Cyber Essentials Plus is decided by a hands-on technical test of a sample of your real devices. The test specification is published, so the main failure conditions are known in advance.

Six issues account for much of the work:

  • A patch left outstanding for more than 14 days.
  • Malware protection that allows a test file through.
  • A cloud service that does not require a second factor.
  • A standard user account that can install software.
  • An internet-facing service that fails the external scan.
  • A legacy system that relies on virtual patching.

These issues may not appear in a self-assessment questionnaire. A questionnaire records what you believe is in place. The Plus audit checks what your devices actually do.

Reading the test conditions before the assessor arrives can make a big difference. It can help you avoid a failed assessment, a retest and the extra cost that comes with it.

Cyber Essentials Plus is an audit, and the assessor does the testing

The basic certification is a verified self-assessment. You answer the questions, someone reviews the answers, and the certificate follows. Cyber Essentials Plus keeps the same five controls and adds an independent assessor who tests them on a sample of your equipment. That sample determines how much of your estate the assessor will examine. The NCSC Cyber Essentials Plus Test Specification requires assessors to test a representative sample of end-user devices, servers and cloud instances. The assessor must also confirm that the sample size has been calculated correctly.

The certifying body keeps evidence of that calculation for at least the lifetime of the certificate.

Standardised builds can reduce the amount of testing required. For example, if you use a fleet of identically configured laptops, the assessor may only need to test a small number of representative devices. A fleet set up individually over six years is not.

One point of vocabulary before the six. The specification defines five test cases; the six failure conditions below sit across them, with two of the six falling inside the patching test case. If you are still deciding which certification you need, our step-by-step Cyber Essentials process guide sets out both routes and the timeline for each.

1. A missing patch with a CVSS score of 7 or above

The authenticated vulnerability scan is the longest part of the assessment. The assessor scans your sampled devices and flags anything the vendor describes as critical or high risk, anything with a CVSS v3 base score of 7 or above, and anything where the vendor gives no severity information at all.

The fail condition is narrower than the flag. A flagged vulnerability fails the test only where a vendor fix has been available for more than 14 days. Where no fix exists, or the fix appeared last week, you are inside the rules.

So the test measures your patching cadence and not your patch level on any given day. A business patching monthly can fail an assessment booked in the third week of the month and pass one booked in the first, which is our reading of how the 14-day condition plays out against a monthly cycle, and not something the specification states. Third-party software is where we see this most often: operating systems tend to update themselves, while PDF readers, browsers, conferencing clients and design tools installed by individual users do not.

2. Malware protection that lets a test file through

The assessor tests malware protection twice, once through email and once through the browser.

The email test starts with a baseline message containing no attachments to confirm delivery works. The assessor then sends test files, one per email. Two conditions can cause a failure: a malware test file reaches the user without access being blocked, or an executable arrives and runs without requiring any additional user interaction. The browser test repeats the exercise with downloads from a website owned by the certifying body.

Organisations using certificate-based application allow listing follow a different route through this control. The test checks that unsigned executables and files with untrusted certificates cannot run. For organisations using the anti-malware route, the most common risk we see is a mail filter that removes attachments before they reach the endpoint.That satisfies the delivery requirement but can still fail the manual check. The assessor also reviews the logs to confirm that anti-malware software remains active, works correctly and receives updates in line with the vendor’s configuration instructions.

3. A cloud service that never asks for multi-factor authentication

The assessor watches a real user and a real administrator sign in to each of your cloud services from an untrusted device or an incognito session. A prompt for a second factor passes. No prompt fails.

Every cloud service is tested for both user and administrative access, though services sharing one authentication provider need only one test per provider. Microsoft 365 behind conditional access covers a great deal of ground in one go. The finance package somebody signed up for on a card in 2021 does not, and in our experience it is the one that goes unmentioned.

Under the April 2026 requirements, multi-factor authentication is mandatory on all cloud services where the service offers it, which closes off the argument that a given tool was too small to bother with. Our piece on phishing-resistant identity for UK businesses covers what to move to once a second factor is in place everywhere.

4. A standard account that can install software

This test takes a minute. The assessor asks a user logged in with a normal account to run an administrative process, and repeats it on every sampled device. A prompt for separate credentials passes. The process running without one fails.

