- First step
- Read the assessor feedback
- Common cause
- MFA & patching auto-fails
- Route back
- Remediate & resubmit
- We help
- Pass on the next attempt
What a fail actually means
A Cyber Essentials fail isn't a black mark — it's a list of things to fix. The assessor tells you which answers didn't meet the standard, you remediate, and you resubmit. Depending on your certification body and where you are in the assessment window, you may be able to correct and resubmit quickly.
The common 2026 reasons for failing
Since April 2026 the marking is stricter, with genuine automatic fails. The usual culprits:
- Missing MFA on a cloud service. Multi-factor authentication must be enabled wherever it's available, and it's mandatory on cloud services. A gap here is now an automatic fail.
- Slow patching. Critical or high-risk security updates must be applied within 14 days — for operating systems, applications, and router/firewall firmware. Beyond that is an automatic fail.
- Unsupported software. Anything past end-of-life and still in scope will fail you.
- Scope and cloud gaps. Under the new rules all cloud services are in scope, and exclusions need clear justification. Vague scope trips people up.
- Default credentials and weak configuration. Kit still on default passwords, or insecure defaults left in place.
How to pass next time
Prioritise the automatic fails first — MFA everywhere and patching within the window usually clear most of it. Then fix the smaller configuration and scope issues. The mistake to avoid is resubmitting the same setup hoping for a different marker; fix the root cause, then go back in.
How we help
Send us the feedback you were given. A certified IASME assessor will translate it into a clear fix list, help you close the gaps, and get you through the re-assessment — so the second attempt is a pass, not another fail.
Common questions
Do I lose my fee if I fail?
Not the way people fear. You're told what to fix and you resubmit; depending on your certification body and timing, corrections can often be made within the assessment window. The goal is to get you certified, not to catch you out.
Why did we fail on MFA when we thought we had it?
The 2026 rules require MFA wherever it's available, and it's mandatory on cloud services — a single cloud app without it is now an automatic fail. It's the most common reason we see.
How long do we have to fix and resubmit?
It depends on your certification body and where you are in the assessment window. Send us the feedback and we'll tell you your realistic route and timeline.
Can you help us pass after a fail with someone else?
Yes. We take the feedback you were given, turn it into a concrete fix list, help you remediate, and support you through the re-assessment.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day