Skip to content

Evidence request lists

Cyber Essentials Plus

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Audit

CEP-AUD-01
Annual Hands On Audit and Recertification

CE Plus certification requires an annual hands on technical audit by a licensed IASME assessor, with sample sizes drawn from each device platform and remediation of all findings before issue.

Artefacts an auditor will ask for
  • IASME assessor engagement letter
  • audit report
  • remediation tracker
  • prior year certificate
Where this commonly fails
  • audit deferred beyond 12 months
  • sample too small to be representative
  • findings not closed before certificate issue

Cloud Services

CEP-CLD-01
Cloud Services in Scope

All cloud services (IaaS, PaaS, SaaS) used to store or process organisational data fall within scope and must meet the same controls as on premise systems.

Artefacts an auditor will ask for
  • cloud service register
  • shared responsibility matrix
  • vendor due diligence records
Where this commonly fails
  • shadow IT SaaS not inventoried
  • no MFA on smaller cloud tools
  • responsibility split misunderstood

Cyber Essentials Plus Test Specification

CE-PLUS.1
Authenticated Vulnerability Scan of Sample Devices

An authenticated vulnerability scan is performed by the assessor on a representative sample of in-scope EUDs and servers. Any high or critical CVE older than 14 days fails.

Artefacts an auditor will ask for
  • assessor scan report
  • device sample list
  • remediation evidence
Where this commonly fails
  • sample not representative
  • patch backlog discovered
CE-PLUS.2
External Vulnerability Scan of Internet IPs

An external (unauthenticated) vulnerability scan of all internet-facing IP addresses in scope. Any high or critical CVE older than 14 days fails.

Artefacts an auditor will ask for
  • external IP list
  • external scan report
  • remediation tickets
Where this commonly fails
  • forgotten public IPs
  • self-signed/expired TLS certs flagged
CE-PLUS.3
Malware Protection Test - EICAR via Email

Assessor tests that mail filtering blocks malicious file attachments using EICAR or simulated malware sample sent to a real user mailbox.

Artefacts an auditor will ask for
  • test sample receipt evidence
  • block confirmation from mail filter
  • assessor test record
Where this commonly fails
  • EICAR not blocked
  • ZIP/encrypted variants not handled
CE-PLUS.4
Malware Protection Test - Web Download

Assessor tests that the device or web filter blocks malicious files when downloaded via browser from a controlled test URL.

Artefacts an auditor will ask for
  • block screenshot from browser/AV
  • URL filtering log
  • assessor record
Where this commonly fails
  • browser allows download
  • AV blocks but logs nothing
CE-PLUS.5
Removable Media Malware Test

Where removable media is permitted, assessor tests that introducing EICAR or sample malware via USB is blocked or detected by anti-malware.

Artefacts an auditor will ask for
  • USB test log
  • endpoint AV detection event
Where this commonly fails
  • AutoPlay launches file
  • AV bypassed by archive
CE-PLUS.6
Account Separation Verification

Assessor verifies on sample devices that standard user accounts cannot install software or perform administrative tasks without separate credentials.

Artefacts an auditor will ask for
  • assessor test transcript
  • screenshot of UAC/sudo prompt
  • failure log for unauthorised install
Where this commonly fails
  • users are local admin
  • UAC disabled
CE-PLUS.7
MFA Verification on Cloud Services

Assessor verifies that MFA is enforced for all admin accounts and all users on cloud services by inspecting policy and attempting sign-in.

Artefacts an auditor will ask for
  • Conditional Access policy export
  • MFA challenge screenshot during test sign-in
  • user/admin MFA coverage report
Where this commonly fails
  • MFA legacy auth bypass
  • users excluded from CA policy
CE-PLUS.8
Sample Size and Representativeness

CE Plus assessor selects a sample of devices covering each OS, build, location and role. Sample size follows IASME guidance (typically square root of population, minimum threshold per OS).

