Compliance · Last updated

Cyber Essentials Plus Audit: What the Assessor Tests

A Cyber Essentials Plus audit tests your devices, patching, malware protection, admin accounts and cloud MFA. What to expect, and the 2026 retest rule.

Nerdster Team

Cyber Essentials Plus is not a harder version of the Cyber Essentials questionnaire. It tests exactly the same five technical controls — but instead of taking your word for it, an assessor gets hands on your infrastructure and checks. IASME, the NCSC’s Cyber Essentials delivery partner, describes it plainly: the audit “can be carried out on site or remotely and includes vulnerability scans of the organisation’s scoped infrastructure.”

Two things trip organisations up more than anything else. The first is timing: you have three months from your Cyber Essentials certification to complete the Plus audit. The second is that the Plus process itself changed with the April 2026 update — and the changes make it materially less forgiving.

Here is what the audit involves, what changed, and how to walk into it confident.

Cyber Essentials vs Cyber Essentials Plus

The controls are the same. The verification is not.

Cyber Essentials is a verified self-assessment. You complete the question set — currently Danzell, published 13 February 2026 and in use for assessment accounts created from 27 April 2026 — against Cyber Essentials: Requirements for IT Infrastructure v3.3. An assessor reviews your answers.

Cyber Essentials Plus adds independent technical testing on top. You cannot hold Plus without first holding the underlying Cyber Essentials certificate, and IASME states that “an organisation can complete their Cyber Essentials Plus audit within 3 months of their last Cyber Essentials certification.”

That three-month window is a hard practical constraint. Book the Plus audit at the same time you start the self-assessment, not after you pass it.

If you have not yet worked through what v3.3 changed, start with our guide to the Cyber Essentials v3.3 April 2026 changes — the Plus audit tests those requirements, so the gap analysis is the same exercise.

What the Assessor Tests

IASME’s own description of the audit covers five areas:

1. External vulnerability scanning. The assessor runs internet-facing scans against your public IP addresses. This is looking for services exposed to the internet that should not be, and for unpatched vulnerabilities on anything reachable from outside.

2. Vulnerability scanning of a device sample. The assessor tests “a sample of devices that is representative of the applicant’s infrastructure”. IASME specifies this “will include servers, desktop computers, laptops, thin clients, tablets and mobile phones. To make sure a full sample is taken, each type of Operating System is required to be tested.”

That last sentence matters. One stray Mac, one Android handset, one Linux server — each operating system in scope pulls at least one device into the sample.

3. Malware protection. The assessor verifies that your malware protection actually works, rather than that a licence exists.

4. User account separation. A check that standard user accounts are separated from administrative accounts — that day-to-day work is not being done from an admin login.

5. Multi-factor authentication on cloud services. The assessor confirms MFA is enabled on your cloud services. IASME describes this as “a check against all cloud services to confirm that the users of the sampled devices are presented with a multi-factor authentication challenge” — every cloud service, not a sample. Under v3.3 this is not a nice-to-have: IASME states that organisations failing to implement MFA for cloud services “whether it is free, included, or a paid option, will now automatically fail the assessment.”

The precise method for each test is set out in the Cyber Essentials Plus Test Specification, which IASME publishes for assessors and makes available so applicants can see what will be carried out. (The word “Illustrative” was dropped from that document’s title at the April 2025 update, when it became the Cyber Essentials Plus Test Specification V3.2.)

How the Device Sample Is Chosen

You do not choose the sample. Since the April 2025 specification update, “the Assessor must verify that the device sample size has been calculated correctly using the method determined by IASME”, and the scope of the Plus assessment “must match the associated Cyber Essentials self-assessment and be verified by the Assessor.”

Two consequences follow:

  • You cannot quietly narrow scope for the audit. If your self-assessment declared the whole organisation, the Plus audit covers the whole organisation. Where a sub-set has been excluded, the assessor must confirm it has been segregated correctly.
  • Preparing only the sampled devices does not work. Which is precisely what the April 2026 change is designed to catch.

What Changed for Plus in April 2026

IASME confirmed two changes to the Cyber Essentials Plus process, applying to assessment accounts created after 26 April 2026.

Retesting now uses a fresh random sample

Previously, an organisation that failed on sampled devices could remediate those devices and be retested. Under the new rule, you must remediate across all in-scope devices — and at retest the assessor checks the original sample and “a new random sample of devices to ensure compliance across the wider environment.”

If issues are found on the second round, the assessment fails and the underlying Cyber Essentials certificate is revoked. This is the single most consequential change: selective, sample-only patching is no longer a survivable strategy.

The self-assessment is locked before Plus testing starts

IASME states that “organisations will no longer be allowed to adjust their verified self-assessment (VSA) responses based on the results of the CE+ assessment”, and the Terms and Conditions now require the VSA to be “completed, finalised, and remain unchanged prior to the commencement of CE+ testing.”

In practice: answer the question set honestly the first time. You can no longer discover a problem during the audit and retrospectively amend what you claimed.

The Control to Get Right First

Security update management. Under v3.3, security updates rated critical or high risk by the vendor — or carrying a CVSS v3 base score of 7.0 or above, or having no vendor rating at all — must be applied within 14 days of release, across operating systems, firmware, browsers, plugins and applications in scope.

