Skip to main content
    NixInfinity-AI
    CE Plus Testing

    VDI for Cyber Essentials Plus: What Gets Tested and How Sampling Works

    Published 11 August 2026

    Three layers, three test approaches

    1. VDI infrastructure

    Authenticated vulnerability scans of broker, gateway, profile services and management servers. Patch status, secure config, account separation and MFA on admin interfaces are all checked.

    2. Server operating systems hosting sessions

    Server OS gold images and live session hosts are scanned. Same rules as endpoints – supported OS, 14-day patching for high/critical, anti-malware (where deployed) and hardened build.

    3. User sessions / VDI desktops

    The assessor logs in as a real user and runs the standard CE Plus tests against the desktop: malware test files, browser configuration, account separation, application allow/block behaviour, MFA on the launching account.

    How sampling works in VDI

    VDI environments often have multiple host pools or build images (e.g. one for finance, one for developers, one for call-centre kiosks). Each distinct build is a separate population for sampling. Testing only one host pool when three exist is a scope failure.

    • Sample each distinct gold image / host pool
    • Sample multiple users per pool, not just one mailbox
    • Cover at least one persistent and one non-persistent build if both exist
    • Include any "kiosk" or call-centre style locked-down build

    For the mistakes most often seen at this stage, see CE Plus VDI sampling mistakes.

    What the assessor actually does inside a session

    1. Launches the VDI session as a sampled user
    2. Runs the EICAR test file via browser download and email attachment
    3. Attempts execution of test executables to confirm malware protection / allowlisting behaviour
    4. Checks browser plugin/extension state and patch level
    5. Checks the account is a standard user, not local admin inside the session
    6. Confirms MFA was enforced on the launching account

    Evidence to gather before the audit

    • Inventory of host pools, builds and user populations
    • Gold image hardening documents and patch dates
    • Test user accounts (standard rights) in each pool
    • MFA configuration screenshots from the broker / IdP
    • Anti-malware policy and EDR coverage report

    For the wider CE Plus picture in virtual and cloud estates, see CE Plus in virtualised and cloud environments.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions

    Related Cyber Essentials Guides