The NCSC's 2024–25 Cyber Essentials at-a-glance figures reported a 1.1% fail rate. That is useful overall context, but the published figures do not rank the reasons assessments fail. The five sections below are practical risk patterns grounded in current scheme rules, not an official frequency table.
This article covers the mechanic people often misunderstand: when a mistake costs you nothing, when it costs the whole fee again, and which control or preparation failures can block an assessment in 2026.
The two-working-day rule
If your assessment is unsuccessful, IASME allows two working days to address the assessor's feedback and resubmit without an extra charge. That window can cover a small correction, such as clarifying an answer or finishing a setting that was already under way.
It is rarely enough for the big stuff. You usually cannot roll out MFA to a whole company, replace an unsupported server, or redo a wrong scope in two days. If it still fails after that window, you must reapply and pay again.
So the useful question is simple: which problems can be fixed in two working days, and which cannot?
For the fee consequences and wider budget, read what Cyber Essentials costs in 2026.
Failure 1: scope decided wrong
Wrong scope poisons everything downstream. Leave out the remote workers, forget a site, ignore half the cloud services, and every subsequent answer was given against the wrong picture. There is no comfortable way to rescope and re-answer a full questionnaire in two days.
Under the current v3.3 requirements, cloud services that host your organisation's data or services must be in scope and cannot be excluded. The 2026 Danzell changes explain the current question set.
Failure 2: MFA not enforced everywhere
Under the current question set this is a headline automatic fail: any cloud service that offers multi-factor authentication where it is not enabled for all users. Everyone means everyone, not just administrators.
MFA is a classic two-day-window casualty because rollouts are logistics: travelling directors, unreachable contractors, shared mailboxes, and the one phone that does not cooperate. Turn it on across the company weeks early, then collect the enforcement evidence.
Failure 3: unsupported software lurking
Somewhere in many businesses there is a machine running software that stopped receiving security updates: Windows 10 without valid ESU or other vendor support, a forgotten server, an abandoned plugin. Unsupported software in scope can sink the assessment, and you cannot procure, migrate, and decommission in two days.
The fix is an honest inventory, early. Then choose a route for each item: remove it, upgrade it, replace it, or remove it from scope using a defined subset that prevents all traffic to and from the internet.
Failure 4: the 14-day patching rule assumed rather than known
High-risk updates must be applied within 14 days. The common failure is not refusing to patch; it is assuming automation covers everything and being wrong at the edges.
One laptop with updates paused. Router firmware never updated. A browser waiting six weeks for a restart. If you answer yes to 14-day patching, it needs to be true on every in-scope device, and you need a report or record that shows how you know.
Failure 5: answers that contradict each other
You say there is no remote access, then describe a VPN. Fifteen laptops appear in one section, twelve patched in another. Personal phones are mentioned in passing, then the mobile questions are answered as if they do not exist.
Assessors read the questionnaire as one document. Inconsistency reads as carelessness or concealment, and both invite scrutiny.
What is deliberately not on this list
This is not a label of being “bad at security”, and it is not an official ranking. Missing MFA, unsupported software and overdue high-risk updates are substantive technical-control failures. Wrong scope and contradictory answers are preparation failures that can make an otherwise sound submission inaccurate. All should be found before submission rather than left for the two-working-day correction window.