Cyber Essentials · Cybersecurity & Cloud
Cyber Essentials Plus: IASME, the hands-on test, and why the badge is not a pen test
How UK organizations prepare for Cyber Essentials Plus — scope, technical verification, and the difference from the questionnaire-only scheme.
6 min read
Cyber Essentials Plus is the independently verified version of the UK's Cyber Essentials scheme. It tests whether the five baseline control themes are working in practice, not just whether the questionnaire was answered confidently.
For many suppliers, CE+ is a procurement gate for UK public sector and regulated customers. It is narrower than ISO 27001 and different from a penetration test, but it is very practical: unsupported devices, weak patching, exposed services, and unmanaged endpoints can stop certification quickly.
The paired checklist gives the execution path. This guide helps teams make the judgment calls around scope, devices, remote work, BYOD, and technical readiness before the assessor's hands-on test turns assumptions into findings.
What Cyber Essentials Plus actually is
Cyber Essentials Plus builds on the self-assessment scheme by adding independent technical verification. The assessor checks a sample of devices and services against requirements for firewalls, secure configuration, user access control, malware protection, and security update management.
The scheme is intentionally baseline-focused. It does not certify that the organization has a full information-security management system, strong application security, or mature incident response. Its value is that it forces basic hygiene to be true across the scoped environment, including devices that touch government work or sensitive customer activity.
The practical object of CE+ is the real endpoint and service estate, not the policy boundary a team wishes it had. Laptops used by contractors, remote devices that reach email, mobile devices with corporate data, and cloud services that expose administration all need to be understood before sampling begins. The assessor's test is strongest when it reflects how work is actually done, including hybrid work patterns that rarely appear in neat network diagrams.
Decisions the checklist will not make for you
The checklist cannot decide what is legitimately in scope. Leadership must determine which networks, endpoints, cloud services, home-working devices, BYOD arrangements, and subsidiaries support the work that requires CE+. Scoping out devices that perform government work because they are inconvenient is a readiness failure, not a strategy.
It also cannot decide how strict the organization will be about unmanaged devices. BYOD without mobile device management, weak patch visibility, or local admin rights may be culturally accepted, but the technical test will evaluate control reality rather than policy intent.
The checklist will not tell you whether to delay the assessment. If external services are unpatched, unsupported systems remain active, or the questionnaire answer cannot be demonstrated, the decision is whether to remediate first or risk a failed test.
Where teams actually fail
The most common failure is scope optimism. Teams exclude laptops, home-working setups, mobile devices, or cloud admin paths that genuinely support in-scope activity. The assessor then finds the forgotten device class, or the buyer asks why the scope does not match the service being procured.
Another failure is passing the questionnaire but failing Plus. A policy may say patches are applied within the required window, but the sample includes an unpatched browser, unsupported operating system, or internet-facing service with a known vulnerability. CE+ rewards operational truth, not documentation.
BYOD and mobile are frequent pain points. If personal devices access corporate mail or customer data without MDM, secure configuration, patch enforcement, and access controls, the organization may not be able to prove the baseline. Teams often discover this only after the assessment is booked.
Internet-facing services deserve their own pre-test review. A forgotten VPN portal, remote desktop service, admin console, or legacy web server can fail the assessment even if the internal endpoint sample is healthy. Asset discovery should include DNS, cloud accounts, external scanning, and ownership checks so the assessment does not uncover an avoidable surprise.
How to use the paired checklist
Use the checklist first to define scope in plain operational terms: who does the work, which devices they use, which cloud services they access, which networks and remote paths are involved, and which internet-facing services belong to the organization.
Then test the answers before the assessor does. Pull patch reports, review local admin, inspect endpoint protection, scan external services, validate firewall rules, and confirm unsupported software has been removed. Treat every checkbox as something that may need technical evidence.
After certification, keep the checklist tied to asset and change management. CE+ can fail again next year if a new unmanaged device group, exposed service, or BYOD exception enters the environment without the same hygiene controls. Treat every new device class, remote-access path, and external service as a potential scope change rather than waiting for the renewal assessment.
What teams get wrong
- Cyber Essentials Plus is basically a penetration test.
- CE+ is a technical verification of baseline controls; a penetration test examines exploit paths in a scoped attack simulation. Many organizations need both, but they answer different buyer and risk questions.
- If the questionnaire passed, Plus will pass.
- Plus checks whether selected devices and services actually meet the requirements, so evidence can contradict questionnaire answers. Treat the self-assessment as a readiness hypothesis that must survive technical testing.
- Personal devices are out of scope by default.
- BYOD can be in scope when it accesses organizational data or services relevant to the certification boundary. If the organization cannot manage or evidence those devices, it needs a different access model before assessment.
When the checklist is enough — and when it is not
- Teams want to exclude devices or services that support the in-scope work.
- Internet-facing services have known vulnerabilities or unsupported software.
- BYOD is used without MDM, patch visibility, or enforceable configuration controls.
- Questionnaire answers cannot be demonstrated with technical evidence.
Related checklists
Information Security
ISO 27001:2022 Implementation & Audit Readiness Checklist
Guide: ISO 27001:2022 audit readiness: what Stage 1 and Stage 2 actually test
Vuln Mgmt
Vulnerability Management Program Checklist
Guide: Vulnerability management: SLA by severity, internet-facing truth, and scanner theatre
PAM
Privileged Access Management (PAM) Checklist
Guide: Privileged access management: standing admin is the incident, not the exception
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer