Cyber Essentials Plus Sampling for VDI Environments: Common Mistakes
Published 12 August 2026
Six mistakes that fail a VDI CE Plus audit
1. Single-user, single-session testing
Testing one mailbox or one launched session does not evidence consistent controls across the population. The assessor must sample multiple users and the organisation should expect that going in.
2. Treating all host pools as one
If finance, developers and a contact-centre kiosk each have their own gold image, that is three populations – each needs sampling. A pass on the finance build does not infer a pass on the kiosk build.
3. Skipping server OS testing
VDI session hosts run server operating systems that need their own patch and configuration checks. "We only tested the user desktop" is not enough – the host underneath the desktop is in scope too. See what gets tested in a VDI CE Plus audit.
4. Excluding hypervisors
If the certified organisation operates the hypervisors, they are in scope. Excluding them because they "sit underneath" is a misread of the scheme – see are hypervisors in scope.
5. Forgetting the launching endpoint
CE Plus tests the device used to launch the session, not just the session itself. Thin clients, BYOD and managed laptops all need to be sampled. See hosted desktops and end-user devices.
6. Assuming the provider's certificate covers you
A VDI provider's CE Plus covers the provider's infrastructure. The customer still has their own scope to test. See why a supplier certificate does not cover customers.
How assessors structure the sample
- List every host pool, build image and user population
- Pick a representative sample from each (size guided by IASME sampling rules)
- Include both standard and privileged users where applicable
- Cover both persistent and non-persistent builds
- Include any locked-down or specialist builds (kiosk, contact-centre)
What "good preparation" looks like
- Provide the assessor with an inventory of all builds and host pools up front
- Create dedicated test accounts (standard user rights) in each pool
- Make sure every distinct image meets the patch / config baseline before testing starts
- Have evidence ready for malware protection, MFA and account separation per pool
- Plan a maintenance window in case a remediation is needed mid-audit
