The firewall section can make a Cyber Essentials self-assessment stall because the questions use terms that many organisations do not use day to day.
This article translates the section: what each firewall question is really asking, what a defensible answer looks like, and the evidence worth keeping.
First: what they mean by boundary firewall
Whatever sits between your network and the internet. In a small office, that is usually the router: the box your ISP supplied or your IT provider installed. For home workers, a company-supplied router is in scope; otherwise the device needs a configured software firewall. If a corporate VPN is used, the internet boundary may be the company or cloud firewall.
For cloud services, responsibility depends on the service type. The applicant remains responsible for confirming that the applicable firewall or data-flow controls are implemented, even where the provider implements them.
Before answering anything, check your scope
The mistake that poisons the whole section is answering as if everyone sits in the office. If your scope includes remote workers, the office router does not protect them. If it includes cloud services, the box in the office is not the whole story.
Answer for everything in scope. The scope decision comes first for a reason.
The questions, translated
Do you have firewalls at the boundaries between your organisation's network and the internet? This is the router question. For a home worker without an organisation-supplied router or corporate VPN boundary, the device's software firewall carries the answer.
Are software firewalls enabled on your computers and servers? Open the settings and look. Check that the software firewall is enabled and configured at all times, including when the device is behind an office firewall.
When you first received your router, did you change the default password? This means the admin password for the router's settings page, not the Wi-Fi password. The default administrative password must be changed on every in-scope router and firewall, including where the vendor supplied a unique default password.
How is your firewall password configured? Record the option actually in use: MFA with a minimum eight-character password; automatic common-password blocking with a minimum eight-character password; a minimum 12-character password; or passwordless authentication.
Do you change the password when you suspect compromise? This needs a who and a how, not just a yes.
Do you have a process to manage your firewall, and have you reviewed the rules in the last 12 months? Review the actual firewall rules with whoever manages them, record the date and decisions, and remove rules that are no longer needed.
Is your firewall configured to allow unauthenticated inbound connections? Allowed unauthenticated inbound connections must be exceptions to a default block. Each exception needs authorised approval and a documented business need.
Can the firewall be administered from the internet? If remote administration is off, say so. Internet administration additionally requires either MFA or a trusted-IP allow-list combined with properly managed password authentication.
Two traps
Home routers. A home router supplied by the organisation is in scope. Other home routers are out of scope, so the endpoint needs the Cyber Essentials firewall controls.
Consistency. If section A2 says ten remote workers, the firewall answers cannot read as if everyone is behind the office router. Assessors read the whole document.
The four pieces of evidence to keep
Keep a screenshot or export showing router admin users and defaults removed, the remote administration setting, a one-page register of inbound rules, and a dated note of the last rule review.
Never include the firewall password itself or a full configuration dump. Assessors want proof that you manage the thing, not the keys to it.