Cyber Essentials Plus Preparation and Audit Support
Plus is where claims meet evidence. We run the same scans an assessor will run, fix what they would find, and get you to the audit knowing the outcome.
What does a Cyber Essentials Plus audit involve?
An assessor independently verifies the same five controls through hands-on testing: authenticated vulnerability scanning of a representative sample of devices, tests that malicious files and web content are blocked, and checks on account separation and multi-factor authentication. It must be completed within three months of your Cyber Essentials certificate.
What the assessor actually tests
Cyber Essentials Plus is not a longer questionnaire. An assessor takes a representative sample across your device types — laptops, desktops, servers where in scope, and mobile devices — and tests them directly. Authenticated vulnerability scanning looks for missing patches and unsupported software on the actual machines rather than trusting your description of them.
They then test that malware protection works in practice by attempting to download and execute benign test files and reach test web content, and they verify that standard user accounts cannot install software, that administrative accounts are separate, and that multi-factor authentication is enforced on cloud services.
- Authenticated vulnerability scan of sampled devices
- Malware protection tested against email and web-delivered test files
- Verification that standard users cannot install software
- Separation of administrative accounts from everyday accounts
- MFA enforcement checked on in-scope cloud services
The fourteen-day patch rule is where people fail
The rule is specific: high-severity and critical updates must be applied within fourteen days of release. The scan will find anything outside that window, including third-party software people forget about — browsers, PDF readers, Java runtimes, conferencing clients, and the plugin somebody installed for one project.
This is why we scan before the assessor does. Running the same authenticated scan a fortnight ahead turns a potential failure into a maintenance task, and gives you time to deal with anything that needs a vendor conversation rather than a click.
- Operating system updates, including feature versions still in support
- Browsers and their extensions
- Third-party applications — readers, runtimes, conferencing, utilities
- Firmware on in-scope devices where the vendor issues security updates
- Mobile operating system versions past vendor support
Timing matters
Cyber Essentials Plus must be completed within three months of your Cyber Essentials certification. Missing that window means recertifying at the basic level first, which costs time and money for no benefit.
We plan both together from the outset: gap review, remediation, Cyber Essentials certification, pre-audit scan, then the Plus assessment — with the deadline built into the schedule rather than discovered late.
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Cyber Essentials Plus — your questions answered
Do we need Cyber Essentials before Cyber Essentials Plus?
How many devices will the assessor test?
What happens if we fail Cyber Essentials Plus?
Is Cyber Essentials Plus worth the extra cost?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about cyber essentials plus?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.