Cyber Essentials Plus Audit: What the Assessor Tests
A Cyber Essentials Plus audit tests your devices, patching, malware protection, admin accounts and cloud MFA. What to expect, and the 2026 retest rule.
Nerdster Team
Cyber Essentials Plus is not a harder version of the Cyber Essentials questionnaire. It tests exactly the same five technical controls — but instead of taking your word for it, an assessor gets hands on your infrastructure and checks. IASME, the NCSC’s Cyber Essentials delivery partner, describes it plainly: the audit “can be carried out on site or remotely and includes vulnerability scans of the organisation’s scoped infrastructure.”
Two things trip organisations up more than anything else. The first is timing: you have three months from your Cyber Essentials certification to complete the Plus audit. The second is that the Plus process itself changed with the April 2026 update — and the changes make it materially less forgiving.
Here is what the audit involves, what changed, and how to walk into it confident.
Cyber Essentials vs Cyber Essentials Plus
The controls are the same. The verification is not.
Cyber Essentials is a verified self-assessment. You complete the question set — currently Danzell, published 13 February 2026 and in use for assessment accounts created from 27 April 2026 — against Cyber Essentials: Requirements for IT Infrastructure v3.3. An assessor reviews your answers.
Cyber Essentials Plus adds independent technical testing on top. You cannot hold Plus without first holding the underlying Cyber Essentials certificate, and IASME states that “an organisation can complete their Cyber Essentials Plus audit within 3 months of their last Cyber Essentials certification.”
That three-month window is a hard practical constraint. Book the Plus audit at the same time you start the self-assessment, not after you pass it.
If you have not yet worked through what v3.3 changed, start with our guide to the Cyber Essentials v3.3 April 2026 changes — the Plus audit tests those requirements, so the gap analysis is the same exercise.
What the Assessor Tests
IASME’s own description of the audit covers five areas:
1. External vulnerability scanning. The assessor runs internet-facing scans against your public IP addresses. This is looking for services exposed to the internet that should not be, and for unpatched vulnerabilities on anything reachable from outside.
2. Vulnerability scanning of a device sample. The assessor tests “a sample of devices that is representative of the applicant’s infrastructure”. IASME specifies this “will include servers, desktop computers, laptops, thin clients, tablets and mobile phones. To make sure a full sample is taken, each type of Operating System is required to be tested.”
That last sentence matters. One stray Mac, one Android handset, one Linux server — each operating system in scope pulls at least one device into the sample.
3. Malware protection. The assessor verifies that your malware protection actually works, rather than that a licence exists.
4. User account separation. A check that standard user accounts are separated from administrative accounts — that day-to-day work is not being done from an admin login.
5. Multi-factor authentication on cloud services. The assessor confirms MFA is enabled on your cloud services. IASME describes this as “a check against all cloud services to confirm that the users of the sampled devices are presented with a multi-factor authentication challenge” — every cloud service, not a sample. Under v3.3 this is not a nice-to-have: IASME states that organisations failing to implement MFA for cloud services “whether it is free, included, or a paid option, will now automatically fail the assessment.”
The precise method for each test is set out in the Cyber Essentials Plus Test Specification, which IASME publishes for assessors and makes available so applicants can see what will be carried out. (The word “Illustrative” was dropped from that document’s title at the April 2025 update, when it became the Cyber Essentials Plus Test Specification V3.2.)
How the Device Sample Is Chosen
You do not choose the sample. Since the April 2025 specification update, “the Assessor must verify that the device sample size has been calculated correctly using the method determined by IASME”, and the scope of the Plus assessment “must match the associated Cyber Essentials self-assessment and be verified by the Assessor.”
Two consequences follow:
- You cannot quietly narrow scope for the audit. If your self-assessment declared the whole organisation, the Plus audit covers the whole organisation. Where a sub-set has been excluded, the assessor must confirm it has been segregated correctly.
- Preparing only the sampled devices does not work. Which is precisely what the April 2026 change is designed to catch.
What Changed for Plus in April 2026
IASME confirmed two changes to the Cyber Essentials Plus process, applying to assessment accounts created after 26 April 2026.
Retesting now uses a fresh random sample
Previously, an organisation that failed on sampled devices could remediate those devices and be retested. Under the new rule, you must remediate across all in-scope devices — and at retest the assessor checks the original sample and “a new random sample of devices to ensure compliance across the wider environment.”
