Cyber Essentials Plus is the technical 'show me' to the 'tell me' of the basic self-assessment. While the basic level is a paper-based exercise, the Plus audit involves a qualified third party arriving to probe your network, scan your devices, and test your users' susceptibility to basic threats. Understanding the specific logistics and technical benchmarks of this day is the difference between a smooth certification and a costly, public-facing failure.
Michael McCarroll— Founder · 20+ yrs GRC, ISO 27001 lead implementer 16 min read Updated June 2026
The Sampling Strategy and Asset Readiness
The audit starts with a sampling exercise where the assessor selects a subset of your devices to test. This isn't a random 'pick anyone'; they will specifically look for a representative sample across all operating systems—Windows, macOS, iOS, and Android—and also different user roles, such as developers and HR staff. You should expect them to test roughly 10% of your fleet, or a minimum of five devices per operating system type, whichever is larger.
Preparation begins with having an up-to-date asset register ready the moment the auditor sits down. If you cannot produce a list of all devices that have accessed your corporate data in the last 90 days, you have failed before you have even begun. The auditor will compare your list against what they see on the network to ensure you aren't hiding 'legacy' machines that haven't been patched since 2018.
Be ready to provide 'hands-on' access. Whether the audit is remote or on-site, a staff member must be present on each sampled device to log in and follow the auditor's instructions. This is a time-consuming process, so ensure your team has cleared their diaries for the day; there is nothing more frustrating for an auditor than waiting twenty minutes for a developer to finish a 'quick call' while the clock is ticking.
The Technical Scan: No Room for Error
The technical core of the day is the vulnerability scan. The auditor will run a scanner—often Nessus or a similar tool—against the sampled devices to look for missing security patches and 'Critical' or 'High' severity vulnerabilities. The threshold for failure is remarkably low: if a patch has been available for more than 14 days and is missing from a device, that is an automatic fail.
The external scan targets your gateway. They are looking for open ports that shouldn't be there, such as RDP (Port 3389) or unencrypted FTP. In the age of remote work, your VPN endpoints will be under heavy scrutiny. Ensure that your firewalls are tightly configured and that any 'temporary' rules created for troubleshooting have been deleted long before the audit starts.
Authenticated internal vulnerability scans on sampled workstations.
External perimeter scans of all public-facing IP addresses.
Verification of 'Supported' status for all installed software.
Check for 'Account Lockout' policies (usually 10 attempts or fewer).
Confirmation that multi-factor authentication (MFA) is active on all cloud services.
Malware Defences and Payload Testing
One of the more interactive parts of the day is the malware protection test. The auditor will attempt to download a series of 'test' files disguised as malware to see if your endpoint protection (EPP) or antivirus blocks them. They will also test if you can execute files that should be blocked by your 'Mark of the Web' settings or local execution policies. This is an objective test of your browser and email security.
They will specifically look at how your system handles different file types like .exe, .zip, and even scripted files like .ps1 or .bat. If a user can download a malicious file and run it without a prompt or a block, your technical controls are deemed insufficient. It is not enough to say 'we have Defender'; you must demonstrate that Defender is actually configured to prevent execution of untrusted code.
The email test is equally rigorous. The assessor will send a series of emails containing ‘malicious’ attachments to a sample mailbox. They aren't looking for the user to be smart; they are testing if your mail filter (be it M365 Business Premium or Google Workspace) strips the attachment before it even reaches the inbox. Ensure your 'Safe Attachments' or equivalent policies are in 'Block' mode, not just 'Monitor' mode.
Administrative Privileges and Default Passwords
The auditor will spend significant time checking your configuration for 'Least Privilege'. Running as a local administrator is the most common reason for failure in UK SMEs. The assessor will manually check the 'Local Users and Groups' on Windows or the 'Users & Groups' pane on macOS to verify that the daily-use account does not have administrative rights. If it does, you will be required to explain why, and 'it's easier for the user' is not an acceptable answer.
Beyond admin rights, they will look for 'Default Passwords'. This applies heavily to your networking hardware—routers, switches, and wireless access points. If the auditor can log into your core switch using 'admin/admin', the audit is over. This also extends to 'Cloud' admin accounts; every single administrative interface must be protected by Multi-Factor Authentication without exception.
Check for local admin rights on standard user accounts.
Validation of 'Strong' password policies or MFA alternatives.
Review of 'Auto-run' and 'Auto-play' settings on removable media.
Verification that BIOS/UEFI passwords are set where applicable.
Mobile Device Management and the BYOD Trap
Mobile devices are the 'dark matter' of the CE+ audit. If your staff use mobile phones to access corporate email or Teams, those devices are in scope. The auditor will want to see that these devices are running a supported version of iOS or Android. For Apple, this generally means the current version or the one previous; for Android, it is far more complex and often leads to older handsets being banned from the network.
The auditor will verify that the devices have a lock screen (PIN, pattern, or biometric) and that they are not 'Jailbroken' or 'Rooted'. This is usually verified via your MDM dashboard. If you don't have an MDM, the auditor is well within their rights to ask to physically see the handsets of the sampled staff to check the settings manually. This is awkward and intrusive, which is why I always recommend implementing a basic MDM before the audit day.
Turn Compliance into Your Competitive Advantage
Don't let manual spreadsheet tracking be the reason you fail your CE+ audit. ISO-STANDARD.app automates the evidence collection and policy management required to maintain continuous compliance, turning security from a tick-box exercise into a competitive edge that wins enterprise contracts.
ISO-STANDARD.app ships a ready-to-adopt Cyber Essentials Plus workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.
Frequently asked questions
How long do I have to complete the Plus audit after the basic certification?
Technically, you have up to 90 days from the date of your basic Cyber Essentials certification to complete the Plus audit. However, I strongly recommend aiming for a 30-day window. This ensures your self-assessment answers are still fresh and the technical state of your environment hasn't drifted significantly, reducing the risk of conflicting evidence.
What happens if we fail one of the vulnerability scans?
A 'fail' during the audit isn't necessarily the end of the road. Most assessors will provide a brief remediation window—usually 2 to 14 days depending on the severity—to fix the identified issues. If you address the vulnerabilities and provide evidence of the fix, you can still achieve certification without restarting the entire process.
Do we have to audit 'Bring Your Own Device' (BYOD) hardware?
Yes, unless you have a robust Mobile Device Management (MDM) solution that can prove strict segregation of business data and compliance with password and update policies. Many firms find it easier to provide corporate handsets for the audit sample rather than trying to audit a diverse range of personal devices.
What specific configuration evidence is checked on the day?
The assessor needs to see your 'Build Standard' or configuration for the operating system and applications. This includes evidence of account lockouts after failed attempts, the removal of default passwords, and that users are not running with local administrative privileges by default.
Action checklist PDF
Mirrors this guide with owners, artefacts & a 30/60/90-day plan.