Cyber Essentials Plus Certification: A Plain-English Guide to Passing the Technical Audit (2026)
25 September 2026

For a small business, the technical audit can feel daunting. It does not need to be.
This guide explains what the assessment involves, what evidence to prepare and how to avoid the common reasons businesses fail.
Important 2026 update: The Cyber Essentials scheme now places greater emphasis on high-risk and critical security updates being applied within 14 days, as well as enforced multi-factor authentication (MFA) for in-scope cloud services.
Cyber Essentials and Cyber Essentials Plus: What is the difference?
Both certification levels assess the same five technical controls:
- Firewalls.
- Secure configuration.
- Security update management.
- User access control.
- Malware protection.
The difference is the level of assurance.
Cyber Essentials certification
Cyber Essentials uses a verified self-assessment. You answer questions about your IT environment and security controls. The answers are then reviewed as part of the certification process.
It helps you establish a recognised baseline against common cyber threats.
Cyber Essentials Plus certification
Cyber Essentials Plus includes the same self-assessment, followed by an independent technical audit.
The assessor may:
- Select a sample of your devices.
- Check operating system and application patch levels.
- Scan for vulnerabilities.
- Review secure configuration settings.
- Test malware protection.
- Check user access controls.
- Verify MFA on cloud services.
- Review email and web protection controls.
- Identify unsupported operating systems and unpatched software.
The aim is simple: to confirm that your stated controls are operating correctly.
You can read more about the two routes in the NCSC Cyber Essentials overview.
How device sampling works
A common misunderstanding is that the assessor will check only the devices you nominate.
That is not how the technical audit should be approached.
The assessor selects a sample from the devices and systems included in your agreed scope. This can include:
- Office desktops and laptops.
- Remote workers’ laptops.
- Servers.
- Network equipment.
- Devices used to access business data.
- Relevant mobile devices and tablets.
- Systems connected to cloud services.
The sample may be relatively small compared with your whole estate. However, every in-scope device must be ready.
Why every device could be tested
If one laptop has an overdue security update, that can indicate a wider problem with your patch management process.
Similarly, one user without MFA, one unsupported operating system or one device with local administrator rights can create an avoidable failure.
The practical rule is:
Do not prepare only the devices you expect to be sampled. Prepare the whole in-scope environment.

What the assessor actually tests
1. Security updates and the 14-day requirement
The assessor checks whether high-risk and critical security updates have been applied within the required timeframe.
This applies to more than Windows updates. You should review:
- Operating systems.
- Browsers.
- Business applications.
- Plugins and extensions.
- Server software.
- Network device firmware.
- Router and firewall firmware.
- Security tools.
- Vendor-published configuration fixes.
Unsupported or end-of-life software is another common problem. If a vendor no longer provides security updates, the software may not meet the requirements.
Problem: One laptop has missed a critical update.
Solution: Use centralised patch management where possible. Review update reports before the audit and investigate every device that has not checked in recently.
Benefit: You reduce both audit risk and the likelihood of an attacker exploiting a known vulnerability.
2. Malware protection
The assessor checks whether malware protection is active, updated and configured correctly.
Depending on your environment, this may include:
- Endpoint protection.
- Anti-malware software.
- Real-time scanning.
- Automatic security updates.
- Protection against unauthorised changes.
- Security controls on supported mobile devices where relevant.
Do not assume that a product is correctly configured simply because it is installed.
Check that:
- Protection is active on all in-scope endpoints.
- Devices are reporting to your management console.
- Alerts are being reviewed.
- Users cannot easily disable protection.
- Devices that have been offline are brought up to date.
3. Secure configuration
Secure configuration reduces the number of ways an attacker can access or misuse a system.
The assessor may review:
- Default passwords.
- Unnecessary accounts.
- Unused services.
- Unnecessary applications.
- Screen-lock settings.
- Encryption.
- Administrative interfaces.
- Remote access configuration.
- Security settings on laptops and servers.
A new laptop that has been configured differently from the rest of your estate can create a weakness.
Use a standard build for company devices. Record the security settings that should be applied. Then check that those settings remain in place.
4. User access controls and administrator rights
The assessment considers who can access systems and what they are allowed to do.
Expect questions and testing around:
- User account management.
- Leavers and joiners.
- Privileged accounts.
- Administrator rights.
- Password controls.
- Separate admin accounts.
- Access to cloud services.
- Shared accounts.
A frequent failure point is giving every employee local administrator rights because it is convenient.
Remove unnecessary admin access. Provide separate privileged accounts for administration. Review access regularly and disable accounts promptly when people leave.
5. MFA on cloud services
In 2026, MFA is one of the most important preparation areas.
You should review every in-scope cloud and internet-facing service, including:
- Microsoft 365.
- Google Workspace.
- Cloud storage.
- Customer relationship management platforms.
- Finance systems.
- Remote access services.
- Collaboration tools.
- Backup platforms.
- Business applications containing company data.
MFA should be enabled and enforced for all relevant accounts, including administrators and standard users.
Do not check only your main email platform. A single cloud service without the required protection can affect the assessment.
Problem: MFA is available but only enabled for administrators.
Solution: Enforce MFA across all users and confirm that new accounts cannot bypass the policy.
Benefit: You reduce the risk of stolen passwords being used to access email, files and business systems.
Your Cyber Essentials Plus checklist
Use this checklist before booking the technical assessment.
Scope and asset management
- Confirm which devices, systems and services are in scope.
- Include remote workers and relevant mobile devices.
- Identify all cloud services that process business information.
- Remove old, unused and unknown devices from the environment.
- Keep an accurate list of users, devices and software.
Patching and software
- Apply high-risk and critical updates within 14 days.
- Patch browsers, plugins, extensions and business applications.
- Update network device and firewall firmware.
- Remove unsupported operating systems.
- Replace or upgrade end-of-life applications.
- Investigate devices missing from your patching console.
Access and MFA
- Enforce MFA on all in-scope cloud services.
- Include standard users, administrators and remote workers.
- Remove unnecessary local administrator rights.
- Use separate administrator accounts.
- Disable leaver accounts immediately.
- Review dormant and shared accounts.
Secure configuration and protection
- Change default passwords.
- Disable unnecessary services and accounts.
- Confirm screen-lock settings.
- Check encryption on laptops and mobile devices where required.
- Confirm malware protection is active and updated.
- Review email and web filtering controls.
- Test that security alerts are being received and acted upon.

