grc-scan

Cyber Essentials question · Secure configuration

Have all default or vendor-supplied passwords been changed or removed on your devices and software?

This is a mandatory item. Answering “No” fails the whole Secure configuration section — and the overall assessment — however strong everything else is.

Why assessors ask this

Default passwords are an automatic fail in Cyber Essentials.

Priority fix

Priority: change or remove every default/vendor password — this is an automatic Cyber Essentials fail on its own.

What “good” looks like for Secure configuration

  • Remove unused user accounts, software and services from your devices.
  • Change or remove every default/vendor password.
  • Set a strong-password baseline (length + lockout) or add MFA where a password is the only control.

See where you stand in 5 minutes

Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.

Start the free readiness check

Part of the Secure configuration control.

This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.