How to fill out a Cyber Essentials questionnaire?

Completing the Cyber Essentials questionnaire might seem like a daunting exercise, but the key word to focus on is ‘Essentials’. When you are answering the questions, try to think about your infrastructure as a whole, not just thinking in too much detail about specific devices that you may have in mind. Looking at secure configuration, URM often finds questionnaire respondents just focussing on password protection rather than protection of the whole infrastructure, e.g., servers, end-user devices, mobile phones, Cloud environments and so on.

Most of the questions are phrased in such a way that only a high level response is required, so don’t write ‘War and Peace’ if it’s not needed . It might be a question about admin accounts, your on-boarding process or firewalls and, generally, you should be thinking about just writing one or two paragraphs to provide the assessor with an understanding of what your infrastructure looks like. Some organisations find it useful to have a checklist when they are answering the different questions. For example, if there is a question on password protection, your checklist will be reminding you to bear in mind all the different types of environments and whether the scope is correct.

There can, of course, be exceptions if the organisation that is applying for Cyber Essentials is large with a complex infrastructure and the processes are not as straightforward. In most cases, however, in the Cyber Essentials world less is more. If you have any query, URM has a dedicated Cyber Essentials Team to help you. Just email cyberessentials@urmconsulting.com

We are extremely grateful for the outstanding support the URM Team provided throughout our Cyber Essentials and Cyber Essentials Plus journey. Their professionalism, technical expertise, and pragmatic guidance were key to our successful certification. We would like to call out a personal thanks to our assessor, who was particularly impressive throughout. From the initial assessment through remediation and validation, he demonstrated clear expertise, practical recommendations, and strong communication. This, coupled with his thoroughness, responsiveness, and collaborative approach, made the process efficient for our whole team.
Aerospace and defence engineering company
Apply for Cyber Essentials certificate

Cyber Essentials Update 2026

Published on
26 Mar
2026

URM’s blog breaks down key changes to the Cyber Essentials scheme coming into force on 27 April 2026, including the new Danzell Question Set.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
11/3/2026
Cyber Security and the Board: A Sign of What’s to Come

URM’s blog explains recent amendments to the Cyber Security and Resilience Bill, how they align with broader regulatory shifts, & practical steps to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/2/2026
NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
19/1/2026
Minimising the Impact When a Breach Occurs

URM’s blog explores the importance of cyber resilience & the steps organisations can take to prepare for and mitigate the impact of a cyber incident.

Read more
"
URM were super helpful and knowledgeable, talking and walking me through each one of the tests and providing some useful information on security and how to improve things in the future.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.