arrow_back Back to Insights CYBER ESSENTIALS

Preparing for Cyber Essentials Plus: What Actually Fails

October 2026 10 min read

Most organisations that struggle with Cyber Essentials Plus do not struggle because the controls are difficult. They struggle because the audit tests what is actually on the devices, and what is on the devices is not quite what everyone believed when the questionnaire was filled in.

I keep Cyber Essentials Plus maintained for a Premier League football club with a stadium and a training ground, and I prepare other organisations for the same assessment. This guide covers the preparation I would do for any of them: setting the scope, finding the usual gaps, and collecting evidence as you work.

One thing to be clear about first. Utilis Technologies is not a certification body. Certificates are issued by certification bodies licensed by IASME, which runs the scheme on behalf of the National Cyber Security Centre (NCSC). My part is the readiness work that comes before you go to one.

What Cyber Essentials and Cyber Essentials Plus are

Cyber Essentials is a verified self-assessment. You answer a questionnaire about how your organisation meets a set of technical requirements, a senior person signs a declaration that the answers are true, and a certification body reviews the submission.

Cyber Essentials Plus uses exactly the same requirements. The difference is that an assessor then tests a sample of your devices and your internet-facing systems to check that the answers hold up in practice. Plus builds on the self-assessment, and the scheme has long required the technical audit to be completed within a set period of it (three months, as the rules have stood), so the two are planned together.

Both certificates last twelve months. Renewal is a fresh assessment against whichever version of the requirements is current at the time, and the requirements are revised regularly. Always work from the current requirements document and question set published by the NCSC and IASME. A guide like this one only shows the shape of the work.

The five technical controls

None of that is exotic. The difficulty is the word every.

Get the scope right before anything else

Scope decides which devices, users and services the assessment covers. I spend more time on it than on any single control, because scope mistakes are the most expensive ones. Discover in audit week that a group of devices should have been included, and you are remediating under time pressure or redoing work you thought was finished.

As the requirements have stood for several years, the following are in scope:

The scheme prefers the whole organisation to be in scope. A smaller scope is possible, but the excluded part has to be genuinely separated from the in-scope network, usually by a firewall or VLAN, and the certificate will describe the scope it covers. A narrow scope may not satisfy the tender or insurer that asked for the certificate, so check before you draw the boundary.

Where organisations commonly fall down

The same gaps turn up in almost every readiness assessment I run.

Unsupported operating systems and software

Anything the vendor no longer issues security updates for cannot meet the update control. That covers old versions of Windows and macOS, phones and tablets that have stopped receiving updates, and applications such as an old Office version or an unmaintained PDF tool. The options are to upgrade it, remove it, or move it to a properly segregated network outside the scope.

Devices missing from the inventory

You cannot patch or protect a device you do not know about. The laptop in a cupboard that still signs in once a month, the meeting room PC, the director’s personal tablet with company email on it. If a device can reach organisational data, it has to be on the list, with its operating system and version.

Security updates not applied in time

The scheme’s long-standing rule is that updates fixing vulnerabilities rated high or critical must be applied within 14 days of release. Confirm the exact wording, including how severity is defined, against the current requirements document. Operating system updates are usually handled by policy. Third-party applications and firewall firmware are what slip.

MFA not enforced on every cloud account

Multi-factor authentication is expected on all accounts for cloud services where the service offers it, for ordinary users as well as administrators. The common failures are service and shared mailboxes with interactive sign-in, a legacy exclusion group nobody reviewed, and a third-party cloud service outside single sign-on where MFA was never switched on.

Admin accounts used for day-to-day work

Administrative accounts should be used for administration only. An account with Global Administrator rights that also reads email and browses the web fails the principle and is easy for an assessor to spot. The same applies to staff who are local administrators on their own laptops.

Default or weak configuration

Default passwords left on a router, printer or switch. Remote management interfaces open to the internet. Devices with no screen lock. Software installed years ago and never used. Each one is small, and an assessor will find them.

Unmanaged BYOD

If personal devices can reach company data, you need a way to show they are supported, updated, locked and protected. In a Microsoft 365 estate that usually means Conditional Access combined with device compliance or app protection policies in Intune. Without it you are relying on each member of staff to keep a personal phone current, with no evidence either way.

Build the evidence as you go

Evidence gathered in the final week is evidence gathered badly. I build it during remediation, so each fix produces the report that proves it.

