Nobody asks this question casually. It is asked quietly, usually by someone who has read the question set properly for the first time and realised they are less certain than they were an hour ago.

So, plainly: failing a Cyber Essentials assessment is not a disaster, it is not public, and for most organisations it is not even expensive. What it is, is information you did not have before, delivered by someone whose job is to be specific about it.

Not publicThere is no register of failed assessments
2 daysWorking days to fix and resubmit, at no extra cost
FeedbackYou are told exactly what fell short

What actually happens

You submit your answers. A qualified assessor marks them, normally within three working days, and there are three possible outcomes.

Pass. The certificate is issued immediately, along with a verifiable digital badge.

More information needed. The assessor is not satisfied that an answer demonstrates what it needs to, and asks for clarification. You have two working days to respond. This is common, it is not a failure, and it frequently means an answer was true but under-described.

Unsuccessful. Something in your submission does not meet the requirements. You are told what, in detail. You then have two working days to make the necessary changes, update your answers and resubmit at no additional cost.

That resubmission window is the part people do not expect. A failure is not the end of the application; it is a defined opportunity to fix something and try again inside the same fee, provided you move quickly.

What it costs

If you resubmit inside the window: nothing extra. The assessment fee you paid covers it.

If you miss the window: the application closes and certifying later means a new application and a new fee. That is the real cost of failing, and it is entirely avoidable by treating those two days as a priority rather than an inconvenience.

If the fix itself takes longer than two days, which happens when the finding is unsupported software or a device that needs replacing, the honest position is that you were not ready to submit. That is worth knowing now rather than at renewal, and it is exactly the situation a scoping conversation beforehand is designed to prevent.

What failing does not mean

It is worth being explicit about this, because the anxiety usually exceeds the reality.

There is no public register of unsuccessful assessments. Your customers are not told. Your insurer is not told. Nothing is published, nothing is flagged, and no record follows your organisation around. The only people who know are the ones you tell.

Failing also does not mean your security is bad. Assessments are frequently unsuccessful on a single specific point in an otherwise well-run environment, and the fix is often smaller than the organisation feared.

The reframe worth making

An assessment that finds nothing wrong tells you nothing you did not already believe. An assessment that finds something has just told you, for a fixed fee, about a weakness that was there yesterday and would still have been there next year. The certificate is the goal, but the finding is the value.

What we see fail most often

Five things account for the overwhelming majority.

Unsupported software in scope. Software no longer receiving vendor security updates cannot remain inside the boundary. This is the failure that cannot be fixed in two days, because replacing an operating system or a line of business application is a project. Check it before you submit, not after.

Missing multi-factor authentication on cloud services. Usually not on the main platform, which everyone remembers, but on the accounting package, the file sharing service or the tool somebody signed up for during a trial.

Administrator accounts used for everyday work. Administrative accounts must be separate from the accounts people work in, and must not be used for email or browsing. We covered the whole subject in administrator account security.

Security updates beyond 14 days. High and critical updates must be applied within 14 days of release. Organisations are often confident here and often wrong, because automatic updates do not cover everything and nobody checks what they missed.

An incomplete picture. Cloud services nobody listed, devices nobody counted, home workers nobody considered. Scope errors rather than security errors, and entirely preventable: our scope guide covers what belongs inside the boundary.

How to not be in this position

The straightforward answer is to find out what would fail before you pay for an assessment rather than after.

Read the requirements and the question set, both free to download. Work through our preparation guide and the five things that most commonly fail an assessment. Check for unsupported software first, because it is the only finding that cannot be resolved inside the resubmission window.

Then, if anything is unclear, have the conversation before you submit. As a licensed certification body we would far rather tell an organisation it is not ready yet than mark it unsuccessful a fortnight later. Nobody enjoys that outcome, least of all the assessor.

If you have already failed

Do these in order.

  1. Read the feedback properly. It is specific, and it tells you exactly which requirement was not met.
  2. Decide, honestly, whether it is fixable in two working days. Configuration changes usually are. Replacing hardware or software is not.
  3. If it is, fix it, update the affected answers and resubmit inside the window.
  4. If it is not, stop and plan. Do a proper remediation piece, then come back and certify. Rushing a resubmission you cannot substantiate wastes the attempt and helps nobody.
  5. Ask the assessor if anything is ambiguous. They marked it; they can tell you what evidence would satisfy the requirement.

Get in touch or call 01722 445972. Whether you are preparing, mid-application or picking yourself up after an unsuccessful attempt, we will tell you plainly what needs to change and how long it is likely to take. Our Cyber Essentials certification page sets out the service and publishes the pricing.