The Cyber Essentials questionnaire is the whole of the basic certification: you answer it, a board-level signatory declares it accurate, and an assessor marks it. From April 2026 the questions come from a new set called Danzell, and it is stricter than the one it replaced — several answers now fail the assessment outright.
This guide covers what the questionnaire asks, what changed with Danzell, the auto-fail answers, and how to prepare so the submission is a formality rather than a discovery exercise.

What the Cyber Essentials questionnaire is
Cyber Essentials is a self-assessment scheme. There is no site visit and no evidence upload at the basic level: the assessor marks your written answers against the scheme’s requirements, and a board member, owner or equivalent signs a declaration that the answers are true. That declaration is the reason the questionnaire is worth taking seriously — it is a statement by the organization, not a form filled in by IT.
The Cyber Essentials questionnaire is grouped into a scope section followed by the five technical controls: firewalls, secure configuration, security update management, user access control, and malware protection. Our guide to Cyber Essentials certification covers what each control requires.
Scope is the section that decides the outcome
The Cyber Essentials questionnaire asks what is in scope before it asks anything technical, and every later answer is read against that boundary. Whole-organization scope is the default expectation; a narrower scope is permitted but has to be described, and what sits outside it has to be described too. Devices in scope include the laptops, desktops, tablets, phones, servers, firewalls, routers and cloud services used to access organizational data or services — including devices owned by staff and used for work.
What Danzell changed
IASME’s update states the new Cyber Essentials questionnaire came into force on 26 April 2026, with a six-month grace period for organizations whose assessment accounts already existed. The five core controls are unchanged. What changed is the strictness:
| Change | What it means for your answers |
|---|---|
| Auto-fail answers | Certain answers end the assessment rather than costing marks |
| MFA on cloud services | Required wherever the service offers it — no longer a partial answer |
| Patching within 14 days | High-risk and critical updates for operating systems, routers and firewall firmware, and for applications |
| Scope transparency | Unlimited-length scope descriptions, and out-of-scope areas must be documented |
| Legal entities named | Names, addresses and company numbers, with individual certificates available per entity |
| Stronger declaration | The signatory now acknowledges responsibility for maintaining the controls throughout the certification period |
That last row is a quiet but real change. Certification was already a point-in-time statement; the declaration now says plainly that the controls are expected to hold for the year, not just on submission day.
Preparing for the Cyber Essentials questionnaire
- Build the asset list first. Every device and cloud service that touches organizational data, with make, operating system and version. Most failed answers trace back to an inventory that was never complete.
- Check the unsupported software. Anything past end of support inside scope has to go, be replaced, or be segregated out of scope — and the segregation has to be real.
- Turn on MFA everywhere it is available. Administrative accounts first, then all users on every cloud service that offers it.
- Prove the 14-day patching claim to yourself. Pick three devices and check the last critical update dates before you answer, not after.
- Write the scope description properly. Since Danzell lifted the length limit, describe the boundary, the entities, and what is excluded and why.
- Have the signatory read the answers. They are attesting to them personally, and the questions about what happens for the rest of the year are now explicit.
Where organizations answer honestly and still fail
Three answers in the Cyber Essentials questionnaire are worth checking twice. Staff-owned devices used for work email are in scope, and their patch status is usually unknown. Cloud services bought by a department outside IT are in scope, and often have MFA available but not enforced. Home routers are generally out of scope where the device’s own software firewall is enabled and configured — but the answer has to reflect the actual configuration, not the assumption.
Frequently asked questions
How many questions are in the Cyber Essentials questionnaire?
It varies with the question set and how many entities and technologies you declare. Expect the scope section plus the five control areas, with follow-up questions triggered by what you have in scope.
Do we submit evidence with the answers?
Not at the basic level — the assessment marks your written answers. Cyber Essentials Plus is where technical verification happens, and we cover the Plus audit separately.
What happens if we fail?
You are told which answers failed. Certification bodies typically allow a resubmission within a short window; beyond that a new application is required.
Who has to sign the declaration?
A board member, owner or equivalent senior person. It cannot be delegated to the IT team that prepared the answers.
How long is certification valid?
Twelve months, and the Danzell declaration makes the expectation of ongoing compliance during that period explicit.
Where this leaves you
Treat the Cyber Essentials questionnaire as an audit you administer to yourself. Build the asset list, verify patch dates and MFA coverage before answering rather than afterwards, describe the scope in full now that length is no longer capped, and check your answers against the auto-fail conditions — a single unsupported operating system or an unpatched critical update inside scope ends the assessment regardless of how strong everything else is.
References
- IASME — changes to Cyber Essentials for April 2026 — the Danzell question set, dates and grace period.
- NCSC — Cyber Essentials overview — the scheme and its five controls.
More on UK cyber certification
- The Cyber Essentials questionnaire — you are here
- Cyber Essentials certification and the five controls
- Cyber Essentials Plus and the 2026 audit
- Phishing-resistant MFA
Asset registers, policy templates and an answer-preparation checklist are in the Cyber Essentials UK Toolkit, or start with the free ISO templates.