Back to articles

What actually happens in a Cyber Essentials Plus audit

By , founder and reviewer at BrightCertPublished Reviewed

Part of our Cyber Essentials vs Cyber Essentials Plus

Short answer

Cyber Essentials Plus adds an independent technical audit on top of the same self-assessment that standard Cyber Essentials uses. An assessor from an IASME-licensed Certification Body runs five test cases against a representative sample of your devices and cloud services. It has to happen within three months of your Cyber Essentials certification. The part most organisations do not plan for is that the assessor mostly watches your people attempt things on their own machines, so the day needs the right humans free, not just the right settings.

Most descriptions of a Cyber Essentials Plus audit stop at “an assessor tests your systems”, which makes it sound like something done to your network while you get on with your day. It is not really that. Three of the five test cases are a qualified assessor sitting with one of your staff, watching them try to open a file, sign in to a service, or install something — and recording what happens.

Where the audit sits, and the clock attached to it

Plus is not a separate scheme. It is standard Cyber Essentials — the same five controls, the same self-assessment — with a technical audit added on top to verify that what you described is actually true on the machines. If you want the comparison in full, the Cyber Essentials vs Cyber Essentials Plus guide covers how the two differ on cost, timeline and assurance.

Two dates govern the sequence, and both catch people out.

The audit must be completed within three months of your Cyber Essentials certification. Certify inside that window and you do not repeat the self-assessment questions stage. Let it lapse and you are starting the self-assessment again before you can book the audit — which is a scheduling problem, not a technical one, and the most avoidable way to lose a month.

Your self-assessment answers are locked before testing begins. Since the April 2026 update, the verified self-assessment has to be completed, finalised and unchanged before Plus testing starts. You cannot quietly revise an answer once the assessor is in. Anything preparation turns up has to be fixed on the front side of that line.

The five test cases, in the order they run

The published test specification sets these out as five numbered test cases. The third column is the one to read if you are planning the day, because it is where the audit stops being a technical exercise and starts being a diary exercise.

The five Cyber Essentials Plus test cases, what the assessor does in each, and what the organisation has to have ready
Test caseWhat the assessor doesWhat you need ready
1. Remote vulnerability assessmentAn external scan of the internet-facing addresses in scope, looking for services that should not be reachable and for known vulnerabilities in the ones that should.A confirmed list of your external IP addresses, agreed before the day. Nobody needs to be present for this part.
2. Patching, by authenticated scanA credentialed vulnerability scan of each sampled device — logged in, not viewed from outside — checking what is installed and what is missing.An account the scanner can log in with on each sampled device, and the devices switched on and reachable for the duration.
3. Malware protectionInert test files are sent to a real mailbox and offered from a website, and your user is watched trying to open and run them. Devices using application allow listing are checked differently.A real user at a real device, with their normal mailbox and normal browser. Not an administrator, and not a clean machine built for the occasion.
4. Multi-factor authenticationA user and an administrator sign in to each cloud service from an untrusted device or an incognito session, and the assessor watches for the MFA prompt.One standard and one administrative account for every cloud service in scope, and the people who hold them available to log in.
5. Account separationA standard user attempts to run an administrative process on every sampled device. The pass is being stopped and asked for separate credentials.The person who normally uses each sampled device, signed in as themselves with their day-to-day account.

The patching test has a specific bar, and it is arithmetic

Test case 2 is the one that fails most often, and it is worth knowing exactly where the line is rather than hoping you are on the right side of it. The authenticated scan looks for vulnerabilities that meet any of three criteria: the vendor describes the fix as critical or high risk; the issue has a CVSS v3 base score of 7 or above; or the vendor gives no detail about what the update fixes at all.

If any of those has a fix that has been available for more than 14 days, that is a fail. Not a discussion about compensating controls — a fail.

So the practical move before an audit date is not “patch everything”. It is to run updates on every in-scope device in the fortnight before the assessor arrives, and to check the devices that do not get used daily. The laptop in a drawer, the machine belonging to someone on leave, and the server nobody logs into are the three that reliably carry a fix that went public five weeks ago. Unsupported software is the harder version of the same problem: no updates exist, so it cannot be patched into a pass and has to be replaced or removed from scope.

How the device sample is chosen

On anything but the smallest network, testing every device is impractical, so the assessor tests a representative sample. Everything inside the scope boundary is eligible: end user devices that can reach organisational data, internally hosted servers, and cloud services of every type.

Three things about sampling are worth knowing before you agree a scope.

  • Every operating system in scope has to be represented. A standardised, well-provisioned estate can be covered by a small number of samples. A varied one cannot. Two people on an unusual setup will pull their machines into the sample and can enlarge it.
  • The sample size is not the assessor’s opinion. It is calculated by a method IASME sets, the assessor has to verify it was calculated correctly, and the Certification Body has to keep evidence of the calculation for at least the life of the certificate.
  • Cloud services are sampled by account, not by device. Every cloud service in scope needs at least one standard user and one administrative user tested. That is the point at which forgotten subscriptions become expensive, so the list of what you actually use has to be right before scoping, not during.

Because scope drives the sample and the sample drives the effort, scope is also what drives the quote. That is covered in the cost guide.

The part nobody warns you about: it is observed, not automated

Read the test descriptions closely and the same verb keeps appearing. The assessor observes the user attempting to open the test attachment. The assessor observes the user accessing the cloud service. The assessor observes a standard user attempting to run an administrative process. This is a supervised session with your staff in it.

