Most organisations that struggle with Cyber Essentials Plus do not struggle because the controls are difficult. They struggle because the audit tests what is actually on the devices, and what is on the devices is not quite what everyone believed when the questionnaire was filled in.
I keep Cyber Essentials Plus maintained for a Premier League football club with a stadium and a training ground, and I prepare other organisations for the same assessment. This guide covers the preparation I would do for any of them: setting the scope, finding the usual gaps, and collecting evidence as you work.
One thing to be clear about first. Utilis Technologies is not a certification body. Certificates are issued by certification bodies licensed by IASME, which runs the scheme on behalf of the National Cyber Security Centre (NCSC). My part is the readiness work that comes before you go to one.
Cyber Essentials is a verified self-assessment. You answer a questionnaire about how your organisation meets a set of technical requirements, a senior person signs a declaration that the answers are true, and a certification body reviews the submission.
Cyber Essentials Plus uses exactly the same requirements. The difference is that an assessor then tests a sample of your devices and your internet-facing systems to check that the answers hold up in practice. Plus builds on the self-assessment, and the scheme has long required the technical audit to be completed within a set period of it (three months, as the rules have stood), so the two are planned together.
Both certificates last twelve months. Renewal is a fresh assessment against whichever version of the requirements is current at the time, and the requirements are revised regularly. Always work from the current requirements document and question set published by the NCSC and IASME. A guide like this one only shows the shape of the work.
None of that is exotic. The difficulty is the word every.
Scope decides which devices, users and services the assessment covers. I spend more time on it than on any single control, because scope mistakes are the most expensive ones. Discover in audit week that a group of devices should have been included, and you are remediating under time pressure or redoing work you thought was finished.
As the requirements have stood for several years, the following are in scope:
The scheme prefers the whole organisation to be in scope. A smaller scope is possible, but the excluded part has to be genuinely separated from the in-scope network, usually by a firewall or VLAN, and the certificate will describe the scope it covers. A narrow scope may not satisfy the tender or insurer that asked for the certificate, so check before you draw the boundary.
The same gaps turn up in almost every readiness assessment I run.
Anything the vendor no longer issues security updates for cannot meet the update control. That covers old versions of Windows and macOS, phones and tablets that have stopped receiving updates, and applications such as an old Office version or an unmaintained PDF tool. The options are to upgrade it, remove it, or move it to a properly segregated network outside the scope.
You cannot patch or protect a device you do not know about. The laptop in a cupboard that still signs in once a month, the meeting room PC, the director’s personal tablet with company email on it. If a device can reach organisational data, it has to be on the list, with its operating system and version.
The scheme’s long-standing rule is that updates fixing vulnerabilities rated high or critical must be applied within 14 days of release. Confirm the exact wording, including how severity is defined, against the current requirements document. Operating system updates are usually handled by policy. Third-party applications and firewall firmware are what slip.
Multi-factor authentication is expected on all accounts for cloud services where the service offers it, for ordinary users as well as administrators. The common failures are service and shared mailboxes with interactive sign-in, a legacy exclusion group nobody reviewed, and a third-party cloud service outside single sign-on where MFA was never switched on.
Administrative accounts should be used for administration only. An account with Global Administrator rights that also reads email and browses the web fails the principle and is easy for an assessor to spot. The same applies to staff who are local administrators on their own laptops.
Default passwords left on a router, printer or switch. Remote management interfaces open to the internet. Devices with no screen lock. Software installed years ago and never used. Each one is small, and an assessor will find them.
If personal devices can reach company data, you need a way to show they are supported, updated, locked and protected. In a Microsoft 365 estate that usually means Conditional Access combined with device compliance or app protection policies in Intune. Without it you are relying on each member of staff to keep a personal phone current, with no evidence either way.
Evidence gathered in the final week is evidence gathered badly. I build it during remediation, so each fix produces the report that proves it.
| Evidence | What it shows | Where it usually comes from |
|---|---|---|
| Asset list | Every in-scope device, with owner, operating system and version | Intune or your RMM, reconciled against Entra ID sign-ins and purchase records |
| Patch reports | Updates applied, and how long they took | Intune update and compliance reports, or your RMM’s patch reporting |
| Conditional Access export | MFA is enforced, and who is excluded | Entra ID policy export |
| Admin role listing | Who holds privileged roles, on separate accounts | Entra ID role assignments and local administrator group membership |
| Cloud service register | Every service holding organisational data, and its MFA status | Finance records and the single sign-on app list |
The reconciliation step matters more than any single export. When the device list in Intune, the sign-in logs and the asset register disagree, the difference is your unknown devices. The estate behind this approach is described in the case studies.
The assessor works to a test specification published by the scheme, and your certification body will explain exactly what applies to you. In general terms, expect:
Because the sample is the assessor’s choice, the only reliable preparation is for every device to be ready. I run the same checks in advance and fix what they find before the assessor arrives.
Estates drift. The organisations that find renewal easy treat the controls as routine operations:
This is ordinary infrastructure and security management. Cyber Essentials gives it a deadline.
Cyber Essentials is a short, recognisable way for a buyer to check that a supplier has the basics in place. Some central government contracts require it, and it appears routinely in public-sector frameworks, pre-qualification questionnaires and customer supply-chain assessments. Cyber insurers ask about the same controls on their proposal forms, whether or not they name the scheme.
In both places you are making a statement someone else will rely on. A certificate that was accurate on assessment day and untrue three months later is a problem if a claim or an incident ever tests it.
The scheme says nothing about how staff use AI tools with company data. For that you need a separate AI usage policy, which I cover in the guide to AI governance for SMEs, and there is a free AI policy template to start from.
I prepare organisations for Cyber Essentials and Cyber Essentials Plus: scope, gap list, remediation and evidence, ready for the certification body you choose. The detail is on the Cyber Essentials readiness page. Get in touch or book a 30-minute call and bring your renewal date.
Book a Free Discovery Call