Cyber Essentials questions often arrive at an awkward moment: a customer or procurement contact wants an answer by Friday, the commercial team does not want an opportunity to stall, and the questionnaire is forwarded to whoever usually deals with IT.
Then the replies split. One provider manages the firewall, another looks after user devices, somebody internal controls cloud accounts, and nobody is sure which systems should be included. The form is waiting, but there is no single, current view of the infrastructure behind the answers.
That is the point to pause. The UK’s National Cyber Security Centre (NCSC) describes Cyber Essentials as a government-recommended minimum standard built around five technical controls. The applicant organisation is still responsible for meeting the requirements and supporting its answers, even where third parties manage parts of the environment.
Before copying last year’s wording or asking one supplier to complete the whole form, use five infrastructure questions to identify the owners, evidence and gaps. They will not replace the official assessment. They will show whether your business is ready to answer it accurately.
The first question is the one that shapes every answer after it: what is actually in scope?
Table of Contents
First, do not treat the questionnaire as an IT form-filling task
Cyber Essentials is an organisational certification, not a form that can simply be handed to the company that manages one part of your technology.
The current Cyber Essentials Requirements for IT Infrastructure are organised around five technical controls:
- firewalls;
- secure configuration;
- security update management;
- user access control;
- malware protection.
Those controls can cut across network equipment, servers, laptops, mobile devices, cloud services and third-party access. Different people may hold different parts of the answer, but somebody inside the applicant organisation still needs to coordinate them.
Start by naming one accountable internal owner. That person does not need to perform every technical task. They do need to know which providers and colleagues own each part, where the supporting evidence sits and which answers remain unresolved.
If that first ownership check exposes a gap around your network, firewall, monitoring or managed infrastructure, Sentinel provides one managed environment and one point of accountability for the infrastructure within its scope.
The NCSC describes a self-led certification route and a supported route through an IASME-licensed Certification Body. If you need advice on interpreting the official questions or an assessment, use one of those authorised routes. The purpose of the five checks below is narrower: to organise the infrastructure facts before you answer.
1. What is actually inside the assessment scope?
A reliable response starts with a current description of the organisation and technology being assessed.
List the organisation, devices, services and networks
Do not limit the list to equipment visible in the office. Depending on your environment, the scope may include:
- legal entities covered by the assessment;
- office and branch networks;
- internet-connected routers and firewalls;
- servers, desktop computers, laptops, tablets and mobile phones;
- cloud services used to hold or process organisational data;
- home and remote-working arrangements;
- accounts your organisation owns but a third party uses to manage infrastructure;
- organisation-owned devices loaned to employees or other parties.
The current requirements state that accounts owned by the applicant remain in scope even when a supplier, contractor or managed service provider uses them. If an external provider remotely administers part of your environment, “our supplier manages it” is not a complete answer. You need to establish which controls are being met and how that can be demonstrated.
If anything is excluded, how is it separated?
An exclusion needs more than a note saying that a system is “not included”. The business should be able to describe what has been excluded, why and how the excluded network or service is segregated from the environment being assessed.
Create one scope record with the asset or service, its owner, the provider involved and any proposed exclusion. If the record cannot show where one environment ends and another begins, resolve that before relying on the exclusion in a formal response.

2. Who controls the firewalls and secure configuration?
The firewall question is not answered by confirming that a firewall exists. You need to know which firewalls protect the devices in scope, who administers them and how their configurations are controlled.
Can you identify the boundary and device firewalls?
A boundary firewall controls traffic entering and leaving a network. A software firewall may protect an individual device, particularly when that device uses a network the organisation does not control.
For each relevant firewall, ask:
- who holds administrative access;
- whether default administrative credentials have been changed;
- whether internet-based administration is disabled or protected appropriately;
- which inbound services are allowed;
- where configuration and change records are kept;
- who provides cover when the usual administrator is unavailable.
Are inbound rules approved, documented and removed?
The current technical requirements say inbound firewall rules should be approved and documented by an authorised person, including the business need. Rules that are no longer required should be removed or disabled.
That creates a practical ownership test. If nobody can explain why an inbound service is exposed, who approved it or when it was last reviewed, the answer is not ready for a questionnaire.
Can you show secure configuration is maintained?
Secure configuration also applies beyond the boundary firewall. Computers and network devices should be managed so that unnecessary accounts, software and network services are removed or disabled. Default or easily guessed passwords should be changed, and users should be authenticated before accessing organisational data or services.
Ask who controls the baseline configuration for each device type and how exceptions are recorded. A device that was configured correctly when installed may no longer meet that baseline after temporary accounts, test services or unused software have accumulated.
Where firewall and network responsibility is already split, Sentinel managed infrastructure may provide a clearer managed boundary for the infrastructure in its scope. Sentinel includes managed networking, firewall management and one point of accountability. This does not mean it covers every device firewall, endpoint configuration, cloud policy or Cyber Essentials requirement across the organisation.
3. Can you show how security updates are managed?
“Updates are automatic” may be true for one device and false for the next. A useful answer identifies which systems are supported, who monitors their update status and what happens when an update cannot be applied normally.
Which systems are supported, and who tracks their status?
The official security update requirements apply across in-scope software and devices, including firewalls, routers, servers, computers, mobile devices and relevant cloud services.
For each system, establish:
- the product and version in use;
- whether the vendor still supports it;
- who receives or monitors update information;
- whether automatic updates are enabled where possible;
- how failed or deferred updates are identified;
- where completion can be evidenced.
Unsupported software cannot be made safe by leaving it untouched. The requirements say unsupported software should be removed from devices or removed from scope using a defined subset that prevents all internet traffic to and from it.
Can the owner evidence the required update timetable?
Under version 3.3, relevant updates must be applied within 14 days of release when they fix vulnerabilities the vendor describes as critical or high risk, carry a CVSS v3 base score of 7 or above, or do not include severity details. The NCSC recommends applying all released updates within 14 days where possible, but that recommendation should not be confused with the specific mandatory conditions.
Take one firewall, one server and one user device. For each, write down who owns it, whether it is supported, how updates are applied and where the evidence sits. Any blank is a question to resolve before you answer.
Sentinel includes firmware updates, security patches and system maintenance within the managed Sentinel environment. It should only be cited for that contracted scope, not as evidence that every endpoint, application or cloud service in the business is covered.

