Publish Date: January 23, 2026
Category: Cyber Essentials
A Cyber Essentials Plus audit is designed to provide organisations with independent assurance that their cyber security controls are correctly implemented and working as intended. Unlike standard Cyber Essentials, which relies on self-assessment, Cyber Essentials Plus involves hands-on technical verification carried out by a licensed assessor on behalf of an accredited certification body.
This article explains how the Cyber Essentials Plus audit is conducted, what assessors look for, and how organisations can prepare in clear, non-technical language.
The Purpose of Cyber Essentials Plus
Cyber Essentials Plus exists to confirm that the security controls declared in the Cyber Essentials self-assessment are accurate and effective in practice. The audit focuses on protection against common cyber attacks rather than advanced or targeted threats.
From an assessor and certification body perspective, the goal is to:
-
Validate real-world security controls
-
Identify exploitable weaknesses
-
Ensure consistency and fairness across assessments
-
Provide organisations with meaningful assurance
Before the Audit Begins: Understanding the Scope
Before testing commences, the assessor verifies Cyber Essentials self-assessment certification and confirms the audit scope, which includes:
- Which devices are included
- Which users are included
- Which networks and cloud services are included
The scope must match the earlier Cyber Essentials self-assessment. This ensures the audit is fair and consistent.
If something is unclear, the assessor will ask questions before proceeding. This step protects the organisation and avoids misunderstandings later.
How Systems Are Selected for Testing
Rather than testing every device, the assessor selects a representative sample that reflects normal day-to-day use.
This includes:
-
End-user devices such as laptops and desktops
-
Servers (both on-premises and cloud-hosted)
-
Mobile devices where applicable
-
Administrator and standard user accounts
-
Cloud services accessed by staff
To ensure fairness, devices are selected by the assessor and declared no more than three working days before testing.
What the Assessor Checks During the Audit
Cyber Essentials Plus focuses on five key areas. Each one is explained below in simple terms.
External Security Exposure
Assessors check what parts of the organisation’s systems are visible from the internet. This ensures:
-
Unnecessary access is blocked
-
High-risk weaknesses are not exposed
-
Attackers cannot easily reach internal systems
Any serious vulnerabilities must be resolved before certification can be issued.
Software Updates and Patching
Outdated software remains one of the most common causes of cyber incidents.
The audit confirms that:
-
Devices and servers are up to date
-
Important security updates are applied promptly
-
Unsupported operating systems are not in use
Where updates are missing, guidance is provided on remediation.
Malware Protection
Assessors verify that malware protection is:
-
Installed on all relevant systems
-
Active and up to date
-
Validate how viruses are handled through practical testing using browser-based downloads and email.
This ensures organisations are protected against common threats such as viruses and ransomware.
Multi-Factor Authentication (MFA)
All in-scope cloud services are checked to confirm MFA is enabled.
This test ensures:
-
Users cannot access cloud systems using passwords alone
-
Both administrator and standard user accounts are protected
-
Remote access risks are reduced
Account Separation
This test confirms that:
-
Standard users do not have administrator privileges
-
System-level changes require separate admin credentials
Proper account separation significantly reduces the impact of compromised user accounts.
Handling Issues and Remediation
It is common for minor issues to be identified during an audit.
When this happens:
-
Clear remediation guidance is provided
-
Organisations are typically given up to 30 days to resolve issues
-
Only failed areas are re-tested
This process ensures improvements can be made without restarting the entire assessment.
Audit Outcome and Certification
To achieve certification:
-
All required tests must pass
-
Any high-risk issues must be remediated
-
Results must be reviewed and signed off by a Lead Assessor
Successful organisations receive Cyber Essentials Plus certification which is valid for 12 months.
Conclusion
A Cyber Essentials Plus audit is not about fault-finding. It is a structured, fair, and practical assessment designed to confirm that essential cyber security controls are in place and effective.
For organisations seeking meaningful assurance, Cyber Essentials Plus provides confidence, credibility, and improved cyber resilience.
Get Cyber Essentials Certified with Shonsys
Start your Cyber Essentials journey with Shonsys, an NCSC Assured Service Provider and IASME Licensed Certification Body. We guide you through the entire assessment process and help you identify and resolve any major issues that could otherwise lead to failure.
Book your free readiness call: https://calendly.com/shonsys/certification
Shonsys supports organisations across Edinburgh, Glasgow, Scotland, and the UK to achieve Cyber Essentials and Cyber Essentials Plus with confidence and clarity.