Cyber Essentials self-assessment questions: what to prepare
By Muhammad Sohaib Roomi, founder and reviewer at BrightCertPublished Reviewed
Part of our plain-English Cyber Essentials guide
Short answer
The Cyber Essentials self-assessment is an online questionnaire you complete and submit through an IASME-licensed Certification Body, where an assessor marks it. Since it uses the Danzell question set. It asks who you are, what you are putting in scope, and how you meet each of the five controls. Answering it takes hours; gathering what the answers depend on is the part that takes weeks, so the useful move is to collect that information before you open the form.
Almost everybody searching for the Cyber Essentials questionnaire wants the same thing: to know what they are walking into. That is a reasonable instinct, and the answer is slightly different from the one people expect. The questions are not the hard part. Being able to answer them is.
What the self-assessment actually is
Cyber Essentials is a self-assessed certification. You answer the questionnaire yourself, and a qualified assessor at an IASME-licensed Certification Body marks your answers against the requirements. There is no audit of your systems at this level — that is Cyber Essentials Plus, which adds an independent technical audit on top of the same self-assessment.
Two things follow from that. Your answers are taken at face value, so they need to describe what is genuinely in place. And because they are marked rather than negotiated, an answer that does not meet the requirement comes back for correction, which costs you time you had not planned for.
Since the question set is called Danzell, replacing Willow, and the underlying requirements are v3.3. If you are renewing and reaching for last year’s saved answers, that date is the one to check first.
What each part asks about, and who in your business holds the answer
The table below maps the assessment to the information it needs from you. The third column is the one worth reading closely. Preparation is usually described as a technical task, but look at where the answers actually live: a director, an IT provider, HR, finance. That is the real reason a questionnaire you could answer in an afternoon takes a fortnight.
| Part of the assessment | What it needs from you | Who usually holds it |
|---|---|---|
| Your organisation | The registered name exactly as it should appear on the certificate, the registered address, your employee count for the fee band, and the person senior enough to sign the declaration. | A director, or whoever files at Companies House |
| Scope | A written description of what you are certifying — the whole organisation, or a clearly defined part of it — covering locations, networks, and the cloud services it touches. | Rarely one person: it needs the org chart and the IT estate together |
| Devices | Every device type that reaches organisational data: laptops, desktops, servers, mobiles, tablets, and personally owned devices in scope. Operating system and version for each, and whether the vendor still supports it. | Your IT provider, or whoever hands out laptops |
| Cloud services | The full list of cloud services actually in use, and for each one whether multi-factor authentication is offered and whether it is switched on for everybody who uses it. | Finance often knows more than IT here — unlisted subscriptions show up on the card statement |
| Firewalls and the network boundary | What sits at each internet boundary, confirmation that default administrative passwords were changed, and a reason for every inbound rule that is open. | Your IT provider or managed service provider |
| People and access | A current user list marking which accounts hold administrative rights, how those rights get approved, and your leaver process with a recent example of it actually running. | HR and IT together, which is why this one stalls |
| Updates and malware protection | How you apply critical and high-risk security updates against the 14-day window, and which malware protection approach covers each device type. | Your IT provider |
| Insurance | Your annual turnover figure. UK organisations turning over under £20 million are offered the included Cyber Liability Insurance, so the assessment asks. | Finance |
If you want this as something to work through and tick off, the Cyber Essentials checklist covers the same ground as a printable list with owner and status columns.
What separates an answer that passes from one that comes back
Assessors are not looking for polished writing. They are checking whether the arrangement you describe meets the requirement, for everybody it needs to cover. Four things distinguish answers that clear that bar:
- It covers everyone, not the case you thought of first. “We have multi-factor authentication” and “multi-factor authentication is enabled for every user of this service” are different statements, and only the second one answers the question. The same gap appears with devices: the answer describes the company laptops and quietly omits the two people using their own.
- It describes today, not the plan. Work that is scheduled for next month is not in place. Answering as though it were converts a gap you could have closed into a correction after marking.
- It is specific about the arrangement.“We patch regularly” does not engage with the requirement; “critical and high-risk updates are applied within 14 days, checked monthly by our IT provider” does.
- Somebody could check it. If the answer rests on memory rather than a list, a setting or a record, it will not survive the follow-up question.
When the honest answer is no
Every organisation preparing for the first time finds something it does not yet do. That is what preparation is for, and finding it before submission is the good outcome rather than the bad one.
The temptation is to answer optimistically — to say yes because the fix is easy and somebody will get to it. It rarely works out cheaper, and there is a specific reason why. The certification fee includes one free resubmission if you do not pass first time. After that, another failed attempt means paying the fee again.
So an optimistic answer is not free. It spends the one correction you were given, on something you already knew about, and leaves you with none in hand for the thing you genuinely missed. Close the gap, then answer yes. If closing it will take longer than the time you have, that is a scheduling conversation, not a wording one.
Where preparation usually stalls
Across the five controls, the same four things account for most of the delay. None of them are difficult. All of them take longer than a day because they need somebody else.
- The cloud services list. The list held by whoever manages IT and the list of services actually in use are almost never the same. Departmental sign-ups, tools attached to a personal login, and anything inherited from a previous supplier all belong on it.
- Personally owned devices. A personal phone used to check work email is in scope for the controls that apply to it. Deciding that personal devices may not reach organisational data is a legitimate answer — provided it is genuinely enforced rather than merely stated.
- The leaver process. Most organisations have one. Fewer can point to it running for the last person who left, which is the form the question effectively takes.
- Software past end of life. This one cannot be patched into compliance, because the updates no longer exist. It needs replacing or removing from scope, and both take planning.
Why this guide does not list the questions
The Danzell question set belongs to IASME, and it is not ours to republish. IASME publishes its own preview of the self-assessment questions, linked at the foot of this page, and that preview is the version that stays current when the question set changes — as it did on 27 April 2026.
There is a practical reason as well as a licensing one. A copied question list goes stale the day the set is updated, and a business preparing against a stale copy is doing the one thing this guide exists to prevent. What does not go stale is the information you need to have gathered, and who in your organisation holds it.
Frequently asked questions
What is the Cyber Essentials self-assessment questionnaire?
It is an online questionnaire completed by the organisation seeking certification and submitted through an IASME-licensed Certification Body, where an assessor marks it. It covers who you are, what you are putting in scope, and how you meet each of the five Cyber Essentials controls.
Can I see the Cyber Essentials questions before I apply?
Yes. IASME publishes a preview of the self-assessment questions on its own website, and reading it before you start is worth the time. This guide does not reproduce that question set — it explains what each part of the assessment needs from you so that you can gather it first.
Which question set is current in 2026?
Danzell. It replaced Willow on 27 April 2026, the same day Cyber Essentials requirements moved to v3.3. Answers written before that date were written against a different question set, which matters most at renewal.
How long does the Cyber Essentials self-assessment take?
Answering it is a matter of hours. Gathering the information the answers depend on is what takes most organisations weeks, because it sits with several different people and no single person can complete the form alone.
What happens if the honest answer to a question is no?
It is a gap to close, not a disqualification. The mistake that costs organisations time is answering yes for something that is planned rather than in place. The fee includes one free resubmission if you do not pass first time, so an optimistic answer spends that correction on a gap you already knew about, and leaves nothing in hand for one you did not.
Does BrightCert submit the self-assessment for me?
No. The self-assessment is submitted through an IASME-licensed Certification Body, which is who issues the certificate. BrightCert assesses your readiness beforehand, scores it, and shows you which gaps to close first.
Answer 60 plain-English questions about your organisation and see where the gaps are before you open the official self-assessment.
Start your assessmentBrightCert helps UK businesses prepare for Cyber Essentials by assessing readiness, identifying gaps, and producing a practical report. BrightCert does not issue the official Cyber Essentials certificate. That comes from an IASME-licensed Certification Body.
Sources: IASME: preview the self-assessment questions · NCSC: Cyber Essentials resources
