Cyber Security

Cyber Essentials Questionnaire: What the Questions Ask

Cyber Essentials questionnaire explained for UK SMEs: what each question family means, how to answer honestly and what happens when you submit.

Cyber Security

Cyber Essentials Questionnaire: What the Questions Ask

Cyber Essentials questionnaire explained for UK SMEs: what each question family means, how to answer honestly and what happens when you submit.

Published:

Updated:

A man sits at his kitchen table with his laptop, notebook and yellow coffee mug and prepares to begin work

The Cyber Essentials self-assessment questionnaire is the IASME form that checks whether five basic technical controls are actually in place in your business. It asks how your users, devices and services are protected today, not what your policy says. The question set changed on 27 April 2026, so anyone certifying or renewing now must prepare from the current version. Certificates are valid for twelve months, so for many SMEs autumn is renewal season — and this is the moment when answering honestly and correctly matters most.

This guide explains what the questionnaire covers in plain English, how marking works, and how to prepare answers you can actually defend.

What the questionnaire is — and what it isn't

At the basic level, Cyber Essentials is a verified self-assessment. There is no vulnerability scan and no technical test at this stage. You answer the questions, someone at board level signs a declaration confirming the answers are true, and a qualified assessor reviews and marks what you have written.

The scheme — described by the NCSC as the minimum standard of cyber security recommended by the Government for organisations of all sizes — is built around five technical controls:

  1. Firewalls — controlling how your network connects to the internet

  2. Secure configuration — setting up devices and services safely, removing unnecessary access points

  3. Security update management — keeping software patched and supported

  4. User access control — controlling who can reach your data and services, and at what level

  5. Malware protection — defending devices from malicious software

Your answers must paint a consistent picture across all five controls for everything in scope. Questions are short and specific — if you cannot answer one straight away, that is usually the first sign of a gap worth fixing before you pay for an assessment.

Can you see the Cyber Essentials questionnaire before you buy?

Yes — and you should. IASME publishes the full question set for free in PDF and Excel formats, specifically so organisations can prepare answers before applying. IASME's own guidance is to download the questions in advance and prepare in the spreadsheet; the answers can then be copied into the assessment portal once you have paid.

One warning most guides miss: the question set changes. As of 27 April 2026 there are two versions sitting on IASME's preview page — 'Willow', for anyone who purchased before that date, and 'Danzell', the set to use for purchases from 27 April 2026. If you are certifying or recertifying now, work from the current version. Downloading an out-of-date question set means preparing answers for a form you will not be asked. The April 2026 questionnaire changes are why getting the right version matters.

If you want an even gentler entry, IASME and the NCSC also publish the free Cyber Essentials Readiness Tool — an interactive walkthrough of the requirements that ends with a tailored action plan. Neither tool requires payment, and neither commits you to anything. For broader context on the scheme, our Cyber Essentials guidance for small businesses hub page covers the full framework.

Scoping: where most wrong answers begin

Before any technical question is marked, you describe your scope — the users, devices and services the assessment covers. Everything that holds or moves your business data belongs in that picture: the laptops, the mobiles, the home broadband routers your staff work through, that old NAS storing everyone's folders.

Three honest checks stop most bad answers:

Is anything in scope running unsupported software? This is the answer that guarantees failure. IASME is explicit: an organisation using unsupported software within the scope of the assessment will not attain Cyber Essentials. Windows that no longer receives updates, an end-of-life router, an abandoned business app — find these before the assessor does.

Does a control apply to everyone you claim? If a protection is switched on for some accounts or devices but not others, describing it as universal is not a small exaggeration — it is an inconsistent answer your assessor will bounce, and a board-signed declaration that isn't true.

Do your policies match your practice? A document nobody follows is not a control. Answer for what happens on an ordinary Tuesday, not what the handbook says.

What happens when you submit

The process has firm clocks worth knowing before you pay:

Once you have paid, you have six months to complete and submit your assessment. After that the account is closed and the fee is not refunded.

After submission, most assessors aim to return results within about three days. If an answer lacks enough information, it comes back to you for more detail.

If you are not fully compliant, you get written feedback against each question, two working days to fix what can be fixed and resubmit — the assessor aims to remark within another three days without extra charge. Fail again and you must reapply and pay the assessment fee again.

