A Cyber Essentials Plus assessment is a structured technical audit carried out by a qualified assessor against a defined test specification. A representative sample of your devices, workstations, laptops and mobile devices across each build type, is selected, and the assessor verifies the five controls in practice.
Expect an external vulnerability scan of your internet-facing services, authenticated scans of the sampled devices to check patching and configuration, tests that malware protection blocks known-bad files and downloads, email and browser-based payload tests, and verification of MFA on cloud services and separation of admin accounts. The 2026 methodology update also introduced checks designed to catch organisations that patch selectively just before assessment day.
If a contract simply says “Cyber Essentials”, check the wording carefully, an increasing share of buyers now specify Plus, and the two are not interchangeable.
Most Plus failures are not exotic. They come from the gap between what an organisation believes about its estate and what an authenticated scan actually finds. A device missing three months of patches, an unsupported browser plugin, or a shared local admin password will surface within minutes of the audit starting.
Our approach is to run the same tests before the real audit. A pre-audit dry run against the current CE+ test specification means every finding is fixed on our time, not discovered on assessment day.
A failed Plus audit means paying for reassessment and, if your 3-month window from the basic pass expires, redoing the self-assessment too. A dry run is far cheaper than a second audit.
What actually happens between booking a Plus assessment and receiving the certificate, based on the 2026 methodology.
Register your interest and we’ll assess your estate against the current CE+ test specification, so when we launch, you’re first in the audit calendar.