Skip to main content
    NixInfinity-AI
    Audit failures

    Common Cyber Essentials Plus Failure Reasons (And How to Avoid Them)

    Published 7 July 2026

    1. Browser or plug-in patches older than 14 days

    Chrome, Edge, Firefox and Adobe Reader all patch faster than most patch management cycles. If a sample device has a browser more than 14 days behind the public release, that is a fail. Fix: force auto-update on browsers and run a patch report on the morning of the audit.

    2. Unsupported operating systems still in scope

    Windows 10 devices past end-of-life, ancient macOS versions and unpatchable server operating systems all fail immediately. Fix: remove them from scope (segment and document) or retire them before the audit.

    3. MFA not enforced on cloud admin accounts

    Enforced, not available. If MFA is a "recommendation" for the M365 or Google Workspace global admin, that is a fail. Fix: apply a conditional access policy that enforces MFA on admin roles with no exceptions.

    4. Legacy authentication still switched on

    IMAP, POP and Microsoft 365 EWS basic auth bypass MFA. Assessors test for it. Fix: disable legacy auth at tenant level and confirm no service accounts still rely on it.

    5. Admin accounts able to browse the web or read email

    Account separation is a hard requirement. If your admin account is your daily driver, that fails on inspection. Fix: separate admin identities that only sign in when performing privileged tasks.

    6. Anti-malware disabled, missing or stale on a sample device

    A sample device with Defender disabled or with signatures more than seven days old fails the malware protection control. Fix: verify Defender or your EDR is active with signatures under 24 hours old on every sample device.

    7. Missing MFA on a lesser-known cloud service

    Xero, GitHub, Docusign, HubSpot, Slack – every in-scope cloud service needs MFA. Fix: complete a cloud inventory before the audit and enable MFA everywhere, not just in Microsoft 365.

    8. BYOD in scope but unmanaged

    If staff read email on a personal phone, that phone is in scope. No MDM, no screen lock policy, no minimum OS = fail. Fix: apply a light-touch MDM profile or move BYOD out of scope via a policy that blocks corporate data.

    9. Leavers still active in identity provider

    A single leaver whose account is still enabled is enough to fail access control. Fix: run the leavers list against the tenant the day before the audit and disable anything unexpected.

    10. Test user accounts that do not work

    Assessors need working accounts to run the email and web tests. If the accounts you provide are blocked, expired or missing mailboxes, the audit stalls. Fix: provision real, working test accounts and verify them 24 hours before.

    The pattern behind the failures

    Most CE Plus fails are drift, not ignorance. The controls were correct at CE time and lapsed in the months between. That is why we build a 30-day readiness planinto every CE Plus engagement and run a full pre-audit scan before the assessor connects.

    For the wider audit picture, see Danzell audit methodology changesand the CE Plus cost guide.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions

    Related Cyber Essentials Guides