Blog › Article
What an assessor actually asks for
Most preparation is aimed at making the answers look right on the day. Assessors are trained to look for the places where the answers and the estate disagree — and the easiest place to find that is the difference between what was true on the day and what was true the rest of the time.
Cyber Essentials: the answers, and whether they hang together
For Cyber Essentials, the assessor works from your questionnaire. They aren't testing your machines; they're testing whether the answers are complete, consistent and meet the requirements. In practice that means looking for:
- A scope that matches reality. The questionnaire asks what's in scope: devices and their operating systems, network equipment, cloud services. A list of operating systems that includes something unsupported, or a count of laptops that doesn't fit the size of the organisation, is the first thing that draws a question.
- Answers that agree with each other. Saying every cloud service has MFA while listing one that doesn't support it, or saying admin accounts are separate while describing a two-person business where everyone is an admin.
- Specifics, not assurances. "We keep everything up to date" isn't an answer to how updates are applied within fourteen days. Assessors want the mechanism.
- The automatic-fail items. MFA on cloud services, for administrators and users, and high-risk updates within fourteen days, for operating systems, routers and firewalls (A6.4) and for applications (A6.5). A "no" to any of them ends the assessment.
The questionnaire is signed by a board-level director or equivalent, declaring the answers true. That declaration is the part of Cyber Essentials that carries the weight, and the part that is easiest to sign without knowing whether it's accurate.
Cyber Essentials Plus: the machines
Plus is where the answers are tested against reality. The assessor typically:
- scans what faces the internet for known vulnerabilities;
- tests a sample of your devices, checking for missing updates older than fourteen days and for unsupported software;
- tests malware protection by trying to deliver harmless test files through email and the web;
- checks that MFA is enforced on cloud accounts, and that administrator and user accounts are separate.
The sample is chosen by the assessor, not by you. It's the machines you'd have left out — the rarely used laptop, the reception PC, the server in the cupboard — that turn up the fourteen-day failures. Since April 2026, a second sample is taken to check that any fixes were applied across the estate, not just to the machines tested first. See Cyber Essentials or Cyber Essentials Plus? for how the two compare.
Screenshots and records answer different questions
When organisations prepare evidence, it usually takes the form of screenshots: the patching dashboard showing green, the antivirus console with every machine protected, the firewall settings page. Each is true. Each shows one moment.
A screenshot taken the week before an assessment answers the question "is it right now?" The requirement asks something different: whether updates are applied within fourteen days as a matter of routine, whether leavers lose access when they leave, whether MFA is on for every service rather than the ones someone checked last week. That question is about the rest of the year, and a screenshot can't answer it.
A dated record answers the question the requirement is really asking. A machine-by-machine history of how far behind each device was, when a firewall was off and when it came back, when an exception was accepted and why — that shows how the estate behaves, not how it looked on one day.
What this costs when the two get confused
- A pass that isn't true. The certificate says the controls are in place. If they were only in place for the screenshot, the organisation is carrying a certificate and an insurance policy based on a claim that won't hold up after an incident.
- A Plus failure nobody saw coming. The questionnaire passed because the answers were right on the day. The audit fails because the sampled laptop has been three weeks behind since it was last switched on.
- A renewal that becomes a project. With no record of the year, every renewal starts from scratch.
What good evidence looks like
- It covers every in-scope machine, not the ones you checked.
- It's dated, so it shows when things changed, not just how they are.
- It shows exceptions with reasons: what was accepted, by decision, rather than what was missed.
- It's produced as a matter of routine, not assembled for the assessment.
- It's honest about its limits: what it evidences, and what has to be evidenced some other way.
Quick answers
Does a Cyber Essentials assessor inspect my systems?
Not for Cyber Essentials, which is assessed from your questionnaire. Cyber Essentials Plus adds a technical audit of your systems.
Do I need screenshots for Cyber Essentials?
The assessor may ask for more detail or supporting evidence, but screenshots only show one moment. Evidence that covers the period is stronger.
Who signs the Cyber Essentials declaration?
A board-level director or equivalent, declaring that the answers are true.