Compliance

Cyber Essentials Plus Preparation and Audit Support

Plus is where claims meet evidence. We run the same scans an assessor will run, fix what they would find, and get you to the audit knowing the outcome.

PREREQUISITE
Valid Cyber Essentials Certificate
DEADLINE
Within 3 Months of CE Certification
METHOD
Hands-On Assessor Testing & Scanning
SAMPLE
Representative Device Sample
In short

What does a Cyber Essentials Plus audit involve?

An assessor independently verifies the same five controls through hands-on testing: authenticated vulnerability scanning of a representative sample of devices, tests that malicious files and web content are blocked, and checks on account separation and multi-factor authentication. It must be completed within three months of your Cyber Essentials certificate.

What the assessor actually tests

Cyber Essentials Plus is not a longer questionnaire. An assessor takes a representative sample across your device types — laptops, desktops, servers where in scope, and mobile devices — and tests them directly. Authenticated vulnerability scanning looks for missing patches and unsupported software on the actual machines rather than trusting your description of them.

They then test that malware protection works in practice by attempting to download and execute benign test files and reach test web content, and they verify that standard user accounts cannot install software, that administrative accounts are separate, and that multi-factor authentication is enforced on cloud services.

  • Authenticated vulnerability scan of sampled devices
  • Malware protection tested against email and web-delivered test files
  • Verification that standard users cannot install software
  • Separation of administrative accounts from everyday accounts
  • MFA enforcement checked on in-scope cloud services

The fourteen-day patch rule is where people fail

The rule is specific: high-severity and critical updates must be applied within fourteen days of release. The scan will find anything outside that window, including third-party software people forget about — browsers, PDF readers, Java runtimes, conferencing clients, and the plugin somebody installed for one project.

This is why we scan before the assessor does. Running the same authenticated scan a fortnight ahead turns a potential failure into a maintenance task, and gives you time to deal with anything that needs a vendor conversation rather than a click.

  • Operating system updates, including feature versions still in support
  • Browsers and their extensions
  • Third-party applications — readers, runtimes, conferencing, utilities
  • Firmware on in-scope devices where the vendor issues security updates
  • Mobile operating system versions past vendor support

Timing matters

Cyber Essentials Plus must be completed within three months of your Cyber Essentials certification. Missing that window means recertifying at the basic level first, which costs time and money for no benefit.

We plan both together from the outset: gap review, remediation, Cyber Essentials certification, pre-audit scan, then the Plus assessment — with the deadline built into the schedule rather than discovered late.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Cyber Essentials Plus — your questions answered

Do we need Cyber Essentials before Cyber Essentials Plus?
Yes. A valid Cyber Essentials certificate is a prerequisite, and the Plus assessment must be completed within three months of it. Missing that window requires recertifying at the basic level first.
How many devices will the assessor test?
A representative sample rather than everything — sized according to your device count and covering each distinct operating system and build type you run. Standard builds therefore make the audit substantially easier and cheaper.
What happens if we fail Cyber Essentials Plus?
You are normally given a defined period to remediate and be retested rather than having to start over. Our pre-audit scan exists to make that scenario unlikely — we want the findings on our report, not the assessor's.
Is Cyber Essentials Plus worth the extra cost?
If a customer or contract requires it, yes, and it carries materially more weight than the self-assessed level precisely because it is independently verified. If nobody is asking for it, basic Cyber Essentials plus a vulnerability assessment often delivers more security value per pound.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about cyber essentials plus?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.