Key points:
- Cyber Essentials is a UK Government-backed certification scheme built around five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection.
- Certification does not replace FCA governance or operational resilience obligations, but it can provide a recognised security baseline and useful evidence for clients, insurers, auditors, and procurement teams.
- Cyber Essentials uses an independently verified self-assessment, while Cyber Essentials Plus applies the same requirements but adds hands-on technical testing of systems within scope.
- Unsupported software, incomplete patching, weak administrator controls, inconsistent MFA, unmanaged devices, and inaccurate assessment scope can prevent firms from achieving certification.
- A structured Root.12 review can identify control and evidence gaps across Microsoft 365, endpoints, access management, security updates, and device governance before the assessment is submitted.
Cyber Essentials certification is often treated as a straightforward questionnaire completed before a contract renewal, insurance application, or client security review. In practice, the assessment examines whether essential security controls are consistently applied across the organisation’s in-scope devices, cloud services, users, software, and internet-facing infrastructure. The certification is renewed annually, meaning firms must demonstrate that their current environment meets the requirements rather than relying on policies or configurations introduced several years earlier.
For FCA-regulated and audit-driven firms, the importance of Cyber Essentials extends beyond displaying a certification badge. Regulators, insurers, investors, and enterprise clients increasingly expect businesses to understand their technology dependencies, manage access and third-party risk, identify vulnerabilities, and maintain appropriate security controls. Cyber Essentials is not an FCA compliance framework and does not prove that every operational resilience obligation has been met. It does, however, create a recognised technical baseline that can support a wider evidence-led governance programme.
The difficulty is that many firms begin the application before confirming what is actually in scope or whether their answers match the configuration of their environment. Microsoft 365 security settings may differ between users, former employees may retain access, laptops may fall outside central device management, and unsupported applications may remain installed without clear ownership. A structured readiness review should therefore take place before submission. By reviewing the environment against the Cyber Essentials controls, Root.12 can expose technical weaknesses, evidence gaps, and inconsistent processes while there is still time to remediate them.
Why Cyber Essentials Certification matters for regulated UK firms
Cyber Essentials Certification provides a recognised cybersecurity baseline for organisations operating across the UK. For FCA-regulated and audit-driven firms, the certification can support wider governance, procurement, insurance, and due diligence requirements by demonstrating that essential technical controls are applied across the business.
Cyber Essentials does not replace FCA obligations, operational resilience planning, or a complete information security framework. However, it can help firms prove that common cyber risks are being addressed through practical controls rather than policy statements alone. This is especially valuable when clients, insurers, investors, or auditors request evidence of basic cybersecurity maturity.
For regulated UK firms, Cyber Essentials Certification can support:
- Client and supplier due diligence assessments
- Cyber insurance applications and renewal reviews
- Procurement requirements for public and private sector contracts
- Evidence of baseline security controls during audits
- Improved visibility into devices, software, users, and cloud services
- Greater confidence among clients handling sensitive or regulated data
- Preparation for more advanced standards and certifications
The certification also creates a useful point of accountability. To answer the assessment accurately, firms must understand which systems are in scope, who has administrative access, how devices are managed, and whether critical security updates are installed consistently. This can expose operational weaknesses that may otherwise remain hidden until an audit, insurance review, or security incident occurs.
TIP: Treat Cyber Essentials Certification as part of a wider evidence-led security programme. The certificate confirms a baseline at a specific point in time, while regulated firms must continue monitoring and maintaining those controls throughout the year.

What Cyber Essentials Certification checks before approval
Cyber Essentials Certification assesses five technical control areas designed to protect organisations from common internet-based attacks. The controls apply to the systems included within the certification scope, which may cover laptops, desktops, servers, mobile devices, network equipment, cloud services, software, and user accounts.
For many firms, the most difficult part is not understanding the controls but applying them consistently across a changing technology environment. Remote workers may use unmanaged devices, Microsoft 365 settings may vary between users, former employees may retain access, or unsupported software may remain active without clear ownership.
The five Cyber Essentials controls are:
- Firewalls: Internet-connected systems must be protected from unauthorised access, with unnecessary ports and services disabled.
- Secure configuration: Devices, applications, and cloud services should be configured securely, with default passwords, unused accounts, and unnecessary functionality removed.
- Security update management: Operating systems, applications, firmware, and other software must remain supported and receive relevant security updates within the required timeframe.
- User access control: Users should only receive the permissions required for their roles, while administrator accounts must be limited and managed separately.
- Malware protection: Organisations must use appropriate measures to prevent malicious software from running, including endpoint protection, application controls, and secure browser or device settings.
The assessment answers must reflect the firm’s real environment rather than its written policies. An organisation may have a patching policy, for example, but still fail if unsupported applications remain installed or critical updates are not deployed consistently. The same principle applies to access control, device management, and Microsoft 365 security.
TIP: Before submitting the assessment, compare every answer against current system reports, user records, software inventories, and security configurations. Any difference between the questionnaire and the live environment should be resolved first.
Cyber Essentials vs Cyber Essentials Plus: which certification is right for your firm?
