Cyber Essentials Plus Audit Methodology Changes 2026
Published 3 July 2026
What changed
- Marking framework – fewer "minor non-conformance" outcomes; more items now sit as pass or fail.
- Sample sizes – revised to scale more steeply with total device count and cloud account count.
- Cloud admin tests – assessor will verify MFA prompts on cloud admin consoles, not just user mailboxes.
- BYOD sampling – BYOD devices must be sampled in line with their share of the user base.
What did not change
The five core tests of CE Plus are intact: external vulnerability scan, authenticated internal scan, malware protection check, account separation check and browser / email content test. The 3-month CE-to-CE-Plus window is unchanged.
How to prepare
- Patch everything 14 days before the audit window opens, not on the day.
- Confirm MFA on every admin console, every identity provider, every IaaS root.
- Have a current device inventory ready, including BYOD.
- Run a self-scan with the same tooling profile the assessor will use.
- Make sure the test user accounts you provide are real working accounts.
Cost impact
For firms in the 50–250 device band, the new sample size logic adds roughly 10–15% to audit time. See our CE Plus cost guide for current 2026 pricing.
On-site vs remote
Most CE Plus audits remain remote under Danzell. On-site is required where remote testing cannot reach the sample (air-gapped environments, certain regulated estates). See on-site vs remote.
