Skip to main content
    NixInfinity-AI
    CE Plus Mistakes

    Cyber Essentials Plus Sampling for VDI Environments: Common Mistakes

    Published 12 August 2026

    Six mistakes that fail a VDI CE Plus audit

    1. Single-user, single-session testing

    Testing one mailbox or one launched session does not evidence consistent controls across the population. The assessor must sample multiple users and the organisation should expect that going in.

    2. Treating all host pools as one

    If finance, developers and a contact-centre kiosk each have their own gold image, that is three populations – each needs sampling. A pass on the finance build does not infer a pass on the kiosk build.

    3. Skipping server OS testing

    VDI session hosts run server operating systems that need their own patch and configuration checks. "We only tested the user desktop" is not enough – the host underneath the desktop is in scope too. See what gets tested in a VDI CE Plus audit.

    4. Excluding hypervisors

    If the certified organisation operates the hypervisors, they are in scope. Excluding them because they "sit underneath" is a misread of the scheme – see are hypervisors in scope.

    5. Forgetting the launching endpoint

    CE Plus tests the device used to launch the session, not just the session itself. Thin clients, BYOD and managed laptops all need to be sampled. See hosted desktops and end-user devices.

    6. Assuming the provider's certificate covers you

    A VDI provider's CE Plus covers the provider's infrastructure. The customer still has their own scope to test. See why a supplier certificate does not cover customers.

    How assessors structure the sample

    • List every host pool, build image and user population
    • Pick a representative sample from each (size guided by IASME sampling rules)
    • Include both standard and privileged users where applicable
    • Cover both persistent and non-persistent builds
    • Include any locked-down or specialist builds (kiosk, contact-centre)

    What "good preparation" looks like

    1. Provide the assessor with an inventory of all builds and host pools up front
    2. Create dedicated test accounts (standard user rights) in each pool
    3. Make sure every distinct image meets the patch / config baseline before testing starts
    4. Have evidence ready for malware protection, MFA and account separation per pool
    5. Plan a maintenance window in case a remediation is needed mid-audit

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions

    Related Cyber Essentials Guides