Cyber Essentials and Cyber Essentials Plus assess the same five technical control areas. The difference lies in how compliance is verified. Standard Cyber Essentials is completed through a verified self-assessment questionnaire, while Cyber Essentials Plus includes an independent technical audit to confirm that the controls described in the questionnaire are operating across the systems within scope.
For smaller firms or organisations responding to an initial supplier requirement, standard certification may provide an appropriate starting point. Cyber Essentials Plus offers a higher level of assurance and may be more suitable when clients, insurers, investors, or procurement teams expect technical verification rather than self-declared compliance.
| Assessment area | Cyber Essentials | Cyber Essentials Plus |
| Control requirements | Covers the five Cyber Essentials technical controls | Covers the same five technical controls |
| Assessment method | Verified self-assessment questionnaire | Self-assessment followed by an independent technical audit |
| Technical testing | No hands-on testing of the environment | Includes internal and external testing of selected systems |
| Evidence level | Demonstrates that the organisation has declared compliant controls | Provides stronger assurance that controls are implemented in practice |
| Typical use | Baseline security, supplier requirements and early certification | Higher-risk contracts, regulated supply chains and stronger client assurance |
| Scope requirements | The firm defines and documents the systems included | The tested scope must match the valid Cyber Essentials certificate |
A business must complete Cyber Essentials before progressing to Cyber Essentials Plus, and the scope used for the technical assessment must match the scope declared during the initial certification. Assessors may also verify that any excluded organisational subsets have been effectively segregated from the systems being assessed.
Choosing the higher certification level does not compensate for unclear scope or incomplete device management. Firms should select the level that matches their contractual and assurance requirements, while ensuring that the underlying controls can be maintained consistently after the certificate has been issued.
Common reasons firms fail Cyber Essentials Certification
Most unsuccessful applications are not caused by a complete absence of cybersecurity controls. Problems usually arise because controls have been implemented inconsistently, the assessment scope is inaccurate, or the answers submitted cannot be supported by the organisation’s current technical configuration.
Regulated firms often operate mixed environments containing Microsoft 365, remote devices, mobile phones, SaaS platforms, legacy applications, third-party support accounts, and personally owned equipment. A single unmanaged device or unsupported application within scope can create a gap that affects the entire application.
Common reasons businesses fail Cyber Essentials Certification include:
- Unsupported operating systems, applications, browser extensions, or network equipment remaining within scope
- Critical or high-risk security updates not being applied within the required 14-day period
- MFA not being enabled across all relevant Microsoft 365 and cloud-service accounts
- Administrator accounts being used for email, web browsing, or routine business activity
- Former employees, contractors, or dormant accounts retaining unnecessary access
- Remote laptops and mobile devices operating outside central device-management policies
- Incomplete software and hardware inventories that prevent the firm from defining its scope accurately
- Cloud services or internet-facing systems being excluded without appropriate justification or segregation
- Assessment answers describing policy intentions rather than the organisation’s live configuration
Support Tree offers a first-attempt pass guarantee for Cyber Essentials and Cyber Essentials Plus, backed by a 100% CE/CE+ pass rate. By identifying and remediating these common gaps before submission, the Root.12 process helps firms approach certification with the controls and evidence already in place.
Under the Cyber Essentials requirements effective from 27 April 2026, MFA must be used for cloud services wherever it is available. The requirements also continue to expect supported software and timely remediation of critical or high-risk vulnerabilities, making Microsoft 365 configuration, patch reporting, and endpoint visibility central to successful preparation.
TIP: Run a technical gap review before opening the formal assessment. Finding an unmanaged laptop, unsupported application, or unprotected Microsoft 365 account before submission is far easier than correcting it within a certification resubmission window.

How Microsoft 365 security affects Cyber Essentials Certification
For many regulated UK firms, Microsoft 365 is one of the most important systems within the Cyber Essentials Certification scope. It may contain corporate email, documents, user identities, administrative accounts, client information, and access to other business applications. Weaknesses within the tenant can therefore undermine otherwise well-managed endpoint and network controls.
Having Microsoft 365 in place does not automatically mean the environment is securely configured. Security settings depend on the organisation’s licence, tenant configuration, access policies, and administrative processes. Microsoft provides Security Defaults across Microsoft 365 business subscriptions, while more detailed Conditional Access and device-management capabilities may require additional licensing and configuration.
Before applying, firms should review:
- Whether MFA is enforced for all relevant users rather than enabled only for selected accounts
- Whether administrative accounts are separated from everyday email and browsing accounts
- Whether former employees, contractors, shared accounts, and dormant users still have access
- Whether legacy authentication and outdated sign-in methods have been restricted
- Whether privileged roles are limited to users who genuinely require them
- Whether emergency access accounts are documented, protected, and monitored
- Whether mobile phones, personal devices, and remote laptops accessing company data are properly governed
- Whether security policies apply consistently across users, groups, and cloud applications
- Whether administrator and sign-in activity can be reviewed when evidence is requested
Device management is particularly important where employees access Microsoft 365 from multiple locations. Microsoft’s device-management tools can apply requirements such as password policies, device compliance rules, approved applications, and controls over access to company data. Without central visibility, firms may be unable to confirm whether every device accessing Microsoft 365 meets the security baseline described in their assessment.
