If you have opened the Cyber Essentials self-assessment, thought "this looks simple", and then stalled on a phrase like "describe your boundary firewall configuration", this is the orientation you needed first.
What the assessment actually is, what changed in 2026, where people get stuck, and what a defensible answer looks like.
RightCyber is independent and is not affiliated with or endorsed by IASME or the NCSC. No preparation product or service can guarantee certification.
What Cyber Essentials actually is
Cyber Essentials is a UK government-backed certification built around five technical controls. At the basic level, an organisation completes a verified self-assessment; a senior person confirms the answers are accurate, and a qualified assessor at a licensed Certification Body reviews them.
The fee is tiered by size, certification lasts 12 months, and the catch that shapes everything is this: your answers have to hold up. If they do not, you normally get two working days to fix small things free. Fundamental problems can mean paying again.
What changed in 2026
The current question set is Danzell, aligned to v3.3 requirements and live for new assessments since 27 April 2026. Four changes matter most: cloud services are fully in scope, MFA not enforced for all users on a cloud service is an automatic fail, the 14-day patching requirement has sharper auto-fail questions, and the responsible-person declaration now points at year-round control maintenance.
Read what changed in Danzell and v3.3 for the detail. If an article you are reading predates April 2026, parts of it may be stale.
The five controls in plain English
Firewalls restrict unnecessary or insecure access from the internet: boundary firewalls plus enabled software firewalls on in-scope computers, laptops and servers.
Secure configuration reduces unnecessary exposure: change default credentials; remove unused software, services and accounts; disable automatic execution; and apply device locking.
User access control means right people, right access, no more: admin accounts separate from daily accounts, leavers removed everywhere.
Malware protection means every device has a route: anti-malware properly configured, or only approved applications can run.
Security update management means supported software only, with high-risk updates applied within 14 days.
The technical sections A4-A8 map to those five controls. The earlier A1-A3 sections cover the organisation, scope, and cyber-insurance questions, so the full assessment is broader than a five-control checklist.
Where people actually get stuck
Not on knowing their business. They get stuck on translation.
Jargon. "Boundary firewall configuration" means how your router and device firewalls are set up, and who can administer them.
Evidence. The questionnaire does not only want a yes. It wants a yes you could back up: a setting, export, dated record, or owner decision.
Scope. Before any technical question, you decide what is in: locations, devices, cloud services, user-owned devices, organisation-owned accounts used by suppliers, and externally managed services. Organisation-owned accounts and devices used by third parties remain in scope. Third-party-owned contractor or MSP devices are out of scope under the scheme table, but the organisation remains responsible for confirming that devices interacting with its services and data are configured correctly.
A worked example: weak vs defensible
The firewall question, two answers, same business, same router.
Weak: "We have a firewall and it is secure."
Defensible: "Our boundary firewall is the office router, managed by our IT provider. Default credentials were changed at install. Remote administration is disabled. The only inbound rule is the VPN, which is restricted by MFA. Rules were last reviewed in May 2026."
The difference is not security expertise. It is four facts: who manages it, what was changed, what is allowed in, and when it was last checked. Possible supporting evidence includes an admin-users export, one settings screenshot and a one-line rule register.
The renewal reality
Cyber Essentials is annual. Keep your answers and evidence, but recheck them against the current question set and requirements at renewal; saved material is a starting point, not proof that the controls still hold.
If it all feels harder than the marketing suggested, that is normal. It is translation work, and translation work can be systemised.