Cyber Essentials Plus
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Audit
CE Plus certification requires an annual hands on technical audit by a licensed IASME assessor, with sample sizes drawn from each device platform and remediation of all findings before issue.
- IASME assessor engagement letter
- audit report
- remediation tracker
- prior year certificate
- audit deferred beyond 12 months
- sample too small to be representative
- findings not closed before certificate issue
Cloud Services
All cloud services (IaaS, PaaS, SaaS) used to store or process organisational data fall within scope and must meet the same controls as on premise systems.
- cloud service register
- shared responsibility matrix
- vendor due diligence records
- shadow IT SaaS not inventoried
- no MFA on smaller cloud tools
- responsibility split misunderstood
Cyber Essentials Plus Test Specification
An authenticated vulnerability scan is performed by the assessor on a representative sample of in-scope EUDs and servers. Any high or critical CVE older than 14 days fails.
- assessor scan report
- device sample list
- remediation evidence
- sample not representative
- patch backlog discovered
An external (unauthenticated) vulnerability scan of all internet-facing IP addresses in scope. Any high or critical CVE older than 14 days fails.
- external IP list
- external scan report
- remediation tickets
- forgotten public IPs
- self-signed/expired TLS certs flagged
Assessor tests that mail filtering blocks malicious file attachments using EICAR or simulated malware sample sent to a real user mailbox.
- test sample receipt evidence
- block confirmation from mail filter
- assessor test record
- EICAR not blocked
- ZIP/encrypted variants not handled
Assessor tests that the device or web filter blocks malicious files when downloaded via browser from a controlled test URL.
- block screenshot from browser/AV
- URL filtering log
- assessor record
- browser allows download
- AV blocks but logs nothing
Where removable media is permitted, assessor tests that introducing EICAR or sample malware via USB is blocked or detected by anti-malware.
- USB test log
- endpoint AV detection event
- AutoPlay launches file
- AV bypassed by archive
Assessor verifies on sample devices that standard user accounts cannot install software or perform administrative tasks without separate credentials.
- assessor test transcript
- screenshot of UAC/sudo prompt
- failure log for unauthorised install
- users are local admin
- UAC disabled
Assessor verifies that MFA is enforced for all admin accounts and all users on cloud services by inspecting policy and attempting sign-in.
- Conditional Access policy export
- MFA challenge screenshot during test sign-in
- user/admin MFA coverage report
- MFA legacy auth bypass
- users excluded from CA policy
CE Plus assessor selects a sample of devices covering each OS, build, location and role. Sample size follows IASME guidance (typically square root of population, minimum threshold per OS).
- device population list
- sample selection rationale
- assessor sample log
- only Windows sampled
- no remote workers in sample
Firewalls
All internet connected devices must sit behind a correctly configured boundary firewall or equivalent, with unused services blocked and administrative interfaces inaccessible from the internet.
- firewall ruleset export
- change tickets for rule additions
- external port scan results
- admin interface restriction proof
- any-any rules in place
- default admin passwords on perimeter devices
- RDP exposed externally
End user devices and servers must have host based firewalls enabled and configured to block unsolicited inbound connections by default.
- MDM or GPO showing firewall enabled
- sample device screenshots
- exception register
- firewall disabled for legacy apps
- user can toggle off without admin rights
- no monitoring of disabled hosts
Malware Protection
All in scope devices must run anti malware software that is kept current, scans files on access and prevents execution of known malicious code.
- EDR console coverage report
- signature update logs
- EICAR test results per device class
- servers without EDR agent
- agents reporting offline 30+ days
- no on access scanning on macOS
As an alternative or supplement to signature anti malware, organisations may use application allow listing or sandboxing to prevent execution of unauthorised code.
- allow list policy export
- sandboxing tool configuration
- exception process records
- allow list in audit mode only
- no review of blocked executions
- sandbox bypass for power users
The CE Plus auditor sends test files including known malicious file types to in scope mailboxes to verify that malicious attachments are blocked or detonated safely.
