← All articles

Why Cyber Essentials submissions fail — and how to pass first time

25 September 2026 · 6 min read

Most Cyber Essentials submissions are not rejected because a business is insecure. They are rejected because of six specific answers that contradict each other, miss a device, or describe an intention rather than a fact. Knowing what they are lets you check yourself before a certification body does.

The first is shared accounts. A generic admin login shared across the office fails the user access control requirement outright, because nobody can tell who did what and multi-factor authentication cannot be tied to an individual. Every person who touches company systems needs their own account — including directors.

The second is multi-factor authentication gaps on email and cloud file storage. These two services are where account-takeover damage is done, so the assessment checks them hardest. 'Most staff have it' is a fail; the answer must be every account, including any old mailboxes and the accountant's shared login nobody remembers creating.

Third: unsupported software still in use. An operating system or application past its last security update cannot be made compliant by patching — it must be upgraded or removed from scope. Devices running old Windows or an unpatched phone are the most common single cause of a returned submission.

Fourth, firewalls on home workers' routers. Since staff started working from home, the assessment treats their internet connection as in scope when they log into company systems. A router still using its default admin password, or one that has not had a firmware update in years, fails the requirement even if the office is perfect.

Fifth, answers that do not match each other. Declaring a cloud accounting service in your asset list but leaving it out of the access control answers, or saying all devices are company-owned when three staff use personal laptops, creates contradictions an assessor is required to query. Consistency across the questionnaire is half the battle.

Sixth, and the quietest failure of all: evidence written the week of the assessment. A cloud service list built from memory, with no dates, is a guess — and guesses are exactly what follow-up questions expose. A register you refresh monthly, with a dated check against each control, turns the same questionnaire from a scramble into an afternoon of copying.

The good news is that all six failures are visible in advance. Kept's free readiness scan shows in about two minutes where your cloud services stand against the five controls — missing multi-factor authentication, forgotten administrators and out-of-date checks included — so you can fix the real gaps before they reach a certification body.