Sin #1
Misunderstanding scope

The mistake

Organisations assume CE certification means “our main office computers.” They exclude home-working laptops, mobile devices, cloud systems, and remote infrastructure — then wonder why their submission is sent back for complete rescoping.

Why it matters

CE scope is all devices connecting to the internet for business use. There are no carve-outs for devices that are “mostly personal” or managed by a third party. Get this wrong and your submission stalls before assessment even begins.

Quick fix

Map your complete digital estate before you start. Include office devices, remote workers’ laptops, mobile phones, tablets, servers, and cloud services. When in doubt, include it — it’s easier to narrow scope on the readiness call than to restart mid-assessment.

Sin #2
The MSP illusion

The mistake

“Our IT provider handles everything, so we’re fine.” Organisations assume their managed service provider has certification covered without ever verifying that the documentation exists in a certification-ready format.

Why it matters

CE certifies your organisation, not your MSP. You must provide evidence of controls. If your IT provider can’t or won’t supply firewall configs, patch records, and access control policies in the format required, your submission stalls — and the MSP rarely feels the pressure of your deadline.

Quick fix

Engage your MSP early and explicitly. Confirm they can produce firewall configurations, patch management records, and access control policies in certification-ready format. If they can’t, you need to know before you open the assessment.

Sin #3
Patch management theatre

The mistake

“Updates are automatic, so we’re compliant.” Organisations rely on Windows Update running in the background — no visibility, no documentation, no evidence that anything is actually happening across the full estate.

Why it matters

CE requires proof that security patches are applied within 14 days of release, across every device in scope, with documented exception handling for anything that can’t be patched on time. Automatic updates alone don’t produce that evidence.

Quick fix

Implement patch visibility tooling. Document your review and deployment process. Track compliance across your full estate and ensure you can produce a patch history showing timely application. Undocumented compliance is indistinguishable from non-compliance.

Sin #4
MFA misconfiguration

The mistake

Organisations enable MFA but don’t configure it correctly — partial coverage, weak methods (SMS), undocumented exceptions, or conditional access policies that barely trigger in practice.

Why it matters

CE requires MFA for all remote access and all admin accounts, using robust authentication methods. SMS-based MFA is increasingly considered weak. Gaps in coverage, or MFA that exists on paper but isn’t consistently enforced, fail the control outright.

Quick fix

Audit MFA comprehensively. Cover every remote access point and every admin account. Use app-based authenticators or hardware tokens where possible. Document any exceptions with a clear business justification — and be prepared to defend them.

Sin #5
Shared account chaos

The mistake

Shared accounts exist for “good reasons” — a generic info@ email login, a communal admin account, a tablet used by the whole team. Organisations don’t see these as compliance failures because they’ve always operated this way.

Why it matters

CE explicitly prohibits shared accounts. Every user must have a unique account for accountability and access control purposes. Even a single shared account means you fail the user access control requirement — there are no exceptions for convenience.

Quick fix

Audit your entire environment for shared credentials and eliminate them. Use shared mailboxes accessed through individual accounts, not shared logins. Implement proper user access reviews so you can evidence who has access to what — and why.

Sin #6
The router isn’t a firewall

The mistake

“We have a router from our ISP with a built-in firewall, so we’re compliant.” Organisations confuse consumer-grade routers with properly configured boundary firewalls — and assume that the default configuration is adequate.

Why it matters

CE requires a deny-by-default firewall configuration with documented rulesets and regular reviews. Default router configurations typically allow unnecessary services — UPnP, remote management interfaces, broad outbound permissions — that wouldn’t pass the control.

Quick fix

Review your boundary firewall configuration actively. Disable unnecessary services. Document your ruleset with a business justification for every permitted service. Isolate guest WiFi from your main network. This is one area where “we have a firewall” and “our firewall meets CE requirements” are very different statements.

Sin #7
Time pressure syndrome

The mistake

“We need the certificate by next week for a tender.” Organisations rush submission without preparation, expect immediate certification, and are surprised when the assessment generates findings that push them past their deadline.

Why it matters

CE is a technical assessment requiring proper preparation: scoping, gap identification, evidence gathering, remediation. Rushed submissions generate extensive back-and-forth with the assessor and often miss the deadline they were trying to meet. The IASME fee is also charged per assessment opened — not per certificate issued — so a failed submission isn’t free.

Quick fix

Plan ahead. Give yourself 4–6 weeks of runway. Conduct a readiness assessment first to identify gaps before formal submission. Idela’s readiness-first approach means we review your evidence before opening the assessment on the portal — so you submit when you’re genuinely ready, not when you hope you are.


The common thread

Every sin on this list comes down to the same thing: treating Cyber Essentials as a paperwork exercise rather than a technical assessment. The organisations that certify first time are the ones that prepare their evidence before they submit — not after they get a finding back.