Scheme Cyber Essentials Plus / Requirements v3.3 (Danzell) / Assessed by IASME

The audit is published.
So we run it before they do.

Cyber Essentials Plus is not a questionnaire. An assessor tests five things on your actual machines. Every one of those tests is written down in public — which means the only good reason to fail is not having read it.

5
test cases, all published
3 months
maximum gap from self-assessment to Plus audit
12 months
certificate validity, then recertify
1–3 days
typical on-site audit, once you are ready

The ledger

What the assessor actually does

Five tests. This is the whole audit. If you can answer for each row, you pass.

  1. TC-01

    Remote vulnerability assessment

    An external scan of every internet-facing address you own.

    Fails on Anything exposed and unpatched. Services nobody remembered were reachable.

  2. TC-02

    Patch management

    An authenticated scan of sampled devices, checking updates are genuinely applied.

    Fails on Critical or high-severity patches older than 14 days. Software past end-of-life.

  3. TC-03

    Malware protection

    Live test files sent by email and attempted as a browser download on a sampled machine.

    Fails on Anything that lets the test file through. A clean baseline email goes first to prove delivery works.

  4. TC-04

    Multi-factor authentication

    A real sign-in watched from an untrusted session, on every cloud service in scope.

    Fails on One qualifying account without MFA. Standard users and administrators are both tested.

  5. TC-05

    Account separation

    A user on a standard account is asked to run an administrative task.

    Fails on No prompt for separate credentials. Run on every sampled device, not a subset.

Source: NCSC Cyber Essentials Plus Test Specification, v3.3. Nerdster is not a certification body — certificates are issued by IASME through a licensed certification body.

Before you book

What actually fails people

  • MFA missing on one cloud service Automatic fail under the current requirements.
  • An operating system past end-of-life Fails unless genuinely isolated from the network.
  • Patching that has quietly drifted The 14-day window is measured, not asserted.
  • A cloud service nobody listed Out of scope on paper, in scope in the audit.
  • Everyone an admin on their own machine TC-05 is run on every sampled device.

None of these are hard to fix in advance. All of them are hard to fix on the day, which is the entire argument for a dry run.

Engagement

How we run it

01

Scope

We agree what is in scope — every device, user and cloud service that touches your data. Getting this wrong is the most expensive mistake available.

02

Dry run

We run the five test cases above against your environment. The specification is public, so there is no reason for audit day to contain surprises.

03

Remediate

You get a written list of everything that would have failed, in the order it should be fixed. Then we fix it.

04

Audit

We prepare the evidence, sit alongside the assessor, and answer the technical questions.

Who you deal with

Deepanshu Sahni

Managing Director, Nerdster Ltd

You will be speaking to the person who scopes the work, not to a sales desk that hands you on afterwards. If your environment is not ready, you will be told that before you are quoted, because a rushed submission is the expensive route rather than the fast one.

0330 043 7414 / [email protected]

Proof block — awaiting real content

This is where one named client engagement belongs: the environment as found, the specific gaps, what was changed, and the outcome. One real example outperforms every adjective on the rest of the page.

Left empty on purpose. Inventing a case study would have made a better-looking demo and a worse business.

Find out what would fail today

A scoping call establishes what is in scope and what state it is in. If you would rather start on your own, the qualifier takes a few minutes and tells you where you stand before you speak to anyone.