Local administrator rights granted years ago to fix a printer problem survive laptop refreshes, because the account is migrated with its group memberships intact. Nobody notices until an assessor sits down at that particular machine.

5. An internet-facing service that fails the external scan

Before touching your devices, the assessor identifies every IP address you use, including infrastructure hosted with a cloud provider, and scans the recommended set of TCP and UDP ports. Each internet-accessible service is then evaluated against the specification’s criteria, and every one has to pass for the test case to pass. Exposure on its own does not fail you; failing the evaluation does.

In our experience the problem is inventory. A firewall rule opened for a supplier’s remote support tool, a test environment stood up on a spare address, an old VPN endpoint left listening after its replacement went in. Businesses know what they meant to expose, and the scan reports what they do expose.

6. A legacy system propped up by virtual patching

The specification closes off one workaround directly. Virtual patching, where a network device intercepts and blocks exploit traffic aimed at an unpatched system, is described as not an acceptable mitigation for the security vulnerabilities of legacy unsupported operating systems long term, and so will not be recognised as a mechanism for compliance.

That wording matters for anyone running a machine tool. A laboratory instrument or a line-of-business application tied to an operating system the vendor stopped supporting. The specification sets no time limit and grants no temporary exception, so virtual patching does not become a compliance route at any point. The two ways forward are genuine segregation, so the device sits outside the scope, or replacing the underlying system. Where an insurer has accepted a compensating control, that acceptance does not carry over to this assessment.

What changed in April 2026, and why a second failure now costs a certificate

Cyber Essentials moved to v3.3, and IASME’s update on the April 2026 changes sets out the full list. Note first how it commences: the changes apply to assessment accounts created after 26 April 2026, and the v3.3 requirements apply to applications registered after that date. An organisation whose assessment account was created before that date has six months to certify under the previous version, so which rules you face depends on when the account was opened and how quickly you move.

What changed for the Plus audit

Three changes bear on the Plus audit. Two new auto-fail questions, A6.4 and A6.5, cover installing high-risk and critical security updates within 14 days of release, which turns the patching expectation from a scan result into a declared commitment. Once Plus testing has taken place, you can no longer change your self-assessment answers. That means an optimistic answer written in March can cause problems when testing starts in May. Update management retests also go beyond checking the devices that failed. The assessor rechecks the original sample and selects a new random sample of devices. So, fixing the three laptops that failed and presenting those same three again will not be enough to close the issue.

The change with the sharpest edge concerns what a second failure costs. IASME’s wording is that a second failure results in revocation of the verified self-assessment certificate, so the consequence reaches back to the basic certification underneath, not only to the Plus attempt. Preparation was always worth an afternoon. It is now worth more than that.

 Cyber EssentialsCyber Essentials Plus
How it is verifiedSelf-assessment, reviewedHands-on assessor testing
What gets examinedYour answersA calculated sample of real devices and cloud accounts
Vulnerability scanningOutside the assessmentInternal authenticated scan and external scan
After a failureFix and resubmitRetest, covering the original sample plus a new random one
Cost of a second failureReapplyVerified self-assessment certificate revoked

Both certifications run for 12 months, so a Cyber Essentials renewal brings the same tests round again. Treating the six conditions as an annual operating standard costs less than treating them as an exam.

Preparing for a Cyber Essentials Plus audit

Four things clear most of the ground before an assessor arrives:

  1. Run an authenticated vulnerability scan yourself and resolve everything at CVSS 7 or above where a fix has existed for more than a fortnight.
  2. List every cloud service anyone in the business signs into, including the ones bought on expenses, and confirm each one prompts for a second factor.
  3. Check whether any user account can install software without separate credentials.
  4. Produce an honest inventory of what your internet connection exposes.

That leaves malware protection and any legacy system, which need a decision instead of a check. The devices you feel least confident about are the ones to look at first, because a random sample eventually reaches them.

We are an authorised Cyber Essentials certificate issuing body. We run assessments for businesses across the North East and throughout the UK.Our Cyber Essentials service and pricing page explains what each tier includes and how pricing works by user band. Before anything is submitted, we carry out an initial audit. This shows you where you stand and highlights any areas that may need attention.