For regulated firms, the objective should not be to activate isolated security features simply to complete the questionnaire. Microsoft 365 controls should form part of a repeatable identity and device-governance process that remains effective when employees join, change roles, work remotely, or leave the organisation.
How to prepare Cyber Essentials evidence before applying
Standard Cyber Essentials is completed through a verified self-assessment, but every answer should still be supported by accurate information from the live environment. Firms should not wait for the application portal to discover that their asset records are incomplete, their patching reports are unclear, or responsibility for a cloud service has never been formally assigned.
The NCSC and IASME provide the current technical requirements and a preview of the self-assessment question set. Reviewing these materials before purchasing or starting the assessment allows the business to map every question to an owner, a technical control, and supporting internal evidence. Firms applying from 27 April 2026 should use the current Danzell question set and version 3.3 of the technical requirements.
A Cyber Essentials readiness file should normally include:
- An agreed description of the certification scope and any organisational subsets
- Current inventories of laptops, desktops, servers, mobile devices, routers, and firewalls
- A list of operating systems, applications, cloud services, and relevant software versions
- Reports showing security updates and vulnerability remediation
- Microsoft 365 user, administrator, MFA, and privileged-role records
- Joiner, mover, and leaver records demonstrating how access is changed or removed
- Evidence that unsupported software and obsolete devices have been removed or isolated
- Device-management reports covering corporate, remote-working, and personally owned devices
- Firewall, router, remote-access, and internet-facing service configurations
- Records explaining any exceptions, exclusions, or temporary remediation actions
A structured Root.12 review can bring these areas together before the application is submitted. Rather than reviewing only the five Cyber Essentials controls in isolation, Root.12 assesses the wider technology estate across 12 areas covering people, systems, and governance. The process can identify technical gaps, assign remediation priorities, improve Microsoft 365 configuration, and build an evidence library that remains useful after certification.
This approach is particularly valuable for FCA-regulated and audit-driven firms because successful certification is only one requirement. Businesses also need to explain how controls are owned, monitored, reviewed, and maintained between annual assessments. By completing the gap analysis and remediation work first, firms can submit answers that reflect their actual security environment rather than assumptions, outdated policies, or incomplete supplier information.

Why Cyber Essentials Certification should be treated as an ongoing security standard
Cyber Essentials Certification gives regulated UK firms a recognised way to demonstrate that essential cybersecurity controls are operating across their technology environment. However, achieving certification requires more than completing a questionnaire. Businesses must understand what is in scope, confirm that their answers reflect live configurations, and provide confidence that controls are applied consistently across users, devices, software, cloud services, and administrative accounts.
For FCA-regulated and audit-driven organisations, the certificate should form part of a wider governance and operational resilience programme. Microsoft 365 security, MFA, patch management, access reviews, and device management all require ongoing ownership after the assessment has been completed. A control that is compliant during the application can quickly become ineffective when new users, applications, devices, or suppliers are introduced without appropriate oversight.
The firms best prepared for certification are those that review their environment before submission, resolve technical gaps, and maintain organised evidence of how controls operate. This reduces the risk of delays or failed assessments while also improving responses to client due diligence, cyber insurance reviews, and regulatory audits.
A structured Root.12 review helps businesses identify weaknesses before they affect the Cyber Essentials Certification application. By connecting technical remediation with clear ownership, evidence management, and continuous governance, regulated firms can approach certification with greater confidence and maintain a stronger security position after the certificate has been awarded.
Preparing for Cyber Essentials or Cyber Essentials Plus? Support Tree can help you identify gaps, complete remediation and prepare for certification through our Cyber Essentials support and Root.12 Framework.
FAQ:
Cyber Essentials Certification is a UK Government-backed scheme that verifies whether an organisation has five core cyber security controls in place. For FCA-regulated firms, certification can provide useful evidence for clients, insurers, procurement teams and auditors, although it does not replace wider FCA governance or operational resilience requirements.
The five Cyber Essentials requirements cover firewalls, secure configuration, security update management, user access control and malware protection. Firms must apply these controls consistently across the systems within scope, including endpoints, cloud services, user accounts and relevant Microsoft 365 environments.
Cyber Essentials uses a verified self-assessment to confirm that the required security controls are in place. Cyber Essentials Plus covers the same controls but adds independent technical testing of systems within scope, providing a higher level of assurance that the controls are working in practice.
Microsoft 365 security can directly affect Cyber Essentials Certification because user accounts, administrator access, MFA and cloud security settings may fall within the assessment scope. Firms should review privileged accounts, dormant users, MFA coverage, device access and security configuration before submitting their Cyber Essentials assessment.
Support Tree offers a first-attempt pass guarantee for Cyber Essentials and Cyber Essentials Plus, backed by a 100% CE/CE+ pass rate. The Root.12 process identifies control and evidence gaps before submission, allowing firms to remediate issues and prepare their environment before the formal assessment.