Skip to main content
    NixInfinity-AI
    Cyber Essentials Plus

    Cyber Essentials Plus Audit: What to Expect

    Published 30 April 2026

    What the assessor actually does

    • External vulnerability scan – on every public IP / domain in scope.
    • Authenticated device scan – on a representative sample of devices (size depends on headcount).
    • Email test – simulated malicious attachments to verify malware protection.
    • Web download test – simulated malicious file downloads.
    • Account separation check – confirms admin accounts cannot browse the web / read email.
    • MFA verification – confirms MFA is actively enforced (not just configured).
    • Patch verification – verifies the 14-day rule is being met in practice.

    Sample sizes

    IASME prescribes sample sizes by headcount. A typical 1–20 staff organisation has 1–3 sample devices per OS family. Larger organisations have proportionally more, capped per IASME tables.

    Remote vs onsite

    The vast majority of CE Plus audits are now delivered remotely using temporary scanning tools installed on sample devices. Onsite is available where required by client policy.

    Common audit failures

    • Patches outside the 14-day window (especially browsers and Adobe products)
    • Unsupported OS versions still in production
    • MFA bypass via legacy authentication protocols (Microsoft 365 EWS, IMAP)
    • Admin accounts able to read email or browse the web
    • Anti-malware disabled or out of date on a sample device

    Before the audit

    We run a pre-audit readiness check on every CE Plus engagement to flag these issues before the formal audit starts – this is the single biggest factor in passing first time. See pricing on our CE Plus cost page.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions