Insights · Cyber Essentials

What does Cyber Essentials Plus actually test?

Cyber Essentials Plus gets talked about like a tick-box exercise. Having gone through it ourselves as a certified provider - and taken clients through it, including an 850-user business that passed first time - it isn't. It's a hands-on technical audit of real devices against a fixed specification, with a retest built in if you fail.

Here's what actually happens, based on the current test specification and our own experience of the assessment.

It starts with the same five controls as base Cyber Essentials

CE+ is built on the same five technical controls as the standard certification - firewalls, secure configuration, security update management, user access control, and malware protection. The difference is verification: instead of self-declaring compliance on a form, an independent IASME-accredited assessor checks it on real machines.

The vulnerability scan comes first, and it's authenticated

The assessor runs an authenticated vulnerability scan against a sample of your devices - logged in, not just probing from outside - to confirm nothing in scope is missing a qualifying patch and no end-of-life software is running.

Sampling isn't discretionary, and it's unforgiving

The assessor doesn't check every device. Sample size scales with your estate and is calculated by a defined IASME methodology rather than picked on the day, but it always covers every operating system, every build type (corporate, contractor, BYOD) and every role profile in scope. Servers are always included.

The part that catches people out: one non-compliant device in the sample counts as a failure of the whole population. If your builds aren't consistent, a single laptop can flag a systemic problem across the fleet.

If the first sample fails, you get a window to remediate, but the retest isn't just the same devices - the assessor adds a second, fresh sample on top. Fail either one and you lose the certificate, including the underlying self-assessment.

The 14-day patching rule is stricter than most people assume

Critical and high-severity updates (CVSS 7.0+) must be applied within 14 days of a fix becoming available - and "available" now includes vendor-published configuration or registry-based mitigations, not just software patches. If devices fail on this, the assessor doesn't simply re-check the same sample after remediation - they pull additional devices on top of the original ones, so patching gaps genuinely have to be fixed estate-wide, not just on the machines being watched.

What they're checking on each sampled device

  • Patching within 14 days for the OS and high-risk applications (browsers, email clients, office suites, PDF readers)
  • Multi-factor authentication enforced on cloud services and admin accounts
  • No web browsing or email on accounts with administrative privileges
  • Real-time malware protection or application allow-listing, active and current
  • Firewall and router configuration - default credentials changed, unnecessary services closed

The bit most SMEs get wrong

Having sat on both sides of this assessment, the failures are rarely exotic. The same four things come up again and again:

  • Local admin rights everywhere. Users running day-to-day as administrators on their own machines. It feels convenient; it fails the access-control requirement, and it's usually the first thing we have to unwind.
  • No real starter and leaver process. Accounts for people who left months ago still live, still licensed, sometimes still syncing mail. If nobody can say who has access right now, the assessment will say it for you.
  • Access to everything, not access to what's needed. Whole-company permissions granted because it was quicker on day one. CE+ expects access to be deliberate and specific, and "everyone can see everything" doesn't survive contact with an assessor.
  • Patching Microsoft and forgetting everything else. Windows Update is on, so patching feels handled - while Chrome, Zoom, Adobe and every other third-party application drift out of date. The authenticated scan finds them all, and they count exactly the same as a missing Windows patch.

None of these are hard to fix. All of them are hard to fix in the two weeks before an assessment, which is why we build them into how a client's IT runs day to day rather than treating certification as an annual scramble.

What it means when a supplier tells you they're CE+ certified

It means an independent assessor has physically tested a representative sample of their machines against a fixed, government-backed specification within the last 12 months, with a real chance of failure built in - not that they filled in a form. If you're vetting an IT provider, CE+ is a meaningfully higher bar than base Cyber Essentials.

Where do you stand today?

Try our free Cyber Essentials readiness checker, or read about our Cyber Essentials certification support - gap analysis, remediation and audit support from a firm that holds CE+ itself.

Independently reviewed by our customers