Most organisations that delay booking Cyber Essentials Plus are not unsure whether they need it. They are unsure what the day itself involves: who has to be there, what the assessor will want access to, how long it takes, and what happens if something fails.

That uncertainty is reasonable, and it is easily resolved. This guide sets out what an audit actually looks like from your side, what changed in April 2026, and the preparation that makes the difference between a smooth day and a stressful one.

3 monthsTo complete the audit after your Cyber Essentials certification
FixedYour self-assessment answers cannot change once testing starts
Two samplesIf patching fails, a second random sample is checked

What Cyber Essentials Plus is testing

Cyber Essentials is a verified self-assessment: you describe your controls and an assessor reviews the answers. Cyber Essentials Plus checks those answers against reality. The assessor tests a sample of your systems to confirm the five controls you described are actually in place and working.

That framing explains most of what happens on the day. The assessor is not looking for clever attack paths, as a penetration test would. They are checking, methodically, that what you declared is true. If you answered the self-assessment honestly and have maintained the controls since, the audit should hold few surprises.

Two changes from April 2026 worth knowing first

The current version of the scheme, introduced on 27 April 2026, tightened Cyber Essentials Plus in two ways that directly affect preparation.

Your self-assessment is locked before testing begins. The verified self-assessment must be completed and finalised before Cyber Essentials Plus testing starts, and it cannot be changed afterwards. Under earlier versions, an organisation could sometimes adjust an answer in light of what testing revealed. That is no longer possible, so the answers need to be accurate before you book, not corrected afterwards.

Patching failures now trigger a second sample. If testing finds missing security updates, the assessor no longer simply retests the devices that failed. They also select a new, random second sample to check that updates have been applied across the whole environment rather than only to the devices that were examined. If the second sample shows the same vulnerabilities as the first, Cyber Essentials Plus fails and the underlying Cyber Essentials certification is revoked as well. If it shows different vulnerabilities, Plus may still be awarded with an advisory. Declining to provide devices for the second sample fails Plus, though Cyber Essentials itself is not revoked.

The practical message is plain: patching has to be a routine, not a preparation step. Updates applied across the whole estate as they are released will pass any sample. Updates applied to the machines you expect to be tested, shortly before the audit, are now the most reliable way to lose both certificates.

Before the day: what to arrange

The audit itself is the short part. Preparation is where the time goes, and most of it is organisational rather than technical.

Confirm your Cyber Essentials certificate and timing. Plus depends on a current Cyber Essentials certificate, and the audit must be completed within three months of that certification. Check the date and work back from it, leaving room to fix anything the audit finds.

Agree the scope and the sample. The audit covers the same scope as your Cyber Essentials certificate. The assessor will select a representative sample of your end user devices, typically reflecting the different device types and operating systems in use. Have an accurate inventory ready, because the sample is drawn from it.

Keep everything patched, all the time. This matters more than anything else on the list. The requirement is that high and critical security updates are applied within 14 days across the whole estate, every day of the year, not in the week before an audit. An organisation that patches consistently has nothing to prepare here; one that catches up just before testing is exactly what the second sample is designed to find. Check that updates have actually installed, because automatic updates report what they installed, not what they missed.

Check malware protection on every in-scope device. Present, up to date and actively protecting, including on devices bought since your last review.

Confirm multi-factor authentication on cloud services. Every cloud service in scope, and particularly on administrator accounts. New services added during the year are the usual gap.

Check account separation. Everyday users should not hold administrator rights on their devices, and administrator accounts should be separate from accounts used for email and browsing.

Agree how access will work. The assessor needs to run checks on the sampled devices and see configuration in your cloud services. Agree in advance with your assessor how that will be done.

Who needs to be available

Most audits need three kinds of input, and the day runs considerably more smoothly when everyone knows in advance.

WhoWhy they are needed
Someone with administrative accessTo facilitate checks on sampled devices and show configuration in cloud services, including multi-factor authentication settings
The users of sampled devicesTheir devices are tested, and some checks happen in the context of their normal account
A decision-makerTo approve changes where they are needed, understand what the audit is finding, and drive engagement across the organisation

If your IT is managed by an external provider, bring them in early. They often hold the administrative access, and their availability on the day is frequently what determines the schedule.

How the assessment runs

Exact steps follow the current Cyber Essentials Plus test specification, but the shape is consistent.

CheckWhat the assessor is confirming
External testingInternet-facing systems do not expose vulnerabilities or unnecessary services
Device patchingSampled devices have high and critical security updates applied within the required timescales
Malware protectionProtection on sampled devices detects and blocks test files delivered by email and through the web browser
Account controlsUsers do not hold unnecessary administrative rights, and administrator accounts are separate
Multi-factor authenticationCloud services in scope enforce multi-factor authentication as declared

Much of this can be carried out remotely, with on-site attendance where the environment or your preference makes it more practical. The time involved depends mainly on the size of the sample and how quickly access can be arranged, which is another reason preparation matters more than the audit itself.

What happens when issues are found

Finding something is common and is not the end of the process. What matters is what kind of issue it is.

Missing security updates. The most frequent finding. You apply the updates, the assessor retests the failed devices, and, under the April 2026 rules, also tests a second random sample to confirm the fix was applied across the estate. This is where selective patching gets caught, and why patching everything before the day is so important.

Malware protection or configuration issues. Typically corrected and then reverified on the affected devices.

A control that does not match what was declared. More serious, because the self-assessment cannot now be amended to fit. If testing shows a control was not in place as described, the issue is with the declaration as well as the device. Accurate answers before booking prevent this entirely.

Everything has to be resolved within the three month window from your Cyber Essentials certification, so leave enough time to fix things rather than booking the audit at the last possible moment.

The short version

Answer the self-assessment accurately, because you cannot change it later. Keep the whole estate patched as a matter of routine, because a second sample will now check. Book with time to spare within the three month window. Do those three things and the audit day is mostly a matter of confirming work you are already doing.

Your preparation checklist

  • Cyber Essentials is current, and you know the date the three month window closes.
  • Self-assessment answers are accurate and final, reviewed against how things actually work now.
  • Device inventory is complete, including operating systems and device types, so the sample is representative.
  • Patching is routine across the whole estate, with high and critical updates applied within 14 days and checked as installed.
  • Unsupported software has been removed or technically separated from the scope.
  • Malware protection is present and updating on every in-scope device, including new ones.
  • Multi-factor authentication is enforced on every cloud service in scope.
  • Users are not local administrators, and administrator accounts are separate from everyday accounts.
  • The right people are booked: administrative access, users of sampled devices and a decision-maker.
  • Access has been agreed with your assessor in advance.
  • Your IT provider is involved, if you have one, and available on the day.
  • Time is left for fixes before the three month window closes.

Our guide to staying compliant with Cyber Essentials covers keeping these controls in place between assessments, and Cyber Essentials vs Cyber Essentials Plus sets out the difference between the two levels.

Discuss your Cyber Essentials Plus assessment

As a licensed IASME Certification Body, we carry out the Cyber Essentials Plus audit ourselves. Tell us when your Cyber Essentials certificate was issued and roughly how many devices are in scope, and we will tell you how the audit would run and how much time you have.

Discuss your assessment Cyber Essentials Plus pricing and process

Based on the Cyber Essentials Requirements for IT Infrastructure v3.3 and the Cyber Essentials Plus test specification introduced in April 2026. Exact test procedures follow the current IASME specification, which your assessor will confirm for your audit.