Blog
Compliance
Cyber Essentials
July 21, 2026
Approx min read

How to pass Cyber Essentials Plus

A tender or a customer's security review asks for Cyber Essentials Plus, the audited certificate. At that point the self-assessed badge no longer clears the bar. The contract sits in the pipeline until an independent assessor has tested your controls in person and confirmed they work.

This guide covers the practical route to passing Cyber Essentials Plus: the certificate you have to hold first, what the assessor actually does, realistic timing, and the failures that stall teams at the audit. For what the standard is and which buyers mandate it, the Cyber Essentials Plus explainer covers the background.

What Cyber Essentials Plus asks of you

Cyber Essentials Plus checks the same five technical controls as the self-assessed certificate: firewalls, secure configuration, user access control, malware protection, and security update management. The difference is verification. An independent assessor tests a sample of your systems by hand to confirm the controls run as declared, instead of grading a questionnaire. The Cyber Essentials Plus explainer sets out each control in full.

Two conditions gate the audit. You must already hold a valid Cyber Essentials certificate, and the Plus assessment must be booked and completed within three months of it. Source: IASME, Cyber Essentials and Cyber Essentials Plus: what is the difference?.

How to pass Cyber Essentials Plus, step by step

The order matters, because each stage depends on the one before it.

1. Get the five controls genuinely working. Firewalls configured, secure baselines applied, access restricted, malware protection active, and high and critical updates installed inside 14 days. This has to hold across every in-scope system, including cloud services, remote-worker laptops, and any device that touches organisation data. A control that is written down but not enforced is where the audit finds you out.

2. Hold a valid Cyber Essentials certificate. The Plus assessment cannot proceed without the underlying certificate in place. Earn that first. The Cyber Essentials how-to guide walks through the self-assessment route step by step.

3. Build an accurate asset inventory. List every in-scope device, server, operating system, and cloud service, plus the people who use them. This inventory is load-bearing. The assessor samples from it. Any machine, platform, or remote device left off skews the scope and delays or fails the assessment. Get it complete before anyone books a date.

4. Book the assessment inside the three-month window. Arrange the Plus audit with a certification body so it completes within three months of the Cyber Essentials certificate. Miss the window and you re-certify at the base level before you can proceed.

5. Agree scope and the device sample with the assessor. The assessor confirms which systems are in scope and selects a representative sample across your device types and operating systems, covering servers, desktops, laptops, and mobile devices. Honest scoping here is what makes sampling valid.

6. The assessor runs the hands-on tests. This is the audit itself, and it covers four things:

  • An authenticated scan of the sampled in-scope devices and servers, run with credentials so it sees what an account holder would.
  • An external scan against each of your public IP addresses.
  • A malware protection test, where the assessor sends test files by email and through a browser and watches how your systems respond.
  • Verification checks that high and critical patches are applied within 14 days, that administrator accounts are kept separate from everyday-use accounts, and that multi-factor authentication is enforced on cloud services.

The audit can run on-site or remotely. For the person whose laptop is sampled, it is a short, practical session: the assessor works through their machine, runs the scan, and moves on. Source: IASME, CE and CE Plus difference.

7. Fix what the tests find. Any high or critical issue blocks the certificate until it is resolved within the allowed remediation window. This window is separate from the 14-day patching rule the scan checks against, so treat them as two different clocks.

8. Receive the certificate and plan the renewal. Once high and critical findings are cleared, the certificate is issued. It is valid for 12 months and renewed through an annual reassessment. Source: NCSC, Cyber Essentials overview.

How long Cyber Essentials Plus takes

The hands-on testing itself is short, often a single session for a small estate. The calendar is set by two other things: the three-month deadline after your Cyber Essentials certificate, and how much remediation the tests surface.

A team that already runs the controls cleanly can book, test, and certify well inside the window. A team that discovers missing patches or unsupported software at the audit spends the extra days fixing and retesting before the certificate is issued. The certificate then holds for 12 months, so budget the reassessment before it lapses if you want continuous cover for buyers. Sources: IASME; NCSC.

Where teams get stuck

The failures are consistent, and most are avoidable before the assessor arrives.

Patches behind the 14-day line. The authenticated scan finds high and critical updates that were never applied on a sampled machine. This is the most common block.

MFA not switched on. Multi-factor authentication is available on a cloud service but not enforced for every account. That fails the check.

Out-of-date or unsupported software. Old browsers, stale extensions, or applications past their support date show up on the sample and count against you.

Scope and inventory gaps. A device type, operating system, cloud service, or remote and bring-your-own-device machine is left out of scope. When the assessor's sample does not match reality, the pass stalls until scope is corrected.

Admin accounts not separated. Administrator rights sit on the same account used for email and browsing, which the audit will not accept.

How Naq gets you there faster

Passing Cyber Essentials Plus depends on evidence being current and complete on the day the assessor tests. Naq is an IASME Certifying Body, and it holds the evidence behind the five controls, the asset inventory, and the review history in one connected system, and the audit runs against a live record.

Evidence you already hold. The controls proven for your Cyber Essentials certificate carry straight into the Plus assessment, and you are not rebuilding the same case twice.

An inventory the assessor can trust. The asset registry tracks devices, cloud services, and per-user access with multi-factor authentication status, which keeps the scope the assessor samples from accurate.

Experts included. In-house virtual DPOs support the data-protection side of the work alongside the technical controls.

Kept current between audits. Enforced reviews stop controls going stale, and the read-only AI assistant checks evidence on demand without ever editing the record.

Frequently asked questions

Do I need Cyber Essentials before Cyber Essentials Plus?

Yes. You must hold a valid Cyber Essentials certificate before the Plus assessment can go ahead, and the audit has to be booked and completed within three months of that certificate. Miss the window and you re-certify at the base level first.

What does the Cyber Essentials Plus assessment test?

An independent assessor runs an authenticated scan of a sample of your in-scope devices and servers, an external scan against each public IP address, and a malware protection test. They also verify 14-day patching, separated admin accounts, and multi-factor authentication on cloud services.

Is Cyber Essentials Plus a penetration test?

No. Cyber Essentials Plus is an IASME-scheme audit that confirms the five Cyber Essentials controls work through hands-on testing of a device sample. A CREST penetration test is a separate, broader engagement. The two are often confused but serve different purposes.

How long is Cyber Essentials Plus valid?

The certificate is valid for 12 months. You keep it current through an annual reassessment, so plan the renewal before the year is up if a buyer needs continuous evidence that your controls are independently verified.

Why do companies fail Cyber Essentials Plus?

Most fails come from missing high or critical patches on a sampled device, multi-factor authentication not enforced on cloud services, out-of-date or unsupported software, or scope and inventory gaps where a device or platform was left out. High and critical findings block the pass until fixed.