- Amy Osborne, Head of Audit Services (Pera-Prometheus)
Key Takeaways
- Cyber Essentials Plus tests the same five controls as Cyber Essentials, but they are independently verified by an assessor instead of being self-certified.
- The assessor starts by confirming your declared scope matches your actual network, then runs vulnerability scans against a representative sample of your devices.
- Missing high risk or critical security updates beyond 14 days is one of the most common reasons organisations do not succeed in achieving CE+.
- Multi factor authentication (MFA) must be enabled on every cloud account, where it is available, or it is an automatic fail.
- If any vulnerabilities are found, you get 30 days to fix them, across every device in scope, not just the ones that were tested.
Plenty of organisations pass the Cyber Essentials self-assessment and then feel uneasy about the next step. Cyber Essentials Plus adds an independent audit to the assessment process and for those business’ who have not experienced a CE+ assessment before, it can seem to be a confusing and difficult target to achieve. The reality is far less mysterious. A Cyber Essentials Plus audit is a structured, process that checks whether the controls you have claimed for your CE self-assessment are working in practice. This post walks through what happens on the day, in plain terms, so you know what to expect and how to walk in ready.
What Cyber Essentials Plus Actually Is
Before going into too much detail, it helps to be clear on what Cyber Essentials is. Cyber Essentials is a verified self-assessment. You complete the questionnaire about your cyber security and your business’ compliance across 5 control areas, a senior person signs a declaration, and a certifying body reviews your answers. This Cyber Essentials self-assessment is where certification begins.
Cyber Essentials Plus covers the same five controls, but an assessor independently tests them to confirm they work in practice. As an approved certifying body for both Cyber Essentials and Cyber Essentials Plus, Pera Prometheus guides organisations through both levels. If you are still weighing up which one you need, our post on Cyber Essentials vs Cyber Essentials Plus explains the difference in full.
The five controls set out by the NCSC are:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
Both levels, of Cyber Essentials, are built on these control areas. The difference with Cyber Essentials Plus is simply the Certification Body conducts physical checks. These checks begin with your scope.
Step One: The Scope Check
Before any scanning starts, the assessor confirms that the scope you declared matches your real network. ‘Scope’ is the boundary of what is being assessed, meaning which devices, users, cloud services and locations are included. If you claimed part of your network was separated and left out, the assessor verifies the separation is for a genuine and justifiable reason. Getting this wrong is one of the simplest ways to fail, which is why we cover it fully in our post on Cyber Essentials scoping. Once the scope is agreed and confirmed, the assessor moves on to the technical testing.
Step Two: The Vulnerability Scan and Device Sample
This is where the Cyber Essentials Plus requirements go beyond self-assessment. The assessor scans every internet-facing address your organisation uses, looking for known weaknesses that an attacker could exploit from the outside. They then take a representative sample of your end user devices, such as laptops, desktops, servers and mobiles, and run an authenticated scan on them. Authenticated simply means the scan logs in like a real user, so it can see the software installed, the updates applied and how each device is set up. It is a more thorough review than an external scan alone.
The sample is chosen to reflect your different device types and operating systems, so you cannot pass by preparing only a handful of machines. That brings us to the things that most often go wrong.
Common Challenges for Organisations
The single most common failure is patching, which is one of the core Cyber Essentials requirements. Under the April 2026 update to Cyber Essentials, high risk and critical security updates for operating systems, applications and firmware must be applied within 14 days of release. If the scan identifies devices which have fallen outside the 14 day patch window, this will result in a non-compliance which ultimately could result in failing the audit.
The second common trap is cloud security. Multi Factor Authentication (MFA) must be enabled on every cloud service where it is available. MFA may come with your license or it may be an additional cost. Leaving it switched off is an automatic fail. Our posts on cloud in scope and what changed in April 2026 explains both points in more detail.
If Something Fails: The 30 Day Fix
A failure is not the end of the process, in fact see it as a positive – the assessment has found a vulnerability that you didn’t know you had, but you found and fixed it before an attacker did. If the assessor finds an issue, you are given 30 days to fix it and provide evidence of doing so. The important detail is that you must fix it across every device in scope, not only the ones that were sampled. A missed patch on the tested laptop suggests the same gap exists elsewhere, so the whole estate has to be brought up to standard.
Handled properly, most organisations clear these items well within the window and go on to successfully certify. Working through a Cyber Essentials checklist against the five controls before your assessment, is the simplest way to check your readiness and is what makes the audit a little more straightforward.
Large Enterprises
The Cyber Essentials scheme was designed as a basic security standard for SMEs, however, it is now expected of most organisations, particularly within defence supply chains. For large organisations with large networks and 1000s of end points, this can seem unachieveable – don’t worry, Pera Prometheus has assisted a number of Large Enterprises prepare for and achieve Cyber Essentials and Cyber Essentials Plus, success lies within preparation and engagement.
Ready to Take the Next Step?
A Cyber Essentials Plus audit is far less daunting once you know what the assessor will actually do. As a certifying body for Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification Level 0, Pera Prometheus works with organisations of every size, to prepare for exactly this. Visit our dedicated CE & CE+ webpage to find out more, request a quote, and chat with us about where your organisation is on its certification journey.
Frequently Asked Questions
Q: How long does a Cyber Essentials Plus audit take?
A: For most organisations the testing takes 1 – 2 days, though larger or more complex networks can take longer. How well you have prepared beforehand is the influencing factor for this.
Q: Do I need Cyber Essentials before Cyber Essentials Plus?
A: Yes. You must hold a valid Cyber Essentials certificate first, and the Plus audit must be completed within 90 days of your CE pass date. If more than 90 days have passed, the Cyber Essentials self-assessment must be completed again before the Cyber Essentials Plus assessment can take place.
Q: Is the audit done remotely or on site?
A: All CE & CE+ audits are carried out remotely using secure tools. This reduces the cost and time taken to complete the assessment
Q: What happens if we fail part of the test?
A: You are given 30 days to fix the issue across all devices in scope, ready for the assessor to conduct one final scan.. Fix it in time and you can still certify.
Q: How long is the CE+ certificate valid for?
A: Twelve months. You reassess each year to keep it current and to stay eligible for benefits such as the free cyber insurance for smaller organisations.
Stay Safe, Stay Secure


