzell assessments are marked against v3.3 with less discretion than earlier years. Two conditions fail a submission outright regardless of everything else: multi-factor authentication missing on any in-scope cloud service where the service supports it, and security update management outside the rules, unsupported software in scope, or high/critical updates unapplied beyond 14 days. Clear those two first; nothing else matters until they're clean.

Beyond the auto-fails, assessors mark for accuracy and internal consistency. An asset list of 12 laptops alongside an answer describing 30 users invites questions; “we plan to enable” anything is a fail for that control, the scheme assesses the present tense. Write every answer as a description of today, verified by someone who can see the admin consoles, not as an aspiration.

Evidence worth gathering as you go:
Export of MFA enforcement status from every cloud service admin console
Patch/update compliance report from your MDM, RMM or update service
Asset register: devices (make, model, OS version) and every cloud service
Firewall/router models and confirmation default credentials are changed
User list with admin accounts separated and leavers removed, dated
Screenshot-level proof of malware protection active on each build type

None of this evidence is submitted with the basic assessment, but gathering it forces the honesty the marking rewards, and it becomes your CE+ pack, insurance evidence and next year’s renewal baseline for free.

Where preparation goes wrong

Failed first attempts cluster around the same patterns: scope drawn optimistically (the director's home laptop “doesn't really count”), cloud service lists built from memory instead of billing records and SSO logs, answers written by someone who can't see the actual configurations, and the declaration signer discovering their responsibilities the morning of submission.

The fix is sequencing. Scope before inventory, inventory before remediation, remediation before answers, review before submission. Teams that jump straight to the questionnaire, the natural instinct, end up rewriting it twice as the real scope emerges underneath them.

Anti-patterns that cause failed submissions:
Writing answers before the asset and cloud inventories exist
Scoping by wishful thinking instead of the v3.3 definitions
Building the cloud list from memory, check billing, SSO and password managers
“We plan to” answers, the scheme assesses the present tense only
Leaving the board signer's briefing until submission day
Skipping the pre-submission review that would have caught all of the above

Preparation done in the right order is boring, and boring is exactly what you want an assessment to be.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

The eight-step preparation sequence

Work top to bottom. Each step produces the input the next one needs.

1
Download the current question set
Get the Danzell question set free from the IASME website (PDF or spreadsheet) and read it end to end. Confirm you're reading Danzell/v3.3, not Willow, advice and templates for older sets can now be wrong. Draft answers in the spreadsheet; the portal comes later.
2
Define your scope honestly
Whole-organisation scope is the default, and it is what qualifies you for the included insurance. Apply the v3.3 definitions: every device accessing organisational data (company and BYOD), every remote worker, every cloud service. If you must exclude anything, it needs genuine network segregation, not a sentence saying so.
3
Build the asset and cloud inventories
List devices with OS and version; list every cloud service, verified against billing records, SSO dashboards and password managers, not memory, and remember business social media accounts are explicitly in scope under the 2026 definition. This inventory decides everything downstream, and incomplete cloud lists are the most common hidden failure under the 2026 definitions.
4
Clear auto-fail #1: MFA everywhere
For each cloud service on the inventory, enforce MFA for all users wherever the service supports it, Microsoft 365, Google Workspace, code repositories, admin consoles, the lot. Export enforcement evidence from each admin console as you go.
5
Clear auto-fail #2: updates and support status
Remove, replace or properly segregate anything running unsupported software. Enable automatic updates where possible and verify high/critical updates apply within 14 days across every build, verify with reports, not settings screens.
6
Fix access control and configuration
Individual accounts for everyone; admin rights separated into distinct accounts used only for admin tasks; leavers disabled; default passwords changed on firewalls and routers; screen locks and device passcodes enforced; malware protection confirmed active per build type.
7
Answer as-is, then review as an assessor would
Complete the question set describing today's reality, checked by someone who can see the consoles. Then have someone independent read it for internal consistency: do the numbers, scope statements and control answers agree with each other? This is the step we formalise as a pre-submission review.
8
Brief the signer, purchase, submit
Walk the board member through what they're declaring before the portal is open. Purchase assessment access through your chosen Certification Body, paste in your prepared answers, and submit, with 6 months of headroom you'll no longer need.

Want a Second Pair of Eyes Before You Submit?

Register your interest and we’ll review your readiness against every auto-fail condition, and contact you the day our certification service launches.

Frequently Asked Questions

Free from the IASME website, downloadable as a PDF or spreadsheet for preparation before you pay anything. Make sure you download Danzell (for applications from 27 April 2026); if a document says Willow or Montpellier, it's the wrong version for new applications.

Yes, and you should. The question set is free, scoping and remediation cost nothing but effort, and the assessment fee only applies when you purchase portal access to submit. Preparing first means the 6-month submission window becomes irrelevant.

Completely. The declaration a board member signs asserts the answers are accurate, and the 2026 wording explicitly brings personally owned devices accessing work data into scope. If BYOD can't meet the controls, the honest paths are managing those devices, issuing company ones, or genuinely blocking work data on them, not omission.

Prioritise the two auto-fail conditions (MFA and updates/support status), everything else at least allows conversation. If a contract deadline is forcing the pace, segregating problem systems out of scope is often faster than fixing them, provided the segregation is real. This is exactly what a readiness review helps triage.

No, but visibility helps. Built-in tools (Windows Update reports, macOS MDM profiles) or whatever RMM your IT provider runs are sufficient, what matters is being able to see, per device, that high/critical updates land within 14 days. If you can't see it, you can't truthfully answer it.

Many well-run small organisations pass using exactly this sequence and nothing more. Paid support earns its keep when estates are messy, deadlines are contractual, nobody internal can own the process, or a previous submission failed. Our pre-submission review exists for the narrower case where you've done the work and want assessor-grade eyes on it before the fee is at stake.
📞 Call us Book a call