A pass gives you a certificate valid for 12 months. Renewal is not a rubber stamp: IASME requires you to re-enter all information each year — it works as an annual review of your security — and questions may have changed since last time. Keep a copy of your submitted answers; they are the starting point for next year's.

On cost: IASME's own published assessment fees are tiered by organisation size — 320 pounds plus VAT for micro organisations (0-9 employees), 440 pounds plus VAT for small (10-49), 500 pounds plus VAT for medium and 600 pounds plus VAT for large. Other licensed certification bodies set their own prices.

How to prepare your answers — a practical sequence

  1. Download the current question set (Danzell, for purchases from 27 April 2026) and the requirements document from IASME's preview page and the NCSC.

  2. Write your scope in plain English: users, devices, services, locations — including home working.

  3. Inventory what runs where. Flag every unsupported operating system, device or application inside the scope.

  4. Check who holds admin rights and why. Broad admin access trips up more SMEs than they expect.

  5. Draft answers in the preparatory Excel, with a note beside each on where you could evidence it.

  6. Only buy the assessment when every answer describes what is actually in place.

  7. Keep your submitted answers when you pass — you will need them at renewal.

If you want worked examples of what "ready to answer" looks like in a Microsoft 365 environment, our Cyber Essentials evidence checklist for Microsoft 365 sets out the practical information to gather against each control.

What about Cyber Essentials Plus?

Cyber Essentials Plus begins with the same self-assessment questionnaire and adds a technical audit: internal and external vulnerability scans, and hands-on testing of a random sample of your systems (typically around 10 per cent of user devices, plus all internet gateways and servers accessible from the internet). The controls themselves are identical — what changes is the level of assurance, because a third party verifies that what you described is what is actually running. If your answers were honest first time, the questionnaire stage simply gets re-tested. IASME notes that if your basic certification completed within the last three months, you do not repeat the self-assessment stage for Plus, and the two can be taken together.

Frequently Asked Questions

How long does the Cyber Essentials questionnaire take?

There is no fixed time limit, but once you have paid for the assessment you have six months to complete and submit it. The questions themselves are short — most SMEs can draft answers in a few hours if they know their estate well. The real time investment is gathering evidence: inventorying devices, checking software support status, and confirming who holds admin rights. If you have never done this before, budget a few days for the initial research phase.

What evidence do I need before I answer?

You need to know what is actually in place, not what should be true. That means having a current inventory of all devices and services in scope, confirmation that every operating system within scope is still receiving security updates, a list of who holds administrative rights on each device, and evidence that malware protection is active on every in-scope endpoint. If you cannot point to a system or process for any single question, that is a gap worth closing before you submit.

What is the difference between IASME and the questions themselves?

IASME is the accreditation body that runs the Cyber Essentials scheme. The questions are the actual content of the self-assessment form — the five technical control families (firewalls, secure configuration, security update management, user access control, malware protection) with specific yes/no questions under each. IASME publishes the questions for free; assessors (who may work for IASME or other licensed certification bodies) review your completed answers. The NCSC sets the standard; IASME runs the certification scheme, and the questions are the tool used to check compliance with it.

What if I cannot answer one of the questions?

If you genuinely cannot answer a question, do not guess. You have two honest options: either close the gap before you submit (for example, install endpoint protection if it is missing), or exclude that system from your scope if it genuinely does not hold or process any business data. Guessing or aspirational answering is what causes failures — the board-signed declaration means every answer must reflect reality, not intention. Fix the gap or remove it from scope.

When the questionnaire isn't the hard part

Most businesses that stumble on the Cyber Essentials questionnaire do not have a form problem — they have an unknown-environment problem. The questions force you to say, in writing, what protects every device, who can reach what, and whether anything running is no longer supported. Answering honestly requires knowing your own estate, and keeping it worth certifying month after month is an operating discipline, not an annual filing exercise.

If you are preparing for the questionnaire and your answers depend on checking what is actually enforced — or you would rather understand your gaps against the Cyber Essentials baseline before you pay for an assessment, book a Security Triage Call. It is a conversation, not a free audit, and it is not a shortcut to certification. If you then want a formal, evidenced review of your controls, that is a separate paid Security Baseline Review.

You can explore more practical guidance across the scheme on our Cyber Security and Cyber Essentials hub, including how Cyber Essentials Plus differs from the self-assessment.

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.