Skip to main content
    NixInfinity-AI
    Readiness

    Cyber Essentials Plus Readiness Checklist: 30-Day Prep Plan

    Published 7 July 2026

    Week 1: scope and inventory

    • Confirm the scope statement matches the one on your current Cyber Essentials certificate. Any drift causes friction on day one of the audit.
    • Build a device inventory: laptops, desktops, servers, mobiles and BYOD in scope. Include OS, patch level and owner.
    • List every cloud service that stores organisational data (M365, Google Workspace, Xero, HubSpot, GitHub, etc.).
    • List every admin account across every service and every device.

    Week 2: patch, harden, verify

    • Patch OS, browsers and productivity software on every device to within 14 days of vendor release. Adobe Reader and browser plug-ins catch out more first-time submissions than anything else.
    • Retire any device on an unsupported OS. There is no path to passing CE Plus with a Windows 10 machine after end-of-life.
    • Enable disk encryption, screen lock, host firewalls and anti-malware on every sample-eligible device.
    • Confirm auto-updates are enabled where possible and evidence the update cadence.

    Week 3: MFA and account separation

    • Enforce MFA on every user account across every cloud service. Not "available", enforced.
    • Turn off legacy authentication protocols (IMAP, POP, basic auth on Microsoft 365 EWS).
    • Every admin needs a separate admin account, distinct from their daily-driver user account. Admin accounts must not have web browsing or email.
    • Disable or delete every account belonging to a leaver. Auditors ask to see the leavers list.

    Week 4: sample devices and evidence pack

    • Nominate the sample devices the assessor will scan (see IASME's sample-size table by headcount). Include at least one of each OS family in scope.
    • Install the assessor's temporary scanning agent 48 hours before the audit and verify it reports back cleanly.
    • Assemble the evidence pack: MFA screenshots, patch reports, admin list, joiners/leavers process, anti-malware exports and asset inventory.
    • Run a self-scan on the sample devices using the same tooling profile. Fix anything the scanner flags before the assessor sees it.

    The 48-hour final check

    Two working days before the audit, run through this list one final time: MFA on every admin, no unsupported OS in scope, no patches older than 14 days on the sample, anti-malware active with signatures under a week old, admin accounts locked out of email and web. If any of those fail, delay the audit rather than fail it.

    What to have ready on audit day

    • Named point of contact who can approve remote access to sample devices.
    • Working test user accounts with realistic mailboxes and permissions.
    • Access to the admin consoles of every in-scope cloud service.
    • The CE certificate PDF and scope statement in the same folder.

    Full costs and what drives them are in the CE Plus cost guide. If you are still deciding whether now is the right time, read when to upgrade from CE to CE Plus.

    Book a CE Plus pre-audit review

    Our IASME-licensed assessors run a full readiness check before the formal audit. First-time pass rates go up, remediation costs go down.

    Frequently Asked Questions

    Related Cyber Essentials Guides