Cyber Essentials Plus remote audit: how the assessor actually tests your controls
The CE Plus audit is less mysterious than it looks. A walkthrough of what the assessor does during the remote audit, device-by-device, and how to prepare so it passes first time.

Section 01
Cyber Essentials Plus remote audit: how the assessor actually tests your controls
Cyber Essentials Plus adds a third-party technical audit on top of the CE self-assessment. The audit sounds intimidating - an independent assessor runs tests on your devices - but it is actually straightforward. The assessor is working through a fixed checklist. This guide explains the current-linked NCSC Plus test specification v3.2, alongside the current technical requirements, to support preparation. Agree applicable delivery-partner procedures with the assessor; preparation does not guarantee a first-time pass.
Section 02
The shape of a CE Plus audit
The current-linked specification has five test cases:
1. Remote vulnerability assessment of in-scope internet-accessible services.
2. Patching checks by authenticated vulnerability scan of representative devices.
3. Malware protection checks appropriate to anti-malware or certificate-based application allowlisting.
4. MFA configuration checks.
5. Account separation checks.
Scope, sub-set segregation and sample calculation must be verified before testing.
Remote delivery may use screen sharing, approved scan tooling and evidence collection. Agree access, testing method and timing with the assessor; a video call alone does not replace the specified tests.
Section 03
What the external scan does
The assessor identifies in-scope internet IP addresses, including IaaS, and uses approved remote vulnerability scanning and the specification's service decision criteria. Appropriate DNS entries can identify dynamic connections. This external test is distinct from the authenticated device patch scan. Preparation can review issues such as:
- Out-of-date TLS configurations (TLS 1.0, 1.1, weak cipher suites).
- Exposed management interfaces (SSH, RDP, database ports).
- Unpatched known-vulnerable services.
- Misconfigured web servers (directory listing enabled, default pages exposed).
How to prepare: run your own scan first. Sign up for the free tier of Censys, Shodan, or Qualys SSL Labs and check what is exposed. Investigate actual findings before testing; these tools do not replace approved assessment scans or establish a measured most-common blocker.
Section 04
How device sampling works
The assessor verifies a representative sample using the delivery partner's calculation method and retains the calculation evidence. Configuration variation and provisioning effectiveness matter, including end-user devices and servers; employee count alone does not prescribe three or ten devices. Cloud services also require representative user-account testing. Agree actual scope and samples before the audit.
On each sampled device the assessor verifies:
Patch currency
The patch test uses an approved authenticated vulnerability scan of sampled devices and checks the specified missing-fix criteria. Windows/Apple update-history screenshots can support preparation but do not substitute for this test. The current requirements cover vendor high/critical, CVSS v3 7+ and unspecified-severity vulnerability fixes within fourteen days of release.
Preparation: make sure Windows Update and Apple Software Update have no pending restarts on the sample devices, and that the update history shows recent installs within the 14-day window.
Malware protection
The assessor selects applicable anti-malware or certificate-based application allowlisting sub-tests. Anti-malware tests include email/browser delivery where applicable, or manual checks as determined by the assessor. The specification requires manual checks where test files did not prove the anti-malware software was configured correctly. Confirm actual updates, scanning/prevention and required website protection rather than assuming a product name proves the complete route.
Preparation: verify effective required malware controls and actual coverage. Defender tamper protection can strengthen the configuration; it is not a universal standalone Plus failure criterion.
Secure configuration
Default accounts disabled, default passwords changed, auto-run disabled, unnecessary software removed. The assessor typically walks through Control Panel / System Settings while you screen-share.
Preparation: remove unnecessary software/accounts and verify actual secure configuration. The mere presence of manufacturer trial software is not a universal standalone Plus failure rule.
MFA on cloud services
The assessor asks the user to sign into M365 / Google Workspace / Okta and verifies that MFA is required. Since v3.3, MFA is mandatory on every cloud service that holds organisational data.
Preparation: verify MFA is enabled for every user before the audit. Verify effective MFA for cloud authentication and wherever available elsewhere, including direct sign-in/recovery. A valid existing MFA session need not generate a fresh prompt on every login; a trusted-location password-only bypass is not effective required MFA.
