InsightsCyber Essentials Plus: What the Audit Actually Tests

Cyber Essentials Plus: What the Audit Actually Tests

IPFour7 min read

Cyber Essentials is a self-assessment. Cyber Essentials Plus is the same five controls with an assessor actually checking, and that difference is where organisations get caught out. Plenty of businesses pass the questionnaire and then fail the audit, not because they lied, but because what they believed was true of their estate was not true of every device in it. This covers what the assessor tests, what fails most often, and how to prepare so the audit is a formality.

The difference in one sentence

Basic Cyber Essentials asks you to answer questions about your controls and a certification body reviews your answers. Cyber Essentials Plus sends an assessor to verify those answers technically, on a sample of your actual devices, within three months of your basic certification.

That verification window matters for planning. You cannot do Plus first, and if your basic certificate is older than three months when you come to the Plus audit, you start again. Booking both together is almost always cheaper and faster than treating them as separate projects.

What the assessor actually does

They take a representative sample of your devices, covering each operating system and device type in scope, including laptops used from home and any mobile devices that access organisational data. Sampling is not you choosing your best machines: the assessor sets the sample.

On each sampled device they run an authenticated vulnerability scan, checking for missing patches and unsupported software. They test malware protection by attempting to download harmless test files and by checking that the protection is active and current. They test whether a standard user can install software or gain administrative rights. They check that accounts have multi-factor authentication where the scheme requires it, particularly on cloud services.

They also test your email and web filtering by sending test files through, and they verify that removable media controls behave as you claimed. Externally, they scan your internet-facing IP addresses for open services and unpatched vulnerabilities.

The five failures we see most often

Unsupported software somewhere in the estate. This is the most common outright fail and it is usually something nobody thought about: an old Windows machine driving a piece of production equipment, a phone that stopped receiving security updates, or a browser plugin whose vendor stopped supporting it. The scheme does not accept risk-based justification here in the way ISO 27001 would.

Patches not applied within fourteen days. The rule is that critical and high severity updates must be applied within fourteen days of release. Monthly patch cycles fail this on their face, and so do estates where a handful of machines are missed because someone was on leave.

Local administrator rights on user accounts. Convenience arrangements from years ago tend to persist, and a single sampled laptop where the day-to-day account can install software will fail the control.

Multi-factor authentication missing on a cloud service nobody listed. Organisations enumerate Microsoft 365 and forget the CRM, the file sharing tool, or the accounting package.

Default credentials still in place on a firewall, router or other network device, most often on equipment supplied by an internet provider and never touched since installation.

How to prepare so it is a formality

Start with an accurate asset inventory, because you cannot verify what you have not listed and the assessor will sample from reality rather than from your list. Include home-working devices and anything that touches organisational data.

Run your own authenticated vulnerability scan across a sample before booking. Most Plus failures would have been visible in a scan a fortnight earlier, and remediating in your own time is far cheaper than failing and rebooking.

Check every internet-facing service you expose, then check whether you meant to expose it. Remote desktop published directly to the internet is both a Cyber Essentials failure and the single most common route into a small business.

Finally, confirm the scope in writing before the audit. Whole-organisation scope is cleanest and is what most buyers assume they are getting, but a defined subset is permitted if it is genuinely segregated. Discovering a scope disagreement on audit day is an expensive way to learn this.

Is it worth it over basic certification

If a contract requires it, the question answers itself, and Plus is increasingly specified in public sector and larger private supply chains where basic certification once sufficed.

If nothing requires it, the honest case is still reasonable: the audit finds things. Every Plus engagement we run surfaces at least one device or service nobody knew was there, and that discovery is worth more than the certificate. A self-assessment cannot do that, because it only reflects what you already believe.

Related services

Free Consultation

Ready to get started?

Tell us about your requirements and one of our UK-based engineers will be in touch within 2 business hours.

020 4525 3748