Skip to content
Guides

Can you fail Cyber Essentials?

Yes - you can fail the Cyber Essentials self-assessment submission. Fig Group includes three free re-submissions; feedback helps you correct gaps, subject to the applicable assessment window.

man wearing white top using MacBook

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Can you fail Cyber Essentials?

Yes - you can fail a Cyber Essentials submission. Failure means the assessor has identified a control gap in the self-assessment and has not issued a certificate. Fig Group includes three free re-submissions. Correcting gaps is possible within the applicable assessment window; included feedback does not guarantee certification.

Section 02

The most common reasons submissions fail

Practical gaps to check against the current scheme requirements, rather than a claimed first-two-quarter v3.3 cohort:

1. Unsupported operating systems in scope. Windows 10 Home without ESU, older Android phones past OEM support. See the Security Update Management pillar guide.

2. Missing effective MFA. MFA is required wherever available and always for cloud authentication. SMS is recognised; suitable alternatives are recommended. An authenticator app is not automatically phishing resistant. See the User Access Control pillar guide.

3. Default credentials on a boundary device. Any router or firewall still on factory admin/admin fails the Firewalls pillar.

4. Patching beyond the 14-day rule. Required vendor-approved fixes not deployed within 14 days of release: vendor high/critical, CVSS v3 7+ or no severity details.

5. No admin / user-account separation. One account used for both daily work and admin tasks.

6. Remote-worker firewall gap. Privately owned home routers are excluded; organisation-supplied routers are in scope, and endpoints need the applicable firewall controls or managed corporate VPN boundary. See Cyber Essentials for remote and hybrid workforces.

Section 03

What happens when you fail

The certification body returns written feedback identifying the failed control and the specific evidence that missed the bar. Fig Group's 6-working-hour service applies to complete compliant submissions received before midday on a UK business day. Feedback identifies work to complete; remediation timing depends on the actual gaps.

You then have a defined number of free re-submissions (three with Fig Group) to correct the gap and resubmit. Once the re-submission passes assessor review, the certificate is issued on the date of the pass.

Section 04

How to avoid failing

  • Run a free readiness check before you pay. Scores your organisation against the five controls in under 10 minutes.
  • Confirm every in-scope device is on a supported OS. Verify the exact version, edition, device model and active vendor vulnerability-fix support. There is no universal N-1 or monthly Android patch rule.
  • Audit Conditional Access. Effective MFA wherever available and always for cloud-service authentication; check direct sign-in, legacy routes and recovery, rather than registration alone.
  • Check remote firewall protection and any organisation-supplied routers. Ordinary privately owned home routers are out of scope.

Section 05

Does failing appear on a public record?

No. Only issued certificates are published on the IASME directory. A failed submission does not appear anywhere buyers or clients can see.

Section 06

Bottom line

Yes, you can fail Cyber Essentials - and it is easier to fail than many organisations realise, particularly on unsupported software, firewall gaps and MFA coverage. The free readiness check supports preparation; it cannot guarantee finding every issue or a pass. Use the assessor's feedback to plan remediation.

Start Cyber Essentials from £299.99 + VAT | Free readiness check | Cyber Essentials Online

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group