Publish Date: January 9, 2026
Category: Cyber Essentials
We've assessed over 100 organisations for Cyber Essentials certification. The number one reason they fail? Outdated software they didn't know they had.
Cyber Essentials certification is the UK government-backed scheme that verifies your organisation meets basic cyber security controls. As an NCSC Assured Service Provider, we see the same preventable failures repeatedly. Here's what's causing organisations to fail, and what you can do about it before your assessment.
The Problem: Out of Date, Out of Support, Out of Compliance
The most common failure we see isn't complex. It's organisations running outdated software, devices, and systems that have reached end of life (EOL) or haven't received security updates within the required 14-day window.
These failures are rarely intentional. Most organisations believe they're "mostly up to date." They don't know certain systems have reached end of life. They assume updates happen automatically.
They're wrong.
During assessment, even a single outdated operating system, browser, mobile device, or router that's reached end of life results in failure. No exceptions.
What We're Finding in Real Assessments
That Windows 10 Machine Nobody's Migrated Yet
Windows 10 support ended in October 2025. If you're still running it, you're now operating an unsupported system that will fail your Cyber Essentials assessment.
We're already seeing this. Organisations that haven't migrated to Windows 11. End-of-life routers that haven't seen a security patch in years. Hardware the vendor stopped supporting years ago.
Once a product reaches end of support, it cannot meet CE requirements. Doesn't matter how well it works. Doesn't matter that "we're planning to replace it." It's an automatic fail.
Missed Security Updates
Outdated browsers and mobile device operating systems appear in almost every failed assessment. The updates were eventually applied, just not within the required 14-day window.
CE requirements are explicit: security updates must be applied within 14 days of release. Not "when we get round to it." Not a month later. A single instance won't necessarily fail you, but it's a non-compliance. Two or more non-compliances? Failed assessment.
The excuse is always the same: "We didn't realise it was that urgent."
How to Stop This Happening to You
Stop Treating Updates Like Housekeeping
Updates aren't an IT maintenance task. They're a mandatory security control. If a system can't be updated or is no longer supported, replace it or remove it.
Turn On Automatic Updates
For most organisations, especially smaller ones, automatic updates are the safest approach. Configure operating systems, browsers, and mobile devices to update automatically. Don't let users delay or dismiss them.
The organisations that pass aren't the ones manually managing update schedules. They're the ones who automated it and moved on.
Know When Your Kit Expires
Keep a simple list of your systems and devices with their end-of-life dates. You can find this information on vendor websites. Check it quarterly.
This lets you plan replacements before something becomes non-compliant, rather than discovering it during your assessment when it's too late.
If you're still running Windows 10, you need a migration plan now. Not next quarter. Now.
Make Someone Responsible
Somebody must own this. In a small organisation, that might be you. In larger ones, assign it to a specific person or team.
"Everyone's responsible" means nobody's responsible. That's when updates get missed.
Check What You've Actually Got
Once a month or quarter, spot-check system versions. Pick five random devices. Check the OS version, browser version, last update date. Takes ten minutes. Prevents failures.
The Pattern in Every Failed Assessment
The organisations that fail aren't running complex environments. They're running normal setups with normal software. They just don't have a process to keep it current.
The organisations that pass aren't the ones with the biggest IT budgets or the fanciest tools. They're the ones with simple, repeatable processes that ensure updates actually happen.
Why This Matters Beyond the Certificate
Keeping systems supported and up to date isn't just about passing Cyber Essentials. It's one of the most effective ways to reduce real cyber security risk.
The vulnerabilities exploited in most cyber attacks aren't sophisticated zero-days. They're known flaws in outdated software that should have been patched months ago. The update that would have stopped the attack was sitting there, waiting to be applied.
Cyber Essentials checks for this because it's the thing that actually matters.
Before You Start Your Assessment, Check Your Readiness
We've seen every failure pattern. The EOL router nobody's checked since 2019. The machine still running Windows 10 because "it works fine."
Before your formal Cyber Essentials assessment, we can review your environment and highlight exactly what will cause problems.
Book a FREE 20-minute readiness call and we'll review your setup with an assessor's eyes, before it becomes an official failure.
We don't just tick boxes. As NCSC-assured assessors, we know what causes failures because we see them every week.
Shonsys supports organisations across Edinburgh, Glasgow, Scotland, and the wider UK to achieve Cyber Essentials certification with clarity, confidence, and measurable assurance.