Artefacts an auditor will ask for
  • device population list
  • sample selection rationale
  • assessor sample log
Where this commonly fails
  • only Windows sampled
  • no remote workers in sample

Firewalls

CEP-FW-01
Boundary Firewall Configuration

All internet connected devices must sit behind a correctly configured boundary firewall or equivalent, with unused services blocked and administrative interfaces inaccessible from the internet.

Artefacts an auditor will ask for
  • firewall ruleset export
  • change tickets for rule additions
  • external port scan results
  • admin interface restriction proof
Where this commonly fails
  • any-any rules in place
  • default admin passwords on perimeter devices
  • RDP exposed externally
CEP-FW-02
Host Based Firewall on Devices

End user devices and servers must have host based firewalls enabled and configured to block unsolicited inbound connections by default.

Artefacts an auditor will ask for
  • MDM or GPO showing firewall enabled
  • sample device screenshots
  • exception register
Where this commonly fails
  • firewall disabled for legacy apps
  • user can toggle off without admin rights
  • no monitoring of disabled hosts

Malware Protection

CEP-MA-01
Anti-Malware Deployment and Operation

All in scope devices must run anti malware software that is kept current, scans files on access and prevents execution of known malicious code.

Artefacts an auditor will ask for
  • EDR console coverage report
  • signature update logs
  • EICAR test results per device class
Where this commonly fails
  • servers without EDR agent
  • agents reporting offline 30+ days
  • no on access scanning on macOS
CEP-MA-02
Application Allow Listing or Sandboxing

As an alternative or supplement to signature anti malware, organisations may use application allow listing or sandboxing to prevent execution of unauthorised code.

Artefacts an auditor will ask for
  • allow list policy export
  • sandboxing tool configuration
  • exception process records
Where this commonly fails
  • allow list in audit mode only
  • no review of blocked executions
  • sandbox bypass for power users
CEP-MA-03
Email Attachment Test

The CE Plus auditor sends test files including known malicious file types to in scope mailboxes to verify that malicious attachments are blocked or detonated safely.

Artefacts an auditor will ask for
  • auditor test plan
  • email gateway logs of blocked test files
  • mailbox screenshots showing quarantine
Where this commonly fails
  • macros not stripped from documents
  • encrypted ZIP test files delivered intact
  • no detonation of unknown files
CEP-MA-04
Web Browsing Malware Test

The auditor attempts to download known malicious files from a test URL list via supported browsers to verify web filtering and endpoint protection blocks the payload.

Artefacts an auditor will ask for
  • web proxy logs
  • endpoint quarantine records
  • auditor results sheet per browser
Where this commonly fails
  • secondary browsers unprotected
  • personal accounts bypass proxy
  • BYOD devices not in scope of filtering

Mobile and Remote

CEP-MOB-01
Mobile Device Management and Encryption

Mobile devices used to access corporate data must be managed, encrypted at rest, require a screen lock and be capable of remote wipe.

Artefacts an auditor will ask for
  • MDM enrolment report
  • encryption status per device
  • remote wipe test record
  • BYOD policy
Where this commonly fails
  • personal devices unmanaged accessing email
  • encryption not verified on Android
  • wipe never tested

Scope

CEP-SCP-01
Scope Definition and Whole Organisation Boundary

The certification scope must include the whole organisation or a clearly defined sub set with documented network and trust boundaries, and the scope must be reaffirmed at each annual cycle.

Artefacts an auditor will ask for
  • scope statement
  • network diagram
  • out of scope justification
  • annual scope review record
Where this commonly fails
  • scope drift after acquisitions
  • untrusted networks not segregated
  • BYOD declared out of scope without controls

Secure Configuration

CEP-SC-01
Secure Configuration of Devices

Devices must be configured to remove or disable unnecessary user accounts, software, services and default passwords before deployment.

