CE Plus On-Site vs Remote Audit: Which to Choose
Published 16 June 2026
What an audit actually involves
A CE Plus audit covers four technical tests: an authenticated vulnerability scan on a sample of devices, an email-content test, a web-content test, and an account-separation/MFA review. The same tests run whether the auditor is in your boardroom or on a video call. See CE Plus overview for the full scope.
Remote audit – what to expect
The auditor schedules a video session. Sample users join, install a temporary scanner agent (Windows, macOS, sometimes a script for Linux), and the auditor watches the scan results live. The email and web tests are sent to live mailboxes from a known auditor address. Total time: 2–4 hours for a small business, half a day for mid-sized.
Best fit for remote
- Cloud-first or hybrid teams with M365 / Google Workspace.
- Distributed workforces where devices live in homes, not offices.
- Standard endpoint estates (Windows / macOS, Intune or Jamf).
Where remote breaks down
- Devices on tightly segmented networks that block the scanner.
- Operational-technology environments (manufacturing, lab equipment).
- Air-gapped or classified-handling environments.
On-site audit – what to expect
The auditor arrives at your office (or sites, plural, if devices are spread). Same four tests, run from the local network. On-site usually adds half a day for travel and setup, plus the auditor's expenses.
When on-site makes sense
- Defence or higher-sensitivity contracts that specify it.
- Heavy on-premise infrastructure where credentials shouldn't leave the building.
- Multi-site businesses where sampling needs to happen physically.
Cost difference
Remote audits are £1,400 + VAT for a micro business. On-site typically adds £400–£900 for travel and time. Multi-site on-site audits scale by location. See the bands in our CE Plus cost guide.
Prep checklist (works for both)
- Export your asset list – every device that touches business data.
- Confirm patch status on the sample devices (within 14 days for high-risk patches).
- Confirm MFA on every cloud user, including third-party SaaS.
- Have an admin-account map ready (who has admin, on what, why).
- Decommission anything you've been meaning to retire – it'll get scanned otherwise.
Common audit-day failures
- One sample device offline or not joined to MDM at audit time.
- A patch backlog the team didn't realise had grown.
- The scanner blocked by a local AV that wasn't whitelisted.
- An old admin account discovered live during account separation review.
Want help choosing between formats? Talk to us via the CE Plus page.