Fourteen days is a hard deadline, and an authenticated vulnerability scan finds a missed patch instantly. It is also the control the new fresh-sample retest rule is aimed at, so a gap here is the hardest to recover from during the audit. If your patching is reactive rather than automated and monitored, fix that before you book the audit.

Passwords are the other perennial source of confusion, and the rules are less onerous than most people assume — see our breakdown of the Cyber Essentials password requirements.

A Pre-Audit Checklist

Work through this with your IT team or provider before the assessor arrives:

  • Confirm the three-month window. Diarise the deadline from your Cyber Essentials certification date and book the audit inside it.
  • List every operating system in scope. Windows, macOS, iOS, Android, Linux, thin clients. Each one will be sampled.
  • Verify patching across the whole estate, not a sample. Run your own authenticated scan first and fix everything, everywhere.
  • Inventory every cloud service and confirm MFA is enabled on all of them. Including the small ones — CRM, accounting, file sharing, design tools. MFA available but not enabled is an automatic fail.
  • Check administrative account separation. No routine work from admin accounts; no shared admin logins.
  • Confirm malware protection is active and reporting on every in-scope device, not merely licensed.
  • Finalise the self-assessment before testing begins. You will not be able to change it afterwards.
  • Agree the scope and the on-site-versus-remote question with your Certification Body up front.

One Thing to Confirm With Your Certification Body

As of 23 September 2026, the NCSC’s Cyber Essentials resources page lists the Requirements for IT Infrastructure v3.3, in effect from 27 April 2026, alongside the Cyber Essentials Plus Test Specification v3.2 as the published test specification. No v3.3 test specification has been published there. The process changes described above come from IASME directly.

If you are booking a Plus audit now, ask your Certification Body which test specification version they will assess you against and request a copy. It is a fair question and a good assessor will answer it without hesitation.

How Nerdster Helps

We take London and South East organisations through Cyber Essentials and Cyber Essentials Plus from gap analysis to certificate — including the unglamorous part, which is getting patching, MFA coverage and account separation into a state that survives an authenticated scan of a random device sample.

For our managed IT support clients, that groundwork is simply how the estate is run, so Plus becomes a scheduled formality rather than a scramble. If you want a read on where you stand before talking to anyone, our free Cyber Essentials Plus readiness check walks the same ground the assessor will. Certification also tends to be one of the more reliable levers on cyber insurance premiums.

If you have a client or contract asking for Cyber Essentials Plus and you are not sure whether you would pass today, book a call about getting certified. We will tell you where the gaps are before an assessor does.


Sources

  • IASME, Cyber Essentials and Cyber Essentials Plus — what is the difference? — iasme.co.uk
  • IASME, Important Update: Changes to Cyber Essentials for April 2026 — iasme.co.uk
  • IASME, Upcoming Changes to the Cyber Essentials Scheme: April 2026 Update — iasme.co.uk
  • IASME, What will the changes be to Cyber Essentials and Cyber Essentials Plus in the April 2025 update? — iasme.co.uk
  • NCSC, Cyber Essentials overview — ncsc.gov.uk
  • NCSC, Cyber Essentials resources (requirements v3.3 and Plus test specification v3.2) — ncsc.gov.uk
  • Claranet, 2026 changes to Cyber Essentials and Cyber Essentials Plus (13 March 2026) — claranet.com

Last reviewed: 23 September 2026. Cyber Essentials requirements are updated regularly — check the current question set and Requirements document before relying on any dated guidance.

Cyber EssentialscertificationauditcomplianceMFA

FAQ

Cyber Essentials Plus Audit: your questions answered

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The technical controls are identical. Cyber Essentials is a verified self-assessment — you answer the question set and an assessor reviews your answers. Cyber Essentials Plus adds an independent hands-on audit in which an assessor tests a representative sample of your actual devices, and MFA on all your cloud services, to confirm the controls are genuinely in place.

How long do I have to complete Cyber Essentials Plus after Cyber Essentials?

IASME states that an organisation can complete their Cyber Essentials Plus audit within 3 months of their last Cyber Essentials certification. Miss that window and you have to redo the self-assessment before the Plus audit can proceed.

What does the Cyber Essentials Plus assessor actually test?

IASME describes the audit as covering external internet scans of your public IP addresses, vulnerability scanning of a representative sample of devices across every operating system in use, verification of malware protection, a check on user account separation, and confirmation that multi-factor authentication is enabled on cloud services. The audit can be carried out on site or remotely.

Are there separate audit questions for Cyber Essentials Plus?

No. The questions are the Cyber Essentials self-assessment question set, currently Danzell, and the Plus audit tests whether your answers hold in practice. Since April 2026 those answers must be finalised before Plus testing begins and cannot be changed afterwards.

Can Cyber Essentials Plus be done remotely?

Yes. IASME states the audit can be carried out on site or remotely. Which is appropriate depends on your infrastructure and how your devices are managed — agree it with your Certification Body before booking.

What happens if devices fail the Cyber Essentials Plus scan?

From the April 2026 update, you must remediate across all in-scope devices, not just the ones sampled. The assessor then retests the original sample plus a new random sample of devices. If issues are found again, the assessment fails and the underlying Cyber Essentials certificate is revoked.

Do I need Cyber Essentials Plus or is Cyber Essentials enough?

It depends entirely on who is asking. Many public sector and MOD-linked contracts, and a growing number of private sector clients in financial and professional services, specify Plus by name. If nobody has asked for Plus, standard Cyber Essentials is usually the proportionate starting point.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report