4. Who owns user, administrator and third-party access?
Access control spans more than the employee directory. It includes administrators, temporary accounts and credentials used by suppliers or support services.
Are accounts approved, unique and removed when no longer needed?
The business should have a process to create and approve accounts, authenticate users with unique credentials, and remove or disable accounts that are no longer required.
Ask who can answer these practical questions:
- Who approves a new user account?
- Who removes access when somebody leaves or changes role?
- Which third parties have accounts in the environment?
- Which accounts have administrative privileges?
- When were privileged and supplier accounts last reviewed?
- Can an administrator use a separate standard account for email and web browsing?
A contract saying that a provider has “secure access” does not show which accounts exist today or whether old privileges have been removed.
Where is MFA required and who reviews privileged access?
The current requirements say multi-factor authentication should be implemented where available, and authentication to cloud services must use MFA. They also require separate accounts for administrative activity, rather than using a privileged account for routine email or browsing.
Sentinel’s confirmed scope includes encrypted remote engineering access, multi-factor authentication, access controls and granular permissions within the described environment. It is still necessary to identify who manages access to business applications, endpoints and cloud services outside that environment.
5. How is malware protection handled on every in-scope device?
This is where an infrastructure-led review must acknowledge its limits.
Which protection mechanism applies to each device type?
The Cyber Essentials requirements say an active malware-protection mechanism must cover every device in scope. Depending on the device, that may involve appropriately configured anti-malware software or application allow listing.
The evidence needs to be more specific than a product name. It should show which devices are covered, whether the protection is active and current, and who deals with exceptions or devices that stop reporting.
Who owns the endpoints and evidence that Sentinel does not cover?
Sentinel is not confirmed to provide endpoint protection across every laptop, desktop, mobile device, application or cloud service in an organisation. On the currently confirmed Sentinel scope, 1Connect should not be named as the owner of this control.
If endpoint or malware-protection responsibility sits with an internal team or another provider, record that owner and request the required evidence from them. An honest gap is more useful at this stage than a confident answer that nobody can support later.
Turn five technical answers into one accountable response
The five questions will probably produce answers from several people. Bring them into one simple ownership record before completing the official Question Set.
| Area | What to record |
|---|---|
| Scope | Asset, service, legal entity, location and any justified exclusion |
| Control | Firewall, configuration, updates, access or malware protection |
| Owner | Named internal person and relevant external provider |
| Evidence | Configuration record, account review, update status or other current proof |
| Review | Date last checked and who confirmed it |
| Gap | Missing answer, unsupported system or responsibility still to assign |
A managed provider can supply facts about the services it manages. It cannot make the applicant organisation’s declaration for areas outside that scope.
The NCSC’s supply-chain guidance explains that Cyber Essentials can give organisations confidence that suppliers have implemented fundamental controls and can reduce repeated due-diligence questionnaires. That value depends on the answers reflecting the real environment, not a collection of assumptions copied from old forms.
When you are ready to work through the official assessment, use the current IASME Question Set and certification route. If you need guidance, use an IASME-licensed Certification Body or an NCSC-assured Cyber Advisor.
Where 1Connect can help
If the unclear answers sit around your network, firewall, managed infrastructure, monitoring, updates or access controls, talk to 1Connect about whether Sentinel fits that part of the problem.
The useful outcome is a defined managed boundary: which infrastructure is included, who maintains it and who is accountable for supplying accurate information about it. Sentinel is not a Cyber Essentials assessment or certification service, and it should not be treated as a substitute for endpoint, application or cloud controls outside its scope.

Need clearer ownership of your network and managed infrastructure?
Explore Sentinel and talk to 1Connect about whether it could give your business a clearer managed boundary for its networking, firewall, monitoring, updates and access controls.
For certification advice or assessment, use the official IASME route.