EvidenceWhat it showsWhere it usually comes from
Asset listEvery in-scope device, with owner, operating system and versionIntune or your RMM, reconciled against Entra ID sign-ins and purchase records
Patch reportsUpdates applied, and how long they tookIntune update and compliance reports, or your RMM’s patch reporting
Conditional Access exportMFA is enforced, and who is excludedEntra ID policy export
Admin role listingWho holds privileged roles, on separate accountsEntra ID role assignments and local administrator group membership
Cloud service registerEvery service holding organisational data, and its MFA statusFinance records and the single sign-on app list

The reconciliation step matters more than any single export. When the device list in Intune, the sign-in logs and the asset register disagree, the difference is your unknown devices. The estate behind this approach is described in the case studies.

What the Plus audit involves

The assessor works to a test specification published by the scheme, and your certification body will explain exactly what applies to you. In general terms, expect:

Because the sample is the assessor’s choice, the only reliable preparation is for every device to be ready. I run the same checks in advance and fix what they find before the assessor arrives.

A realistic preparation sequence

  1. Read the current requirements. Note anything that changed since your last certificate.
  2. Agree the scope. Write it down, including cloud services, home workers and BYOD.
  3. Build the inventory. Reconcile every source until the device and software lists are complete.
  4. Assess against the five controls. Mark each as met, partly met or not met, from configuration and reports.
  5. Remediate in order of lead time. Hardware replacement and BYOD decisions take longest, so start them first.
  6. Prove patching over time. Check the reports show fixes landing inside the window across several update cycles.
  7. Complete the self-assessment. Answer from the evidence, and put anything you cannot answer honestly back on the remediation list.
  8. Pre-audit, then book the audit. Scan a sample yourself and fix the findings first.

Staying compliant between renewals

Estates drift. The organisations that find renewal easy treat the controls as routine operations:

This is ordinary infrastructure and security management. Cyber Essentials gives it a deadline.

Why tenders, insurers and supply chains ask for it

Cyber Essentials is a short, recognisable way for a buyer to check that a supplier has the basics in place. Some central government contracts require it, and it appears routinely in public-sector frameworks, pre-qualification questionnaires and customer supply-chain assessments. Cyber insurers ask about the same controls on their proposal forms, whether or not they name the scheme.

In both places you are making a statement someone else will rely on. A certificate that was accurate on assessment day and untrue three months later is a problem if a claim or an incident ever tests it.

The scheme says nothing about how staff use AI tools with company data. For that you need a separate AI usage policy, which I cover in the guide to AI governance for SMEs, and there is a free AI policy template to start from.

FAQ

Cyber Essentials is a self-assessment: you answer a questionnaire about the five technical controls, a senior person signs a declaration, and a certification body reviews it. Cyber Essentials Plus covers the same requirements and adds hands-on technical testing, in which an assessor scans and checks a sample of your devices and your internet-facing systems to confirm the answers are true in practice. Both certificates are renewed annually.
Yes, if they access organisational data or services. A personal phone or tablet that reads company email or opens company files is in scope and has to meet the controls. The usual exception in the requirements is a device used only for voice calls, text messages or a multi-factor authentication app. Check the current requirements document for the exact wording.
It depends on the gaps, so I do not quote a number before a readiness assessment. An organisation with managed devices, MFA everywhere and patching under control mostly needs accurate answers and evidence. What extends the timeline is replacing unsupported hardware, settling a BYOD position, finding devices missing from the inventory, and showing over several update cycles that patches land inside the required window.
A failed finding is not usually the end of the process. Certification bodies generally allow a period to fix the issues found and have them re-checked, but the length of that period, what is re-tested and whether a further fee applies are set by the scheme rules and your certification body’s terms. Ask before you book, and run the same scans yourself in advance.
No. An AI service that holds organisational data is a cloud service, so its accounts fall under the access control requirements, but the scheme says nothing about which AI tools staff may use or what data they may put into them. Pair it with an AI usage policy and a register of approved tools.

Assessment or renewal coming up?

I prepare organisations for Cyber Essentials and Cyber Essentials Plus: scope, gap list, remediation and evidence, ready for the certification body you choose. The detail is on the Cyber Essentials readiness page. Get in touch or book a 30-minute call and bring your renewal date.

Book a Free Discovery Call