Skip to main content
ExplainerCyber Essentials7 min read

The Cyber Essentials Firewall Questions, Explained in Plain English

The main firewall questions in the current Cyber Essentials self-assessment, translated into plain English: what is being asked, what a defensible answer needs, and what evidence to keep.

BylineWritten by Alec Pedersen · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 22 August 2026 · Review due 7 November 2026

At a glance

Document each firewall, administrator route, inbound exception and rule review with current evidence.

On this pageArticle contents

Share this article

LinkedInEmail

The firewall section can make a Cyber Essentials self-assessment stall because the questions use terms that many organisations do not use day to day.

This article translates the section: what each firewall question is really asking, what a defensible answer looks like, and the evidence worth keeping.

First: what they mean by boundary firewall

Whatever sits between your network and the internet. In a small office, that is usually the router: the box your ISP supplied or your IT provider installed. For home workers, a company-supplied router is in scope; otherwise the device needs a configured software firewall. If a corporate VPN is used, the internet boundary may be the company or cloud firewall.

For cloud services, responsibility depends on the service type. The applicant remains responsible for confirming that the applicable firewall or data-flow controls are implemented, even where the provider implements them.

Before answering anything, check your scope

The mistake that poisons the whole section is answering as if everyone sits in the office. If your scope includes remote workers, the office router does not protect them. If it includes cloud services, the box in the office is not the whole story.

Answer for everything in scope. The scope decision comes first for a reason.

The questions, translated

Do you have firewalls at the boundaries between your organisation's network and the internet? This is the router question. For a home worker without an organisation-supplied router or corporate VPN boundary, the device's software firewall carries the answer.

Are software firewalls enabled on your computers and servers? Open the settings and look. Check that the software firewall is enabled and configured at all times, including when the device is behind an office firewall.

When you first received your router, did you change the default password? This means the admin password for the router's settings page, not the Wi-Fi password. The default administrative password must be changed on every in-scope router and firewall, including where the vendor supplied a unique default password.

How is your firewall password configured? Record the option actually in use: MFA with a minimum eight-character password; automatic common-password blocking with a minimum eight-character password; a minimum 12-character password; or passwordless authentication.

Do you change the password when you suspect compromise? This needs a who and a how, not just a yes.

Do you have a process to manage your firewall, and have you reviewed the rules in the last 12 months? Review the actual firewall rules with whoever manages them, record the date and decisions, and remove rules that are no longer needed.

Is your firewall configured to allow unauthenticated inbound connections? Allowed unauthenticated inbound connections must be exceptions to a default block. Each exception needs authorised approval and a documented business need.

Can the firewall be administered from the internet? If remote administration is off, say so. Internet administration additionally requires either MFA or a trusted-IP allow-list combined with properly managed password authentication.

Two traps

Home routers. A home router supplied by the organisation is in scope. Other home routers are out of scope, so the endpoint needs the Cyber Essentials firewall controls.

Consistency. If section A2 says ten remote workers, the firewall answers cannot read as if everyone is behind the office router. Assessors read the whole document.

The four pieces of evidence to keep

Keep a screenshot or export showing router admin users and defaults removed, the remote administration setting, a one-page register of inbound rules, and a dated note of the last rule review.

Never include the firewall password itself or a full configuration dump. Assessors want proof that you manage the thing, not the keys to it.

Provenance

Sources reviewed

Reviewed 22 August 2026

Sources reviewed by RightCyber on 22 August 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is an independent cyber security organisation and is not affiliated with or endorsed by IASME or the NCSC. This article is general guidance, not legal or professional advice.

Clarifications

Frequently asked questions

What is a boundary firewall in Cyber Essentials?
It is the device or control between your network and the internet. For a home worker, that may be an organisation-supplied router, a corporate or cloud VPN boundary, or the device's configured software firewall.
Do home workers need their routers assessed?
A home router supplied by the organisation is in scope. Other home routers are out of scope, so the in-scope endpoint needs the Cyber Essentials firewall controls.
What inbound connections are acceptable?
Allowed unauthenticated inbound connections must be exceptions to a default block. Each exception needs authorised approval and a documented business need. Internet administration separately requires MFA or a trusted-IP allow-list with properly managed password authentication.

Relevant RightCyber product

RightCyber Certification Workspace — In-house

The In-house workspace keeps the firewall questions with your evidence notes against each reference, and takes networks and network equipment as inventory rows with columns rather than prose.

Keep exploring

Browse the RightCyber Blog