Cyber Essentials in a month: what actually blocks certification
Cyber Essentials is a short questionnaire covering five controls. Most organisations that fail do so on the same three points, and all three are fixable in weeks rather than months.
What actually blocks certification
- 01Unsupported software. A handful of machines on an operating system past end-of-life, or a browser nobody updated. This fails outright — there is no partial credit.
- 02Missing multi-factor authentication on administrative accounts, particularly the cloud admin accounts created during setup and never revisited.
- 03Default firewall and router configuration, including the administrative password that shipped with the device.
Everything else in the scheme tends to be either already true or quick to arrange. These three account for most of the failures we see.
A realistic four-week path
This assumes a team without a dedicated security specialist and one person able to give it a few hours a week.
- Week one — inventory. Every device, every operating system version, every account with administrative rights. Most of the eventual work is discovered here.
- Week two — patch and retire. Update what can be updated; replace or isolate what cannot. Unsupported software is the single most common cause of failure.
- Week three — accounts and access. Multi-factor authentication on every administrative account, removal of accounts belonging to people who have left, and separation of admin accounts from everyday ones.
- Week four — boundary and evidence. Change default credentials, close ports nothing needs, and assemble the evidence for the questionnaire.
Do the inventory honestly. A certificate obtained around a machine you did not declare protects nobody, and the first incident will find it.
Why bother
Two practical reasons beyond the security itself. It is increasingly a procurement requirement — public sector contracts and larger private buyers ask for it, and its absence quietly removes you from consideration. And it lowers cyber insurance premiums often enough to cover its own cost.
Staying certified
Certification lapses annually, and the second year is harder than the first if nothing changed structurally. Build the evidence into how you already work — automated patch reporting, a joiners and leavers process that actually removes access, a quarterly review of administrative accounts — and recertification becomes an afternoon.
Related practice
Compliance & Governance
Get certified, and stay certified without the annual panic.
What this involvesRead next
Working on something this touches? We start with a two-week, fixed-fee discovery.
Talk to an engineer