Home How it works Resources About Contact Get in touch

Resources

Guide · ~7 min read

Preparing for CE without failing

If you’re going to try DIY, here’s what to watch for.

Most first-time Cyber Essentials failures are not exotic. They are the same handful of gaps, repeated. If you are preparing without external help, check these early.

  1. Unsupported operating systems still in production. One legacy server or laptop can block the whole submission.
  2. MFA missing on cloud admin accounts. User MFA is not enough if admins can still sign in without it.
  3. Admin accounts used for daily email. Separate admin from day-to-day work.
  4. Firewall admin exposed to the internet. Or still on the default password.
  5. BYOD in scope with no controls. Personal phones reading corporate mail without MAM/MDM or a clear exclusion.
  6. No written policies — or policies nobody owns. Templates help; sign-off and ownership matter more.
  7. Patching “on” but no evidence. Assessors want compliance you can show, not a belief that Windows Update is running.
  8. Anti-malware silent on the console. Devices that have not checked in for weeks.
  9. Leavers still active. Accounts from months ago still signing in somewhere.
  10. Scope misunderstandings. Submitting for the wrong boundary, or forgetting cloud services that hold corporate data.

If several of these apply, fix them before you spend the application fee — or get a readiness verdict first so you know which ones actually block you.

Get in touch · What CE asks for