Skip to main content
Practical guideCyber Essentials6 min read

How Businesses Fail Cyber Essentials (And How Not to Pay Twice)

Five control and preparation failures that can block a Cyber Essentials assessment in 2026, how the two-working-day resubmission rule works, and what official data says about the overall fail rate.

BylineWritten by Alec Pedersen · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 22 August 2026 · Review due 7 November 2026

At a glance

Check scope, MFA, supported software, patching and answer consistency before starting the assessment clock.

On this pageArticle contents

Share this article

LinkedInEmail

The NCSC's 2024–25 Cyber Essentials at-a-glance figures reported a 1.1% fail rate. That is useful overall context, but the published figures do not rank the reasons assessments fail. The five sections below are practical risk patterns grounded in current scheme rules, not an official frequency table.

This article covers the mechanic people often misunderstand: when a mistake costs you nothing, when it costs the whole fee again, and which control or preparation failures can block an assessment in 2026.

The two-working-day rule

If your assessment is unsuccessful, IASME allows two working days to address the assessor's feedback and resubmit without an extra charge. That window can cover a small correction, such as clarifying an answer or finishing a setting that was already under way.

It is rarely enough for the big stuff. You usually cannot roll out MFA to a whole company, replace an unsupported server, or redo a wrong scope in two days. If it still fails after that window, you must reapply and pay again.

So the useful question is simple: which problems can be fixed in two working days, and which cannot?

For the fee consequences and wider budget, read what Cyber Essentials costs in 2026.

Failure 1: scope decided wrong

Wrong scope poisons everything downstream. Leave out the remote workers, forget a site, ignore half the cloud services, and every subsequent answer was given against the wrong picture. There is no comfortable way to rescope and re-answer a full questionnaire in two days.

Under the current v3.3 requirements, cloud services that host your organisation's data or services must be in scope and cannot be excluded. The 2026 Danzell changes explain the current question set.

Failure 2: MFA not enforced everywhere

Under the current question set this is a headline automatic fail: any cloud service that offers multi-factor authentication where it is not enabled for all users. Everyone means everyone, not just administrators.

MFA is a classic two-day-window casualty because rollouts are logistics: travelling directors, unreachable contractors, shared mailboxes, and the one phone that does not cooperate. Turn it on across the company weeks early, then collect the enforcement evidence.

Failure 3: unsupported software lurking

Somewhere in many businesses there is a machine running software that stopped receiving security updates: Windows 10 without valid ESU or other vendor support, a forgotten server, an abandoned plugin. Unsupported software in scope can sink the assessment, and you cannot procure, migrate, and decommission in two days.

The fix is an honest inventory, early. Then choose a route for each item: remove it, upgrade it, replace it, or remove it from scope using a defined subset that prevents all traffic to and from the internet.

Failure 4: the 14-day patching rule assumed rather than known

High-risk updates must be applied within 14 days. The common failure is not refusing to patch; it is assuming automation covers everything and being wrong at the edges.

One laptop with updates paused. Router firmware never updated. A browser waiting six weeks for a restart. If you answer yes to 14-day patching, it needs to be true on every in-scope device, and you need a report or record that shows how you know.

Failure 5: answers that contradict each other

You say there is no remote access, then describe a VPN. Fifteen laptops appear in one section, twelve patched in another. Personal phones are mentioned in passing, then the mobile questions are answered as if they do not exist.

Assessors read the questionnaire as one document. Inconsistency reads as carelessness or concealment, and both invite scrutiny.

What is deliberately not on this list

This is not a label of being “bad at security”, and it is not an official ranking. Missing MFA, unsupported software and overdue high-risk updates are substantive technical-control failures. Wrong scope and contradictory answers are preparation failures that can make an otherwise sound submission inaccurate. All should be found before submission rather than left for the two-working-day correction window.

Provenance

Sources reviewed

Reviewed 22 August 2026

Sources reviewed by RightCyber on 22 August 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is an independent cyber security organisation and is not affiliated with or endorsed by IASME or the NCSC. This article is general guidance, not legal or professional advice.

Clarifications

Frequently asked questions

What happens if you fail Cyber Essentials?
You receive assessor feedback and usually have two working days to correct issues and resubmit free of charge. If it still fails, you reapply and pay again.
What are the automatic fails?
Current automatic-fail areas include MFA for cloud services where available, the two 14-day update questions, and unsupported in-scope software. Default credentials are non-compliant and must be corrected.
How long should Cyber Essentials preparation take?
There is no universal duration. Review the official questions before applying and leave enough time for scope checks, MFA rollout, patching verification, and remediation rather than relying on the two-working-day resubmission window.

Relevant RightCyber product

RightCyber Certification Workspace — In-house

Use the In-house workspace to record uncertainties as actions against their questions. Before export, RightCyber's rules flag selected high-risk answers and missing files. Unflagged answers still need review; the certification body decides the outcome.

Keep exploring

Browse the RightCyber Blog