P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Free tool

Cyber Essentials v3.3 readiness check

Which answers fail the assessment outright, and which merely cost you points. Updated for the April 2026 requirements. No sign-up.

Cyber Essentials is pass or fail, and a handful of answers fail the whole assessment whatever else is true. Every free readiness checker in this category is published by a certification body whose real product is selling you the certification, and none of them lead with that list. This one does. It is built on the April 2026 requirements, v3.3, where multi-factor authentication became an outright failure condition rather than a recommendation.

Nothing leaves your browser: Your answers describe exactly where your security controls fall short, which is not a list to hand to anyone in exchange for a PDF. Nothing is submitted and nothing is stored, the page is served with a Content Security Policy whose connect-src 'none' rule blocks fetch, XHR, WebSocket, EventSource and sendBeacon, and you export the plan yourself. A policy inside the page cannot stop you copying the result somewhere else, so what you do with it afterwards is yours to protect.

Last reviewed:
Open data: download the full dataset as JSON

Cyber Essentials v3.3

Not yet assessed

Answer the questions below. Nothing is submitted and nothing is stored.

This is where v3.3 tightened hardest. Accounts outlive the reason they were created, and administrative rights spread quietly.

  1. Fails outrightNew in v3.3

    Is MFA enabled on every cloud service that offers it?

    This is the change with teeth. MFA is mandatory wherever a cloud service makes it available, and it makes no difference whether the feature is free, bundled or costs extra. Leaving an available MFA option switched off fails the assessment outright.

  2. Do administrators use separate accounts for administrative work and for email and browsing?

    One of the oldest requirements and still one of the most commonly failed, usually because it is inconvenient rather than because anyone disagrees with it.

  3. New in v3.3

    Do your password rules meet one of the scheme's accepted combinations, rather than being whatever the system defaulted to?

    The scheme accepts more than one route, combining length with MFA or with a deny-list of common passwords. What it does not accept is a policy nobody chose.

  4. Are accounts removed promptly when someone leaves or changes role?

    Assessors sample this. A dormant account belonging to someone who left is the finding that undermines everything else you say about access control.

  5. Is there a documented approval step before an account is created or given administrative rights?

    The scheme wants a process, not a recollection. Being able to say who approved a given administrator is the evidence.

The answers that fail you outright

Cyber Essentials is pass or fail. Most questions cost you a pass on that question; a small number fail the entire assessment whatever else is true. Knowing which is which before you open an assessment account is worth more than any score, because opening the account starts a six month clock.

Is MFA enabled on every cloud service that offers it?

This is the change with teeth. MFA is mandatory wherever a cloud service makes it available, and it makes no difference whether the feature is free, bundled or costs extra. Leaving an available MFA option switched off fails the assessment outright.

A6.4

Are high-risk and critical updates for operating systems, routers and firewall firmware installed within 14 days of release?

Question A6.4. Answering no fails the assessment. Router and firewall firmware is the part that catches people, because it is rarely on the same patching cycle as the estate.

A6.5

Are high-risk and critical updates for applications, including their extensions and plug-ins, installed within 14 days of release?

Question A6.5, and also an outright failure. Extensions and plug-ins are explicitly included, which is where browser add-ins and content management plug-ins land.

How certification actually runs

The order matters more than people expect. The six month window starts when the assessment account is created, not when you submit, so opening one before you know the answers spends time you may need.

Cyber Essentials, start to certificate

  1. Step 1Define scope
  2. Step 2Self-assess
  3. Step 3Remediate
  4. Step 4Open account
  5. Step 5Submit and certify
Self-assessment is answered under declaration by a board-level representative. Cyber Essentials Plus adds an independent technical test of the same five controls.

Steps three and four are the ones organisations reverse. Remediating first is slower to start and very much faster to finish.

The five technical controls

Firewalls

Something between your devices and the internet, configured rather than merely present.

Almost every device ships with a firewall and almost nobody checks what it permits. The control is about the rules, not the box.

Secure configuration

Devices and services set up deliberately, with what you do not need removed.

Default configurations are built to work on first boot, not to be defensible. Accounts, services and software you never chose are the exposure.

User access control

People have the access their job needs, and prove who they are properly.

This is where v3.3 tightened hardest. Accounts outlive the reason they were created, and administrative rights spread quietly.

Malware protection

Something stopping malicious code running, by one of the approved routes.

There is more than one acceptable answer here, and the scheme accepts allow-listing and sandboxing as well as anti-malware software.

Security update management

High-risk and critical updates applied within fourteen days, everywhere in scope.

The clearest, hardest number in the scheme. It is also the one most often failed, because the fourteen days apply to everything in scope and not just to servers.

