Cyber Essentials Plus
Will you pass the Plus audit? Sixteen checks, five tests
Cyber Essentials Plus is not a questionnaire. An assessor tests your systems in front of you. Here is exactly what they do, and what has to be true before audit day.
Nothing you tick here is saved or sent anywhere. It is a working sheet for you.
Remote vulnerability assessment
The assessor finds every internet address your organisation uses, scans them, and looks at each service that answers from the outside.
What is in scope: Every internet facing address, including cloud instances. Nothing is sampled here, it is all of them.
Patching, checked with a credentialed scan
The assessor runs a scan with a login on a sample of your devices and servers, and looks for anything the vendor rates critical or high, or anything scoring 7 or more on the standard severity scale.
What is in scope: A representative sample of staff devices, servers and cloud instances.
Malware protection, tested for real
Three parts. The assessor emails test files to a real mailbox and watches what arrives. They watch someone download test files in a browser. Then they check your anti-malware logs.
What is in scope: The same sampled devices, plus any server with a desktop someone logs in to.
Multi-factor authentication
The assessor watches a normal user and an administrator sign in to each of your cloud services, from an untrusted device or a private browser window.
What is in scope: Every cloud service you use. At least one normal user and one administrator for each.
Account separation
The assessor watches a standard user account try to run something administrative on each sampled device.
What is in scope: Every sampled device. This one is not a sample of a sample, they all get tested.
How much gets tested
- Test 1 covers every internet facing address. Nothing is sampled.
- Tests 2, 3 and 5 use a representative sample of your devices, often around a tenth of them. The more your devices differ from one another, the larger that sample gets.
- Test 4 needs one normal user and one administrator on every cloud service.
A tidy, consistent estate is tested with a smaller sample than a mixed one. That is worth knowing before you buy anything new.
Do the basic certificate first
If you achieve the verified self-assessment Cyber Essentials certificate less than three months before your Plus audit, you do not have to repeat the self-assessment questions. Leave it longer and you do it twice.
Want us to get you ready?
The checklist above tells you what good looks like. Closing the gaps is the work. We go through your devices, your cloud services and your patching with you, tell you plainly what would fail on the day, and stay with you until it would not. Tell us your audit date and we will tell you honestly whether it is doable.
Paid support. We will come back with scope and a price before anything starts.
Who can actually certify you
Only an IASME licensed Certification Body can carry out a Cyber Essentials Plus audit and issue the certificate. CyberSafe Coach gets you ready for it. We are not a Certification Body, so book your audit slot with one directly, and book it early if you are working to a tender deadline.
The five tests, the 14 day patching rule and the sampling rules on this page come from the Cyber Essentials Plus Test Specification published by the National Cyber Security Centre, read at source on 22 September 2026. The three month rule comes from the IASME Cyber Essentials frequently asked questions. Check both before your audit in case a newer version has been published.
