Skip to content

Technical controls and assessment

How often do you run vulnerability scans for CE Plus?

Cyber Essentials Plus includes the specified initial technical tests, including external and representative internal testing; remediation can require retesting before a compliant result. These audit checks are distinct from optional continuous vulnerability scanning between annual assessments. Agree the current test specification, asset sample, access and any retest schedule with your assessor.

Short answer

Cyber Essentials Plus includes the specified initial technical tests, including external and representative internal testing; remediation can require retesting before a compliant result. These audit checks are distinct from optional continuous vulnerability scanning between annual assessments. Agree the current test specification, asset sample, access and any retest schedule with your assessor.

Why this matters

Technical-control questions decide whether the self-assessment can be approved. Cyber Essentials is not a paper-only exercise: the applicant must be able to show that secure configuration, patching, access control, malware protection, and firewalls are implemented in the actual environment.

The strongest submissions use evidence from device management, endpoint security, vulnerability scanning, identity controls, and asset registers. If a control is implemented manually, the organisation should still be able to explain ownership, frequency, and how exceptions are handled.

What to check next

  • Apply every qualifying high-risk, CVSS v3 7+ or unspecified-severity fix within 14 days of release.
  • Remove unsupported software or agree the permitted isolated subset with the assessor.
  • Keep endpoint protection, firewall rules, and admin accounts documented.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.