A Cyber Essentials application can look straightforward until the questionnaire reaches the people who must answer it. The questions cover everyday controls, but accurate answers depend on knowing how your organisation actually manages devices, accounts, software and updates. This guide to Cyber Essentials questionnaire answers will help you prepare properly, reduce last-minute uncertainty and turn certification work into practical security improvement.
Cyber Essentials is not a test of whether you have the most expensive security tools. It assesses whether essential controls are in place and applied consistently within the scope of your application. For a growing business, school, charity or manufacturer, that consistency is usually where the work lies.
Start with scope before answering anything
The most common early mistake is treating the questionnaire as a generic description of the business. It is an assessment of the systems and people included in scope. Before assigning questions, write down the organisation, sites, users, devices, cloud services and home-working arrangements that are covered.
Most organisations include their whole IT estate. That is often the clearest and most useful approach, particularly where staff share services such as Microsoft 365, a central firewall, internet connection or device management platform. A narrower scope may be appropriate in some circumstances, but exclusions must be genuine, clear and defensible. You cannot exclude a device simply because it would make an answer more difficult.
Be especially careful with personally owned devices, mobile phones, tablets and home computers. If they access business email, files, systems or remote-desktop services, they are likely to matter. The same applies to third parties that administer systems on your behalf. Outsourcing a service does not outsource your responsibility to understand the control.
Treat the questionnaire as an evidence exercise
The questionnaire requires declarations, not a folder of evidence submitted with every answer. However, the strongest way to complete it is to work as though each response could be checked. Cyber Essentials Plus involves independent technical verification, while the standard certification relies on the accuracy of your self-assessment. Either way, unsupported assumptions create risk.
For each answer, identify three things: the person who owns the control, the system that enforces it and the evidence that shows it is operating. For example, an IT manager may own account security, Microsoft 365 may enforce multi-factor authentication, and configuration reports or policy settings may demonstrate coverage.
This approach also prevents a familiar problem: answering “yes” because a policy exists, when the setting has not been applied to all users or devices. A written policy is useful, but it is not a substitute for implementation.
Build a small working group
One person should coordinate the application, but they should not be expected to know every detail. Bring together the relevant people from IT, operations, HR and, where needed, an external IT provider. Finance or procurement may also need to confirm software subscriptions and hardware replacement plans.
Keep the process controlled. Record each question, the proposed answer, who confirmed it and any action needed before submission. This avoids contradictory answers and gives management a clear view of outstanding risk. It is also useful when the certificate needs renewing.
Your guide to Cyber Essentials questionnaire control areas
The precise wording and format of the assessment can change, so always work from the current questionnaire supplied through the certification process. Its themes are consistent, however: boundary security, secure configuration, access control, malware protection and security update management.
Boundary security and internet connections
Questions in this area establish how your organisation controls traffic between its systems and the internet. In practical terms, this usually means understanding your firewall, router or cloud security controls, who can change them and whether unnecessary services have been exposed.
Do not answer based on the presence of a box in the comms cabinet. Check that the device is supported, receives updates and has a managed configuration. Default administrator passwords, old remote-management interfaces and undocumented firewall rules are all warning signs. If remote access is required, make sure it is designed, authorised and protected rather than left available for convenience.
Secure configuration
Secure configuration covers the settings that reduce unnecessary exposure on laptops, desktops, servers, mobiles and cloud services. The questions may cover user privileges, password and authentication settings, removal of unused accounts, installed software and the configuration of devices when they are first issued.
The key principle is least privilege. Staff should normally use standard user accounts for day-to-day work. Administrative access should be limited to people who need it, with separate administrator accounts where appropriate. This can feel less convenient for a small team, but it sharply reduces the impact of a compromised account or accidental change.
For cloud platforms, verify the settings rather than relying on supplier defaults. Microsoft 365, for example, can be configured securely, but licences alone do not guarantee that multi-factor authentication, conditional access, external sharing and administrator roles are set correctly.
Access control and multi-factor authentication
Access control questions are often where organisations discover a gap between policy and practice. You need to know who has access to what, how new starters are set up and how quickly access is removed when someone leaves or changes role.
Multi-factor authentication is a central safeguard for internet-facing services. Check coverage for email, cloud storage, remote access, administrator accounts and any other system accessed from outside the organisation. Consider service accounts and shared accounts carefully. Shared credentials make accountability difficult and can create obstacles when a member of staff leaves.
There are legitimate operational exceptions in some environments, particularly around older equipment or specialist software. The right response is not to ignore them. Document the constraint, reduce exposure where possible and agree a realistic remediation plan. It may affect whether you are ready to certify now.
Malware protection
Malware protection is more than installing antivirus software. The questionnaire considers whether protection is active, current and managed across relevant devices. That may be traditional endpoint protection, a managed detection service, application controls or a combination of measures, depending on your systems.
Confirm that devices are not silently falling outside management. Remote workers, spare laptops, workshop machines and newly purchased devices are frequently missed. Also check how alerts are monitored. A security tool that raises an alert but has no defined response process offers less protection than management reports suggest.
Security updates
Patch management is one of the most operationally demanding areas because it involves every supported operating system, application, mobile device, firewall and cloud-managed service in scope. The question is not simply whether updates are available. It is whether critical and high-risk updates are applied within the required timeframe and whether unsupported software has been addressed.
Create an asset list before you answer. Include device type, operating system, main applications, support status and patching method. Automatic updates can be appropriate for many systems, but business-critical or production equipment may need testing and scheduled maintenance windows. That is a valid trade-off, provided the process still meets the required timescales and risks are managed.
Avoid answers that are technically true but incomplete
Cyber Essentials questionnaires reward precision. A statement such as “we use multi-factor authentication” may be true, but it does not answer whether it covers every relevant service and user. Likewise, “our provider handles updates” is incomplete unless you know which assets they manage, what is excluded and how compliance is reported.
Take particular care with legacy systems. Older production machinery, specialist education software and line-of-business applications can be difficult to patch or upgrade. These systems should be identified early, not discovered during the final review. Sometimes segmentation, restricted access and a planned replacement are sensible interim measures. Sometimes the risk means certification should wait until the system is brought up to standard.
Make certification useful after submission
The value of Cyber Essentials is not the certificate on its own. It is the discipline of knowing your technology estate, assigning responsibility and removing avoidable weaknesses before they cause disruption. Keep the asset list, access review records and configuration decisions current rather than recreating them at renewal time.
If your team is unsure whether a control is working as intended, investigate before submitting a confident answer. A short period spent validating settings, patching overlooked devices or clarifying provider responsibilities is far less disruptive than responding to a security incident later. CETSAT can help organisations translate the questionnaire into practical actions that fit their systems, people and budget.

