Scheme Cyber Essentials Plus / Requirements v3.3 (Danzell) / Assessed by IASME
The audit is published.
So we run it before they do.
Cyber Essentials Plus is not a questionnaire. An assessor tests five things on your actual machines. Every one of those tests is written down in public — which means the only good reason to fail is not having read it.
- 5
- test cases, all published
- 3 months
- maximum gap from self-assessment to Plus audit
- 12 months
- certificate validity, then recertify
- 1–3 days
- typical on-site audit, once you are ready
The ledger
What the assessor actually does
Five tests. This is the whole audit. If you can answer for each row, you pass.
- TC-01
Remote vulnerability assessment
An external scan of every internet-facing address you own.
Fails on Anything exposed and unpatched. Services nobody remembered were reachable.
- TC-02
Patch management
An authenticated scan of sampled devices, checking updates are genuinely applied.
Fails on Critical or high-severity patches older than 14 days. Software past end-of-life.
- TC-03
Malware protection
Live test files sent by email and attempted as a browser download on a sampled machine.
Fails on Anything that lets the test file through. A clean baseline email goes first to prove delivery works.
- TC-04
Multi-factor authentication
A real sign-in watched from an untrusted session, on every cloud service in scope.
Fails on One qualifying account without MFA. Standard users and administrators are both tested.
- TC-05
Account separation
A user on a standard account is asked to run an administrative task.
Fails on No prompt for separate credentials. Run on every sampled device, not a subset.
Source: NCSC Cyber Essentials Plus Test Specification, v3.3. Nerdster is not a certification body — certificates are issued by IASME through a licensed certification body.
Before you book
What actually fails people
- MFA missing on one cloud service Automatic fail under the current requirements.
- An operating system past end-of-life Fails unless genuinely isolated from the network.
- Patching that has quietly drifted The 14-day window is measured, not asserted.
- A cloud service nobody listed Out of scope on paper, in scope in the audit.
- Everyone an admin on their own machine TC-05 is run on every sampled device.
None of these are hard to fix in advance. All of them are hard to fix on the day, which is the entire argument for a dry run.
Engagement
How we run it
Scope
We agree what is in scope — every device, user and cloud service that touches your data. Getting this wrong is the most expensive mistake available.
Dry run
We run the five test cases above against your environment. The specification is public, so there is no reason for audit day to contain surprises.
Remediate
You get a written list of everything that would have failed, in the order it should be fixed. Then we fix it.
Audit
We prepare the evidence, sit alongside the assessor, and answer the technical questions.
Who you deal with
Deepanshu Sahni
Managing Director, Nerdster Ltd
You will be speaking to the person who scopes the work, not to a sales desk that hands you on afterwards. If your environment is not ready, you will be told that before you are quoted, because a rushed submission is the expensive route rather than the fast one.
Proof block — awaiting real content
This is where one named client engagement belongs: the environment as found, the specific gaps, what was changed, and the outcome. One real example outperforms every adjective on the rest of the page.
Left empty on purpose. Inventing a case study would have made a better-looking demo and a worse business.
Find out what would fail today
A scoping call establishes what is in scope and what state it is in. If you would rather start on your own, the qualifier takes a few minutes and tells you where you stand before you speak to anyone.