Three consequences follow, and all three are logistical rather than technical.

  1. Real people on real devices. The malware tests need a genuine user, using their own mailbox and their own browser on the machine they use every day. A freshly built laptop is not a sample of your estate, and an administrator clicking through the tests does not demonstrate what a standard user experiences.
  2. Availability is a real dependency. If the sample includes a device belonging to someone on annual leave, that is not a small problem. Book the audit around the people whose devices are likely to be sampled, and tell them beforehand what will be asked of them — the malware test is uncomfortable if it is a surprise.
  3. Test files are inert by design. Nothing harmful is delivered to your network. They are known, benign files used to check whether your protection notices, and the whole exercise is arranged with you in advance.

What happens when something fails — and what changed in 2026

A failed test case is not the end of the process. You remediate the issue and retest. What changed in the April 2026 update is how much the retest covers, and it is a meaningful tightening.

Previously a retest could reasonably be read as rechecking what failed. Now the assessor rechecks the original sample and tests a new random sample as well. The intent is plain: to establish that the fix reached the whole estate rather than the specific devices that got caught. A second failure means the certification is not awarded.

This changes what a sensible response to a failure looks like. Patching the three laptops that failed and rebooking used to be a viable strategy. It is now the strategy most likely to fail twice, because the retest deliberately looks somewhere else. If one device was missing an update because a process did not reach it, the honest question is which other devices that process also does not reach.

Remote or on-site

Both are used. Remote delivery has become common: the assessor works over a screen share while your staff drive their own machines, which suits a distributed team and removes travel from the quote. On-site suits estates with physical constraints, restricted networks, or devices that cannot be reached remotely.

It is a conversation to have with the Certification Body early, because it affects scheduling and cost. What it does not affect is difficulty. The same five test cases are run, against the same criteria, either way — remote is not a lighter audit.

What to have ready on the day

None of this is difficult. All of it takes longer than the morning of the audit, which is the argument for reading it now rather than the night before.

  • A confirmed and unchanged verified self-assessment, finalised before testing starts.
  • The external IP addresses in scope, agreed in advance.
  • Every in-scope device switched on, reachable, and updated — including the ones that are not in daily use.
  • Credentials the authenticated scan can use on each sampled device.
  • One standard and one administrative account for each cloud service, with the people who hold them available.
  • The users whose devices are likely to be sampled, briefed and free — not their IT provider standing in for them.
  • An answer for any unsupported software, since it cannot be patched into a pass.

If you want to work through the underlying controls first, the Cyber Essentials checklist covers them with owner and status columns, and the requirements v3.3 guide explains what each control asks for.

Who can carry out the audit

Only an assessor at an IASME-licensed Certification Body can run a Cyber Essentials Plus audit, and only a Certification Body can issue the certificate. That is not a formality — the independence is the entire point of the Plus level, and no preparation service can stand in for it or shorten it.

What preparation can do is make sure the audit is the first time nobody is surprised. The five test cases map onto the same five control areas the self-assessment covers, so the gaps that would fail an audit are largely findable before you book one.

Frequently asked questions

What actually happens during a Cyber Essentials Plus audit?

An assessor from an IASME-licensed Certification Body runs five test cases: an external vulnerability scan, an authenticated scan of a sample of your devices, malware protection tests delivered by email and by browser, a multi-factor authentication check on your cloud services, and an account separation check. Most of them involve the assessor observing one of your staff attempting something on their own device, rather than software running in the background.

How long do I have between Cyber Essentials and Cyber Essentials Plus?

Three months. The Plus audit has to be completed within three months of your Cyber Essentials certification. If you certify to Plus inside that window you do not repeat the self-assessment questions stage.

How many devices does the assessor test?

A representative sample rather than everything, sized by a method IASME sets and verified by the assessor, who must retain evidence of how it was calculated. Every operating system and device type in scope has to appear in the sample. Cloud services are tested with at least one standard and one administrative account each.

What happens if we fail part of the audit?

You remediate and retest. Since the April 2026 update the retest is wider than it used to be: the assessor rechecks the original sample and also tests a new random sample, to establish that the fix reached the whole estate rather than the devices that were caught. A second failure means the certification is not awarded.

Is the Cyber Essentials Plus audit remote or on-site?

Both are used, and it is a matter for the Certification Body and the shape of your estate. Remote delivery is common, with the assessor observing over a screen share while your staff drive their own machines. Remote does not make it lighter — the same five test cases are run either way.

Can we change our self-assessment answers once the audit starts?

No. As of the April 2026 update the verified self-assessment must be completed, finalised and unchanged before Plus testing begins. Anything you discover during preparation has to be corrected before that point, not during the audit.

Does BrightCert carry out the Cyber Essentials Plus audit?

No. The audit can only be carried out by an assessor at an IASME-licensed Certification Body, and only they can issue the certificate. BrightCert helps you find the gaps beforehand, across the same five control areas the audit tests.

Check your readiness across the same five control areas the Plus audit tests, and see which gaps to close before you book an assessor.

Start your assessment

BrightCert helps UK businesses prepare for Cyber Essentials by assessing readiness, identifying gaps, and producing a practical report. BrightCert does not issue the official Cyber Essentials certificate. That comes from an IASME-licensed Certification Body.

Sources: NCSC: Cyber Essentials Plus test specification · IASME: changes to Cyber Essentials for April 2026 · NCSC: Cyber Essentials resources