Skip to main content
Practical guideCyber Essentials7 min read

Cyber Essentials Self-Assessment 2026: The Walkthrough Nobody Gives You

How the Cyber Essentials self-assessment works in 2026: the five controls, where people get stuck, a worked example of a defensible answer, and the fail mechanics.

BylineWritten by Alec Pedersen · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 22 August 2026 · Review due 7 November 2026

At a glance

Confirm scope first, then answer each control from verified current evidence rather than assumptions.

On this pageArticle contents

Share this article

LinkedInEmail

If you have opened the Cyber Essentials self-assessment, thought "this looks simple", and then stalled on a phrase like "describe your boundary firewall configuration", this is the orientation you needed first.

What the assessment actually is, what changed in 2026, where people get stuck, and what a defensible answer looks like.

RightCyber is independent and is not affiliated with or endorsed by IASME or the NCSC. No preparation product or service can guarantee certification.

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed certification built around five technical controls. At the basic level, an organisation completes a verified self-assessment; a senior person confirms the answers are accurate, and a qualified assessor at a licensed Certification Body reviews them.

The fee is tiered by size, certification lasts 12 months, and the catch that shapes everything is this: your answers have to hold up. If they do not, you normally get two working days to fix small things free. Fundamental problems can mean paying again.

What changed in 2026

The current question set is Danzell, aligned to v3.3 requirements and live for new assessments since 27 April 2026. Four changes matter most: cloud services are fully in scope, MFA not enforced for all users on a cloud service is an automatic fail, the 14-day patching requirement has sharper auto-fail questions, and the responsible-person declaration now points at year-round control maintenance.

Read what changed in Danzell and v3.3 for the detail. If an article you are reading predates April 2026, parts of it may be stale.

The five controls in plain English

Firewalls restrict unnecessary or insecure access from the internet: boundary firewalls plus enabled software firewalls on in-scope computers, laptops and servers.

Secure configuration reduces unnecessary exposure: change default credentials; remove unused software, services and accounts; disable automatic execution; and apply device locking.

User access control means right people, right access, no more: admin accounts separate from daily accounts, leavers removed everywhere.

Malware protection means every device has a route: anti-malware properly configured, or only approved applications can run.

Security update management means supported software only, with high-risk updates applied within 14 days.

The technical sections A4-A8 map to those five controls. The earlier A1-A3 sections cover the organisation, scope, and cyber-insurance questions, so the full assessment is broader than a five-control checklist.

Where people actually get stuck

Not on knowing their business. They get stuck on translation.

Jargon. "Boundary firewall configuration" means how your router and device firewalls are set up, and who can administer them.

Evidence. The questionnaire does not only want a yes. It wants a yes you could back up: a setting, export, dated record, or owner decision.

Scope. Before any technical question, you decide what is in: locations, devices, cloud services, user-owned devices, organisation-owned accounts used by suppliers, and externally managed services. Organisation-owned accounts and devices used by third parties remain in scope. Third-party-owned contractor or MSP devices are out of scope under the scheme table, but the organisation remains responsible for confirming that devices interacting with its services and data are configured correctly.

A worked example: weak vs defensible

The firewall question, two answers, same business, same router.

Weak: "We have a firewall and it is secure."

Defensible: "Our boundary firewall is the office router, managed by our IT provider. Default credentials were changed at install. Remote administration is disabled. The only inbound rule is the VPN, which is restricted by MFA. Rules were last reviewed in May 2026."

The difference is not security expertise. It is four facts: who manages it, what was changed, what is allowed in, and when it was last checked. Possible supporting evidence includes an admin-users export, one settings screenshot and a one-line rule register.

The renewal reality

Cyber Essentials is annual. Keep your answers and evidence, but recheck them against the current question set and requirements at renewal; saved material is a starting point, not proof that the controls still hold.

If it all feels harder than the marketing suggested, that is normal. It is translation work, and translation work can be systemised.

Provenance

Sources reviewed

Reviewed 22 August 2026

Sources reviewed by RightCyber on 22 August 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is an independent cyber security organisation and is not affiliated with or endorsed by IASME or the NCSC. This article is general guidance, not legal or professional advice.

Clarifications

Frequently asked questions

How long does the Cyber Essentials self-assessment take?
There is no fixed duration. Download the official question set before applying and allow enough time to verify scope, roll out missing controls, and complete remediation before submission.
Who reviews the self-assessment?
A qualified assessor at a licensed Certification Body reviews the answers. Before submission, a senior person in the applicant organisation confirms they are accurate.
Can you fail a self-assessment?
Yes. You usually get two working days to fix issues free. Failures that cannot be fixed in that window can mean reapplying and paying again.
Where do I get the official questions?
IASME publishes a free preview of the self-assessment questions. Use official IASME and NCSC sources alongside any preparation tool.

Relevant RightCyber product

RightCyber Certification Workspace — In-house

The In-house workspace groups the questions into IASME’s own sections with a ready count for each, takes device and cloud lists as inventory rows, and marks the questions your own answers make unnecessary.

Keep exploring

Browse the RightCyber Blog