Artefacts an auditor will ask for
  • build standards documents
  • CIS or NCSC hardening checklists
  • default credentials remediation log
Where this commonly fails
  • default accounts left enabled on servers
  • no documented build
  • test images deployed to production
CEP-SC-02
Auto-Run and Auto-Play Disabled

Auto run and auto play must be disabled on all devices to prevent execution of code from removable media without explicit user authorisation.

Artefacts an auditor will ask for
  • GPO or MDM configuration
  • auditor USB plug-in test result
  • user policy acknowledgement
Where this commonly fails
  • auto run still enabled on older Windows builds
  • no policy on macOS
  • removable media unrestricted
CEP-SC-03
Multi-Factor Authentication for Cloud Services

Multi factor authentication must be enforced on all administrator and standard user accounts accessing cloud services, including email and file storage.

Artefacts an auditor will ask for
  • MFA conditional access policies
  • MFA registration reports
  • exception register with expiry
Where this commonly fails
  • MFA on admins only not standard users
  • legacy authentication protocols still open
  • break glass accounts without monitored alerts

Security Update Management

CEP-PM-01
High and Critical Vulnerability Patching

Security updates rated high or critical must be applied within 14 days of release for operating systems and supported applications, or vulnerable software removed.

Artefacts an auditor will ask for
  • patch deployment reports
  • internal authenticated scan results
  • exception register with risk owner sign off
Where this commonly fails
  • scan shows 14+ day breaches
  • no scan of servers
  • patches deferred without documented risk acceptance
CEP-PM-02
Unsupported Software Removal

Software and operating systems that are no longer supported by the vendor must be removed from in scope devices or isolated with compensating controls.

Artefacts an auditor will ask for
  • software inventory with vendor support status
  • EOL remediation plan
  • isolation network diagrams
Where this commonly fails
  • Windows 7 or unsupported Server still in scope
  • EOL Java runtimes on user devices
  • no inventory accuracy check
CEP-PM-03
Authenticated Vulnerability Scan of Sample Devices

An authenticated vulnerability scan of a representative sample of end user devices and servers must show no high or critical CVEs older than 14 days with CVSS 7.0 or above.

Artefacts an auditor will ask for
  • scan tool configuration
  • sample selection rationale
  • scan report with CVSS scores
  • remediation evidence
Where this commonly fails
  • unauthenticated scans only
  • sample biased to new builds
  • false positive list undocumented
CEP-PM-04
External Vulnerability Scan of Internet Facing Services

An external vulnerability scan from the auditor against all internet facing IP addresses and services must show no exploitable high or critical findings.

Artefacts an auditor will ask for
  • asset list of internet facing IPs
  • external scan report
  • remediation records for findings
Where this commonly fails
  • forgotten cloud assets out of scope
  • open management interfaces
  • expired TLS or weak ciphers

User Access Control

CEP-UA-01
Separation of Administrator Accounts

Administrative accounts must be separate from standard user accounts and must not be used for routine activity such as email or web browsing.

Artefacts an auditor will ask for
  • admin account inventory
  • PAM tool reports
  • training records on dual account use
Where this commonly fails
  • admins using single account for everything
  • domain admin rights to daily driver laptop
  • no audit of admin email use
CEP-UA-02
Account Provisioning and Deprovisioning

User accounts must be created through an approved process and disabled or removed promptly when no longer required, including on leaver day.

Artefacts an auditor will ask for
  • JML procedure
  • HR feed to identity system
  • leaver disablement timestamps
  • quarterly access review records
Where this commonly fails
  • leavers still enabled weeks later
  • shared accounts in use
  • no quarterly review
CEP-UA-03
Password Policy and Brute Force Protection

Authentication must be protected against brute force, including minimum password length, password deny lists or use of MFA and lockout or throttling.

Artefacts an auditor will ask for
  • password policy export
  • deny list source
  • lockout threshold screenshots
  • MFA coverage report
Where this commonly fails
  • 12 character minimum not met
  • no deny list for common passwords
  • lockout disabled to reduce help desk calls
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.