Resources
Guide · ~7 min read
Preparing for CE without failing
If you’re going to try DIY, here’s what to watch for.
Most first-time Cyber Essentials failures are not exotic. They are the same handful of gaps, repeated. If you are preparing without external help, check these early.
- Unsupported operating systems still in production. One legacy server or laptop can block the whole submission.
- MFA missing on cloud admin accounts. User MFA is not enough if admins can still sign in without it.
- Admin accounts used for daily email. Separate admin from day-to-day work.
- Firewall admin exposed to the internet. Or still on the default password.
- BYOD in scope with no controls. Personal phones reading corporate mail without MAM/MDM or a clear exclusion.
- No written policies — or policies nobody owns. Templates help; sign-off and ownership matter more.
- Patching “on” but no evidence. Assessors want compliance you can show, not a belief that Windows Update is running.
- Anti-malware silent on the console. Devices that have not checked in for weeks.
- Leavers still active. Accounts from months ago still signing in somewhere.
- Scope misunderstandings. Submitting for the wrong boundary, or forgetting cloud services that hold corporate data.
If several of these apply, fix them before you spend the application fee — or get a readiness verdict first so you know which ones actually block you.