What changed in v3.3

The requirements document was updated for April 2026. The headline is MFA: leaving an available multi-factor option switched off on a cloud service now fails the assessment, and it makes no difference whether the feature is free, bundled or costs extra.

  • Have you identified every internet-accessible service that stores or processes your data, and included it in scope?v3.3 defines a cloud service formally for the first time and confirms cloud services cannot be scoped out. The list is almost always longer than the one finance knows about.
  • Can you justify to an assessor anything you have excluded from scope?v3.3 removed the vaguer scoping language and now expects any internet-connected device to be in scope unless you can explain the exclusion.
  • Is MFA enabled on every cloud service that offers it?This is the change with teeth. MFA is mandatory wherever a cloud service makes it available, and it makes no difference whether the feature is free, bundled or costs extra. Leaving an available MFA option switched off fails the assessment outright.
  • Do your password rules meet one of the scheme's accepted combinations, rather than being whatever the system defaulted to?The scheme accepts more than one route, combining length with MFA or with a deny-list of common passwords. What it does not accept is a policy nobody chose.

On the exact date

IASME’s own change notices give different cutover days for v3.3, one saying assessment accounts created after 27 April 2026 and another after 26 April, and several published summaries say 28 April. The substance is not in dispute and the day only matters if you are opening an account in that week. Rather than pick one and present it as settled, this page says they disagree: confirm with your certification body if you are near the boundary. Accounts opened before the change keep the previous question set and have six months to certify against it.

Use the data

The full question set, the control structure and the outright-failure flags are published as JSON under CC BY 4.0. The flags are the part worth having: they turn a checklist into a decision about whether to open an assessment account yet.

Sources: IASME: changes to Cyber Essentials for April 2026; IASME: upcoming changes to the Cyber Essentials scheme. Not affiliated with IASME or the NCSC.

What this is not

It is not certification, and it is not the assessment. The real self-assessment is answered under declaration by a board-level representative, and Cyber Essentials Plus adds an independent technical test of the same five controls on a sample of your devices. Passing here means your answers would pass; it says nothing about whether the evidence behind them holds up when someone looks.

It also cannot define your scope, which is the decision everything else depends on. v3.3 tightened exactly that: any internet-connected device is in scope unless you can justify the exclusion to an assessor, and cloud services can no longer be left out at all.

Common questions

What fails a Cyber Essentials assessment outright?

Leaving multi-factor authentication switched off on any cloud service that offers it, and missing the 14-day window for high-risk or critical security updates. The update requirement is split across two questions: A6.4 covers operating systems, routers and firewall firmware, and A6.5 covers applications including their extensions and plug-ins. Answering no to any of these fails the assessment regardless of how well you do elsewhere.

What changed in Cyber Essentials v3.3?

MFA became mandatory for every cloud service that makes it available, and it makes no difference whether the feature is free, bundled or costs extra. A cloud service is formally defined for the first time and cloud services can no longer be scoped out. Scoping language was tightened so that any internet-connected device is in scope unless you can justify the exclusion. There is more emphasis on passwordless authentication and passkeys, and backup guidance moved earlier in the document.

When does v3.3 apply?

To assessment accounts created from late April 2026. Accounts opened before that keep the previous question set and have six months to certify against it. Worth knowing: IASME's own change notices give different days, one saying after 27 April and another after 26 April, and other summaries say 28 April. If you are opening an account in that week, confirm the position with your certification body rather than relying on any published summary, including this one.

Does Cyber Essentials cover cloud services?

Yes, and v3.3 removed any remaining ambiguity. Any internet-accessible service that stores or processes your organisation's data is in scope, and the list is almost always longer than the one finance knows about. The practical exercise is to inventory what staff actually use rather than what was procured.

How long does Cyber Essentials take?

The assessment itself is a questionnaire that can be completed in a day. The time goes into remediation beforehand, and the sequencing catches people out: the six-month window starts when the assessment account is created, not when you submit. Remediating first and opening the account second is slower to start and considerably faster to finish.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The same five controls and the same requirements. Cyber Essentials is a self-assessment answered under declaration by a board-level representative; Plus adds an independent technical test on a sample of your devices. Plus does not raise the bar, it verifies that the answers you gave were true, which is why an honest self-assessment is the right preparation for it.

When you need more than a tool

ISO/IEC 27001 Implementation and Remediation

Full-cycle ISO/IEC 27001 consultancy: gap analysis, ISMS implementation, remediation of failed audits, and internal audit cycles, led by a Lead Auditor with six programmes taken through certification.

Plan your certification

Share this tool

Free, no sign-up, and nothing you type leaves your browser.

Related analysis

← All free tools