Can you fail Cyber Essentials?
Yes - you can fail the Cyber Essentials self-assessment submission. Fig Group includes three free re-submissions; feedback helps you correct gaps, subject to the applicable assessment window.

Section 01
Can you fail Cyber Essentials?
Yes - you can fail a Cyber Essentials submission. Failure means the assessor has identified a control gap in the self-assessment and has not issued a certificate. Fig Group includes three free re-submissions. Correcting gaps is possible within the applicable assessment window; included feedback does not guarantee certification.
Section 02
The most common reasons submissions fail
Practical gaps to check against the current scheme requirements, rather than a claimed first-two-quarter v3.3 cohort:
1. Unsupported operating systems in scope. Windows 10 Home without ESU, older Android phones past OEM support. See the Security Update Management pillar guide.
2. Missing effective MFA. MFA is required wherever available and always for cloud authentication. SMS is recognised; suitable alternatives are recommended. An authenticator app is not automatically phishing resistant. See the User Access Control pillar guide.
3. Default credentials on a boundary device. Any router or firewall still on factory admin/admin fails the Firewalls pillar.
4. Patching beyond the 14-day rule. Required vendor-approved fixes not deployed within 14 days of release: vendor high/critical, CVSS v3 7+ or no severity details.
5. No admin / user-account separation. One account used for both daily work and admin tasks.
6. Remote-worker firewall gap. Privately owned home routers are excluded; organisation-supplied routers are in scope, and endpoints need the applicable firewall controls or managed corporate VPN boundary. See Cyber Essentials for remote and hybrid workforces.
Section 03
What happens when you fail
The certification body returns written feedback identifying the failed control and the specific evidence that missed the bar. Fig Group's 6-working-hour service applies to complete compliant submissions received before midday on a UK business day. Feedback identifies work to complete; remediation timing depends on the actual gaps.
You then have a defined number of free re-submissions (three with Fig Group) to correct the gap and resubmit. Once the re-submission passes assessor review, the certificate is issued on the date of the pass.
Section 04
How to avoid failing
- Run a free readiness check before you pay. Scores your organisation against the five controls in under 10 minutes.
- Confirm every in-scope device is on a supported OS. Verify the exact version, edition, device model and active vendor vulnerability-fix support. There is no universal N-1 or monthly Android patch rule.
- Audit Conditional Access. Effective MFA wherever available and always for cloud-service authentication; check direct sign-in, legacy routes and recovery, rather than registration alone.
- Check remote firewall protection and any organisation-supplied routers. Ordinary privately owned home routers are out of scope.
Section 05
Does failing appear on a public record?
No. Only issued certificates are published on the IASME directory. A failed submission does not appear anywhere buyers or clients can see.
Section 06
Bottom line
Yes, you can fail Cyber Essentials - and it is easier to fail than many organisations realise, particularly on unsupported software, firewall gaps and MFA coverage. The free readiness check supports preparation; it cannot guarantee finding every issue or a pass. Use the assessor's feedback to plan remediation.
Start Cyber Essentials from £299.99 + VAT | Free readiness check | Cyber Essentials Online
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
AI & Security
AI-powered Cyber Essentials assessment: what Fig Group does differently
How AI-assisted assessment workflows can support triage and feedback, the boundaries they must respect, and why Fig Group’s certification decision remains with a human assessor.
Read articleGuides
Can small businesses get Cyber Essentials?
Yes - Cyber Essentials is designed for UK small businesses. Fig Group prices the Micro tier for organisations with 1-9 staff at £299.99 + VAT. An eligible scheme-level cyber-liability benefit is arranged separately by IASME and its insurance partner.
Read articleCompliance
Cyber Essentials with Outsourced IT: Who Does What?
Your MSP can complete the Cyber Essentials self-assessment for you. Learn what your organisation must review, authorise and sign off before submission.
Read article

