VDI for Cyber Essentials Plus: What Gets Tested and How Sampling Works
Published 11 August 2026
Three layers, three test approaches
1. VDI infrastructure
Authenticated vulnerability scans of broker, gateway, profile services and management servers. Patch status, secure config, account separation and MFA on admin interfaces are all checked.
2. Server operating systems hosting sessions
Server OS gold images and live session hosts are scanned. Same rules as endpoints – supported OS, 14-day patching for high/critical, anti-malware (where deployed) and hardened build.
3. User sessions / VDI desktops
The assessor logs in as a real user and runs the standard CE Plus tests against the desktop: malware test files, browser configuration, account separation, application allow/block behaviour, MFA on the launching account.
How sampling works in VDI
VDI environments often have multiple host pools or build images (e.g. one for finance, one for developers, one for call-centre kiosks). Each distinct build is a separate population for sampling. Testing only one host pool when three exist is a scope failure.
- Sample each distinct gold image / host pool
- Sample multiple users per pool, not just one mailbox
- Cover at least one persistent and one non-persistent build if both exist
- Include any "kiosk" or call-centre style locked-down build
For the mistakes most often seen at this stage, see CE Plus VDI sampling mistakes.
What the assessor actually does inside a session
- Launches the VDI session as a sampled user
- Runs the EICAR test file via browser download and email attachment
- Attempts execution of test executables to confirm malware protection / allowlisting behaviour
- Checks browser plugin/extension state and patch level
- Checks the account is a standard user, not local admin inside the session
- Confirms MFA was enforced on the launching account
Evidence to gather before the audit
- Inventory of host pools, builds and user populations
- Gold image hardening documents and patch dates
- Test user accounts (standard rights) in each pool
- MFA configuration screenshots from the broker / IdP
- Anti-malware policy and EDR coverage report
For the wider CE Plus picture in virtual and cloud estates, see CE Plus in virtualised and cloud environments.