User access control
The assessor reviews the device's local user accounts. Verify that daily work uses standard privileges and administrative tasks use separate accounts, with unique users and unnecessary accounts disabled. A business reason for privileges does not waive account separation.
Preparation: demote standard users to standard accounts. If a user has local admin because they "need it" - have a documented reason. "They have always had it" is not acceptable.
Section 05
The malware execution test
The assessor sends the user a set of test files - typically via email and via a download from a web server under the assessor's control. The specification distinguishes malware test files from executable attachment/file types. The assessor uses the applicable approved test set and sub-tests; there is no blanket requirement to block every macro-enabled document, ISO or password-protected archive at the gateway.
For malware test files, verify the specified protection against user access. For executable-file email/browser tests, distinguish delivery from execution: the criteria concern whether execution occurs without the required additional interaction/prompt, not whether any executable simply reaches the desktop. Allowlisting and manual-check routes have their own applicable criteria.
Preparation: review the applicable approved malware and executable test behaviour with the assessor. Do not run live malware or assume a gateway product/blanket attachment block is compulsory. Protect against malicious websites and confirm the actual chosen route.
Section 06
Inbound email and web-content filtering
Email and browser delivery form part of the applicable malware test sub-tests. SPF, DKIM, DMARC and broader phishing simulations are useful security work but are not described by this specification as a separate mandatory Plus test case.
Preparation: run your domain through https://dmarc.org/tools/ or Microsoft's DMARC checker. Fix any SPF, DKIM, or DMARC issues before the audit.
Section 07
Common first-time audit failures
Practical gaps to investigate, without claiming a measured first-time cohort ranking:
1. MFA not enforced on every user. "Most users have it" is not sufficient.
2. Required malware protection ineffective on a sampled device.
3. TLS 1.0 still enabled on a public-facing service.
4. 14-day patch window missed on an engineer laptop (they deferred a reboot).
5. Malware or executable handling failing the applicable specified sub-test, rather than attachment delivery alone.
Remediation effort depends on the actual issue. The challenge is that by the time the assessor finds them, the audit window has already compressed. Fix them before the audit, not during.
Section 08
How long does it take?
Illustrative planning steps, not guaranteed test durations:
- Kick-off call: 30 minutes.
- External scan: 2-4 hours (runs in background).
- Device sampling calls: 30-60 minutes per device, the agreed representative sample, calculated under the delivery partner method.
- Email/web filtering tests: 30 minutes.
- Write-up and certification: same day or next business day.
Fig Group Plus timing depends on agreed scope, availability, access, representative sampling and successful testing/remediation. Do not assume universal 2-3-working-day completion or guaranteed same-day issue.
Section 09
Bottom line
CE Plus is not a black box. Read the applicable specification and agree scope/testing with the assessor. Preparation can reduce gaps, but does not guarantee a first-time pass or that every finding can be fixed in an afternoon.
Buy Cyber Essentials Plus Micro (1-9 staff) | See CE Plus pricing | Read the readiness checker
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Choose the right Plus assessment for your organisation
Review your scope, baseline certificate date and device availability before arranging the technical audit. Certification follows a successful assessment; the Basic six-working-hour guarantee does not apply to Plus.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Technical Guides
Cyber Essentials Firewall Requirements: What Assessors Actually Check
The firewall question looks simple but fails more submissions than people expect. This guide covers boundary firewalls, software firewalls, what v3.3 (Danzell) actually says about home routers for remote workers, default credentials, and the cloud firewall configuration assessors expect in 2026.
Read articleTechnical Guides
Malware Protection for Cyber Essentials: What Qualifies and What Does Not
Malware protection looks simple - "we have antivirus" - but the question set asks specifically about configuration, coverage, and fallback approaches. This guide covers what qualifies under v3.3, including the application allow-listing alternative and the most common mistakes during assessment.
Read articleTechnical Guides
Cyber Essentials BYOD rules in 2026: phones, laptops, personal devices
Under v3.3, the BYOD question is harder than it looks. A clear walkthrough of which personal devices are in scope, the sub-set exclusion rules, and how to document both approaches.
Read article