If issues are found on the second round, the assessment fails and the underlying Cyber Essentials certificate is revoked. This is the single most consequential change: selective, sample-only patching is no longer a survivable strategy.
The self-assessment is locked before Plus testing starts
IASME states that “organisations will no longer be allowed to adjust their verified self-assessment (VSA) responses based on the results of the CE+ assessment”, and the Terms and Conditions now require the VSA to be “completed, finalised, and remain unchanged prior to the commencement of CE+ testing.”
In practice: answer the question set honestly the first time. You can no longer discover a problem during the audit and retrospectively amend what you claimed.
The Control to Get Right First
Security update management. Under v3.3, security updates rated critical or high risk by the vendor — or carrying a CVSS v3 base score of 7.0 or above, or having no vendor rating at all — must be applied within 14 days of release, across operating systems, firmware, browsers, plugins and applications in scope.
Fourteen days is a hard deadline, and an authenticated vulnerability scan finds a missed patch instantly. It is also the control the new fresh-sample retest rule is aimed at, so a gap here is the hardest to recover from during the audit. If your patching is reactive rather than automated and monitored, fix that before you book the audit.
Passwords are the other perennial source of confusion, and the rules are less onerous than most people assume — see our breakdown of the Cyber Essentials password requirements.
A Pre-Audit Checklist
Work through this with your IT team or provider before the assessor arrives:
- Confirm the three-month window. Diarise the deadline from your Cyber Essentials certification date and book the audit inside it.
- List every operating system in scope. Windows, macOS, iOS, Android, Linux, thin clients. Each one will be sampled.
- Verify patching across the whole estate, not a sample. Run your own authenticated scan first and fix everything, everywhere.
- Inventory every cloud service and confirm MFA is enabled on all of them. Including the small ones — CRM, accounting, file sharing, design tools. MFA available but not enabled is an automatic fail.
- Check administrative account separation. No routine work from admin accounts; no shared admin logins.
- Confirm malware protection is active and reporting on every in-scope device, not merely licensed.
- Finalise the self-assessment before testing begins. You will not be able to change it afterwards.
- Agree the scope and the on-site-versus-remote question with your Certification Body up front.
One Thing to Confirm With Your Certification Body
As of 23 September 2026, the NCSC’s Cyber Essentials resources page lists the Requirements for IT Infrastructure v3.3, in effect from 27 April 2026, alongside the Cyber Essentials Plus Test Specification v3.2 as the published test specification. No v3.3 test specification has been published there. The process changes described above come from IASME directly.
If you are booking a Plus audit now, ask your Certification Body which test specification version they will assess you against and request a copy. It is a fair question and a good assessor will answer it without hesitation.
How Nerdster Helps
We take London and South East organisations through Cyber Essentials and Cyber Essentials Plus from gap analysis to certificate — including the unglamorous part, which is getting patching, MFA coverage and account separation into a state that survives an authenticated scan of a random device sample.
For our managed IT support clients, that groundwork is simply how the estate is run, so Plus becomes a scheduled formality rather than a scramble. If you want a read on where you stand before talking to anyone, our free Cyber Essentials Plus readiness check walks the same ground the assessor will. Certification also tends to be one of the more reliable levers on cyber insurance premiums.
If you have a client or contract asking for Cyber Essentials Plus and you are not sure whether you would pass today, book a call about getting certified. We will tell you where the gaps are before an assessor does.
Sources
- IASME, Cyber Essentials and Cyber Essentials Plus — what is the difference? — iasme.co.uk
- IASME, Important Update: Changes to Cyber Essentials for April 2026 — iasme.co.uk
- IASME, Upcoming Changes to the Cyber Essentials Scheme: April 2026 Update — iasme.co.uk
- IASME, What will the changes be to Cyber Essentials and Cyber Essentials Plus in the April 2025 update? — iasme.co.uk
- NCSC, Cyber Essentials overview — ncsc.gov.uk
- NCSC, Cyber Essentials resources (requirements v3.3 and Plus test specification v3.2) — ncsc.gov.uk
- Claranet, 2026 changes to Cyber Essentials and Cyber Essentials Plus (13 March 2026) — claranet.com
Last reviewed: 23 September 2026. Cyber Essentials requirements are updated regularly — check the current question set and Requirements document before relying on any dated guidance.