Skip to main content
    NixInfinity-AI
    Danzell 2026

    Cyber Essentials Plus Audit Methodology Changes 2026

    Published 3 July 2026

    What changed

    • Marking framework – fewer "minor non-conformance" outcomes; more items now sit as pass or fail.
    • Sample sizes – revised to scale more steeply with total device count and cloud account count.
    • Cloud admin tests – assessor will verify MFA prompts on cloud admin consoles, not just user mailboxes.
    • BYOD sampling – BYOD devices must be sampled in line with their share of the user base.

    What did not change

    The five core tests of CE Plus are intact: external vulnerability scan, authenticated internal scan, malware protection check, account separation check and browser / email content test. The 3-month CE-to-CE-Plus window is unchanged.

    How to prepare

    • Patch everything 14 days before the audit window opens, not on the day.
    • Confirm MFA on every admin console, every identity provider, every IaaS root.
    • Have a current device inventory ready, including BYOD.
    • Run a self-scan with the same tooling profile the assessor will use.
    • Make sure the test user accounts you provide are real working accounts.

    Cost impact

    For firms in the 50–250 device band, the new sample size logic adds roughly 10–15% to audit time. See our CE Plus cost guide for current 2026 pricing.

    On-site vs remote

    Most CE Plus audits remain remote under Danzell. On-site is required where remote testing cannot reach the sample (air-gapped environments, certain regulated estates). See on-site vs remote.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions

    Related Cyber Essentials Guides