Skip to main content
    NixInfinity-AI
    CE Plus

    CE Plus On-Site vs Remote Audit: Which to Choose

    Published 16 June 2026

    What an audit actually involves

    A CE Plus audit covers four technical tests: an authenticated vulnerability scan on a sample of devices, an email-content test, a web-content test, and an account-separation/MFA review. The same tests run whether the auditor is in your boardroom or on a video call. See CE Plus overview for the full scope.

    Remote audit – what to expect

    The auditor schedules a video session. Sample users join, install a temporary scanner agent (Windows, macOS, sometimes a script for Linux), and the auditor watches the scan results live. The email and web tests are sent to live mailboxes from a known auditor address. Total time: 2–4 hours for a small business, half a day for mid-sized.

    Best fit for remote

    • Cloud-first or hybrid teams with M365 / Google Workspace.
    • Distributed workforces where devices live in homes, not offices.
    • Standard endpoint estates (Windows / macOS, Intune or Jamf).

    Where remote breaks down

    • Devices on tightly segmented networks that block the scanner.
    • Operational-technology environments (manufacturing, lab equipment).
    • Air-gapped or classified-handling environments.

    On-site audit – what to expect

    The auditor arrives at your office (or sites, plural, if devices are spread). Same four tests, run from the local network. On-site usually adds half a day for travel and setup, plus the auditor's expenses.

    When on-site makes sense

    • Defence or higher-sensitivity contracts that specify it.
    • Heavy on-premise infrastructure where credentials shouldn't leave the building.
    • Multi-site businesses where sampling needs to happen physically.

    Cost difference

    Remote audits are £1,400 + VAT for a micro business. On-site typically adds £400–£900 for travel and time. Multi-site on-site audits scale by location. See the bands in our CE Plus cost guide.

    Prep checklist (works for both)

    • Export your asset list – every device that touches business data.
    • Confirm patch status on the sample devices (within 14 days for high-risk patches).
    • Confirm MFA on every cloud user, including third-party SaaS.
    • Have an admin-account map ready (who has admin, on what, why).
    • Decommission anything you've been meaning to retire – it'll get scanned otherwise.

    Common audit-day failures

    • One sample device offline or not joined to MDM at audit time.
    • A patch backlog the team didn't realise had grown.
    • The scanner blocked by a local AV that wasn't whitelisted.
    • An old admin account discovered live during account separation review.

    Want help choosing between formats? Talk to us via the CE Plus page.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions

    Related Cyber Essentials Guides