Common reasons businesses fail
Most failures are avoidable. The same issues appear repeatedly:
A single laptop is missing patches
The business has a patching policy, but one device has been offline or overlooked.
Fix: Run a full device compliance report. Contact users with stale devices and remediate exceptions before assessment.
Microsoft 365 MFA is not enforced
MFA may be enabled for some users but not required for everyone.
Fix: Apply conditional access or equivalent controls. Check service accounts, administrators and any external access routes.
Employees have excessive admin rights
Users may have administrator access because they need to install software.
Fix: Remove standard users from the local administrators group. Use approved software deployment or temporary elevation instead.
Mobile devices are outside the process
Businesses often manage laptops but forget smartphones and tablets used to access business email or files.
Fix: Confirm whether mobile devices are in scope. Apply appropriate mobile management, update and access controls. Agree any scope questions with your certification body early.
Unsupported software remains in use
An old operating system or application may still work, but it no longer receives security updates.
Fix: Upgrade, replace or remove it. Document any exceptional systems and discuss them with your assessor before the audit.
What to expect on assessment day
The exact process depends on your certification body and agreed scope. In general, you should expect:
-
Scope confirmation
The assessor confirms the devices, services and networks included. -
Technical access or remote testing
You provide the access or information needed to complete the checks. -
Device sampling
The assessor selects devices for inspection and scanning. -
Control testing
They check patching, malware protection, configuration, access controls and related security measures. -
Findings and remediation
If issues are identified, you may need to fix them and provide evidence. -
Retesting where applicable
The assessor may retest remediated devices and select an additional sample.
Do not leave preparation until the week before. A realistic timeline for a small business is often:
- Week 1: Confirm scope and complete a gap analysis.
- Weeks 2–3: Fix patching, MFA, access and configuration issues.
- Week 4: Validate the full estate and prepare for assessment.
Complex environments, remote workers and unsupported systems may require longer.
Why Cyber Essentials Plus matters
CE+ provides stronger assurance than a self-assessment alone. That matters when you need to:
- Meet customer security requirements.
- Support enterprise procurement.
- Respond to public sector tenders.
- Demonstrate security to partners and insurers.
- Progress towards Defence Cyber Certification.
- Improve confidence in your internal controls.
Cyber Essentials Plus is required for DCC Levels 2 and 3, alongside additional Defence Cyber Certification controls. The certificate must also remain current. Check the SimpleCyber DCC guidance and your contract requirements before planning your route.
How a virtual CISO can reduce the risk
A virtual CISO, or virtual security manager, can help you manage the process without hiring a full-time security executive.
Support can include:
- Defining your assessment scope.
- Reviewing your Cyber Essentials requirements.
- Running a readiness assessment.
- Checking patch and asset reports.
- Reviewing Microsoft 365 MFA.
- Reducing excessive administrator access.
- Preparing evidence.
- Coordinating technical remediation.
- Managing communication with the certification body.
- Maintaining controls after certification.
This is particularly useful when your IT provider manages technology but nobody owns security risk across the business.
SimpleCyber provides Virtual CISO support on a flexible basis. The focus is practical: identify the gaps, prioritise the fixes and help you achieve certification with less disruption.
Ready to prepare for Cyber Essentials Plus?
Passing the technical audit first time starts with understanding your full scope and checking every device, user and cloud service.
SimpleCyber can help with a readiness review, Cyber Essentials Plus preparation or ongoing virtual security management.
Contact SimpleCyber to discuss your requirements or explore our Cyber Essentials certification support.
