7 Mistakes You’re Making with Cyber Essentials Plus (and How to Fix Them)
26 June 2026

Achieving Cyber Essentials Plus certification is no longer just a "nice-to-have" for UK businesses. Whether you are bidding for government contracts or proving your security posture to a high-growth startup partner, the "Plus" badge is the gold standard.
Unlike the basic self-assessment, Cyber Essentials Plus involves a rigorous technical audit. An independent assessor will scan your systems, test your defenses, and look for any cracks in your digital armor. In 2026, the requirements have become even more stringent, and many SMEs are finding themselves failing at the final hurdle.
At SimpleCyber, we’ve helped dozens of teams navigate these technical waters. We see the same pitfalls time and again. Here are the seven most common mistakes businesses make when aiming for Cyber Essentials Plus: and exactly how you can fix them.
1. Defining Your Scope Too Narrowly
One of the most frequent reasons for a failed audit is an incorrect "scope." You might think you only need to secure the laptops in your main office, but the cyber essentials plus framework is much broader.
The Mistake: Excluding Bring Your Own Device (BYOD) phones, home routers for remote workers, or cloud-based SaaS platforms like Microsoft 365 and Google Workspace.
The Fix:
- Create a comprehensive asset register.
- Include every device that accesses corporate data (even if it's a personal phone used for Teams).
- Ensure your scope matches your basic Cyber Essentials certification exactly; if the two don't align, your Plus audit will stall.
2. Falling Into the "14-Day" Patching Trap
The Cyber Essentials scheme has a strict rule: all "Critical" or "High" security updates must be applied within 14 days of release. During a Plus audit, the assessor will run vulnerability scans to see if any of your devices are lagging behind.
The Mistake: Relying on staff to manually update their own machines or waiting for a monthly "patch Tuesday" that falls outside the two-week window.

The Fix:
- Implement an automated patch management system.
- Run weekly internal scans to catch missing updates before the official assessor arrives.
- Prioritize operating systems and web browsers, as these are the first things an auditor will check.
3. Inconsistent Multi-Factor Authentication (MFA)
In 2026, "MFA on most things" is no longer enough. The requirements for cyber essentials plus certification now mandate that MFA must be enabled on all cloud services and all administrative accounts.
The Mistake: Forgetting to enable MFA on "legacy" admin accounts or third-party integrations that have high-level access to your network.
The Fix:
- Enforce MFA across your entire organization, starting with your Virtual CISO or IT leads.
- Audit your Microsoft 365 or Google Workspace settings to ensure MFA is required, not just optional.
- If a service doesn't support MFA, you must document a valid technical justification: or find a new service.
4. Keeping "Ghost" Software Alive
End-of-Life (EoL) software is an automatic fail. If you are running an old version of Windows, an unsupported version of Office, or a niche legacy application that no longer receives security updates, you cannot pass.
The Mistake: Keeping one old server or laptop "just in case" it's needed for an old project. If it’s on the network, it’s in scope.

The Fix:
- Conduct a "software sweep" to identify anything no longer supported by the manufacturer.
- Decommission old hardware or move it to a completely isolated network segment that is out of scope.
- Upgrade to the latest versions well before your audit date.
5. Misconfigured Cloud and SaaS Settings
Many SMEs assume that because they use a secure provider like Amazon AWS or Microsoft, they are automatically compliant. This is a dangerous assumption. While the infrastructure is secure, your configuration of it might not be.
The Mistake: Leaving default "Admin" passwords unchanged or having overly permissive firewall rules in your cloud environment.

The Fix:
- Review your cloud security posture. Ensure "Block all" is the default for incoming traffic unless specifically required.
- Disable unnecessary features and auto-run functions.
- Use a Fractional Security Consultant to perform a gap analysis on your cloud setup.
6. Treating the Audit Like a Questionnaire
The basic Cyber Essentials is a self-assessment. The Plus version is a technical exam. You cannot "talk your way" out of a technical failure during the audit.
The Mistake: Not preparing for the practical tests. The assessor will literally try to download a (safe) malware file onto your laptop to see if your antivirus stops it.
The Fix:
- Perform a "pre-audit" run. Test your antivirus settings and your firewall blocks yourself.
- Ensure your team knows that an assessor will be requesting remote access or a physical visit.
- Check out our guide on Cyber Essentials vs. Cyber Essentials Plus to understand the technical differences.
7. Vague Documentation and Lack of Evidence
When the auditor asks, "How do you manage your firewall?" saying "We have a guy who does it" isn't enough. You need to show the configuration screens, the logs, and the policy.
The Mistake: Having no written record of your security processes. If it isn't documented, from an auditor's perspective, it didn't happen.
The Fix:
- Document your onboarding and offboarding processes for staff.
- Keep a log of when you last reviewed your firewall rules.
- Have screenshots ready that prove MFA and antivirus are active across your fleet.
How SimpleCyber Makes It Easy
Navigating cyber essentials plus shouldn't feel like a full-time job. We specialize in taking the jargon out of security and giving you a clear, actionable path to certification.
Whether you need a full Cyber Essentials accreditation guide or ongoing support from a security expert, we’re here to help you strengthen your defenses without the headache.
Ready to secure your business and win more contracts?
Contact SimpleCyber today for a straightforward, no-nonsense consultation.

