Cyber Essentials
Questionnaires.
Navigating the IASME Self-Assessment Questionnaire (SAQ) can be complex and technical. We help you correctly scope your network, interpret the questions accurately, and avoid instant failures.
What does the questionnaire actually ask?
The Cyber Essentials SAQ is divided into sections covering your organization's infrastructure and the five core technical controls. Here is how the questions break down.
Scoping & Assets
FoundationBefore testing controls, you must define what is actually being assessed. You must list all company-owned devices, BYOD (Bring Your Own Device) equipment used for work, cloud services, and network boundaries.
Firewalls & Gateways
Control 1You will be asked how your internet boundary is protected. Questions focus on whether default admin passwords have been changed on routers, and if unnecessary inbound ports are strictly blocked.
Secure Configuration
Control 2This section examines how devices are set up. You must confirm that unnecessary software and services are removed, and that auto-run features for external media (like USB drives) are disabled.
User Access & MFA
Control 3Questions here focus on identity. You must verify that admin accounts are only used for administrative tasks (not daily email/web browsing), and that Multi-Factor Authentication (MFA) is mandated across all cloud services.
How we navigate the IASME Portal.
Portal Setup & Scoping
We set up your official IASME portal account and work with you to accurately define the scope of your assessment. Getting the scope wrong (e.g., forgetting a subsidiary or cloud service) is the most common reason for failure.
Drafting the Questionnaire
Instead of answering directly in the portal where mistakes are permanent, we work through a draft version with your IT team. We translate complex technical questions into plain English and gather the necessary technical facts.
Pre-Assessment Review
Before you hit submit, our certified assessors review your answers. If any responses do not meet the standard, we pause the process, explain the gap, and advise you on exactly how to fix the underlying technical issue.
Submission & Grading
Once we are confident your environment meets the criteria, the answers are uploaded and submitted. Because of our pre-assessment check, organizations using our guided support achieve a 100% first-time pass rate.
⚠️ Top Reasons for SAQ Failure
Unsupported Operating Systems
Devices running end-of-life software (like Windows 7 or old macOS versions) that no longer receive security updates will result in an automatic failure.
Missing Cloud MFA
A recent update to the scheme mandates that Multi-Factor Authentication must be enforced for all users on all cloud services (IaaS, PaaS, SaaS).
Unpatched Software
Failing to confirm that all high and critical security patches are applied to devices and software within 14 days of release by the vendor.
IASME & Certification - Practical guidance for a more secure business
Small Business Compliance: GDPR & Cyber Essentials
How SMEs can navigate UK Cyber Essentials, Cyber Essentials Plus, and IASME Cyber Assurance standards smoothly with certified assessor guidance.
Read full briefing →A Beginner’s Guide to Security Awareness & Verification
Building strong human defences and technical controls required to satisfy government and defence supply chain certification audits.
Read full briefing →GDPR Compliance for SMEs: A Practical 90-Day Roadmap
A step-by-step 90-day framework to build audit-ready GDPR compliance, data mapping, and evidence controls without operational overhead.
Read full briefing →Why Modern Businesses Need Continuous Cyber Protection
One-off assessments are no longer enough. Here is why continuous cyber protection has become the baseline for organisations serious about security.
Read full briefing →Ready to tackle the Cyber Essentials SAQ?
Talk to our official IASME assessors for help scoping your environment, translating technical questions, and guaranteeing a first-time pass.
Get Questionnaire Help → info@worldcomputing.co.uk