- auditor test plan
- email gateway logs of blocked test files
- mailbox screenshots showing quarantine
- macros not stripped from documents
- encrypted ZIP test files delivered intact
- no detonation of unknown files
The auditor attempts to download known malicious files from a test URL list via supported browsers to verify web filtering and endpoint protection blocks the payload.
- web proxy logs
- endpoint quarantine records
- auditor results sheet per browser
- secondary browsers unprotected
- personal accounts bypass proxy
- BYOD devices not in scope of filtering
Mobile and Remote
Mobile devices used to access corporate data must be managed, encrypted at rest, require a screen lock and be capable of remote wipe.
- MDM enrolment report
- encryption status per device
- remote wipe test record
- BYOD policy
- personal devices unmanaged accessing email
- encryption not verified on Android
- wipe never tested
Scope
The certification scope must include the whole organisation or a clearly defined sub set with documented network and trust boundaries, and the scope must be reaffirmed at each annual cycle.
- scope statement
- network diagram
- out of scope justification
- annual scope review record
- scope drift after acquisitions
- untrusted networks not segregated
- BYOD declared out of scope without controls
Secure Configuration
Devices must be configured to remove or disable unnecessary user accounts, software, services and default passwords before deployment.
- build standards documents
- CIS or NCSC hardening checklists
- default credentials remediation log
- default accounts left enabled on servers
- no documented build
- test images deployed to production
Auto run and auto play must be disabled on all devices to prevent execution of code from removable media without explicit user authorisation.
- GPO or MDM configuration
- auditor USB plug-in test result
- user policy acknowledgement
- auto run still enabled on older Windows builds
- no policy on macOS
- removable media unrestricted
Multi factor authentication must be enforced on all administrator and standard user accounts accessing cloud services, including email and file storage.
- MFA conditional access policies
- MFA registration reports
- exception register with expiry
- MFA on admins only not standard users
- legacy authentication protocols still open
- break glass accounts without monitored alerts
Security Update Management
Security updates rated high or critical must be applied within 14 days of release for operating systems and supported applications, or vulnerable software removed.
- patch deployment reports
- internal authenticated scan results
- exception register with risk owner sign off
- scan shows 14+ day breaches
- no scan of servers
- patches deferred without documented risk acceptance
Software and operating systems that are no longer supported by the vendor must be removed from in scope devices or isolated with compensating controls.
- software inventory with vendor support status
- EOL remediation plan
- isolation network diagrams
- Windows 7 or unsupported Server still in scope
- EOL Java runtimes on user devices
- no inventory accuracy check
An authenticated vulnerability scan of a representative sample of end user devices and servers must show no high or critical CVEs older than 14 days with CVSS 7.0 or above.
- scan tool configuration
- sample selection rationale
- scan report with CVSS scores
- remediation evidence
- unauthenticated scans only
- sample biased to new builds
- false positive list undocumented
An external vulnerability scan from the auditor against all internet facing IP addresses and services must show no exploitable high or critical findings.
- asset list of internet facing IPs
- external scan report
- remediation records for findings
- forgotten cloud assets out of scope
- open management interfaces
- expired TLS or weak ciphers
User Access Control
Administrative accounts must be separate from standard user accounts and must not be used for routine activity such as email or web browsing.
- admin account inventory
- PAM tool reports
- training records on dual account use
- admins using single account for everything
- domain admin rights to daily driver laptop
- no audit of admin email use
User accounts must be created through an approved process and disabled or removed promptly when no longer required, including on leaver day.
- JML procedure
- HR feed to identity system
- leaver disablement timestamps
- quarterly access review records
- leavers still enabled weeks later
- shared accounts in use
- no quarterly review
Authentication must be protected against brute force, including minimum password length, password deny lists or use of MFA and lockout or throttling.
- password policy export
- deny list source
- lockout threshold screenshots
- MFA coverage report
- 12 character minimum not met
- no deny list for common passwords
- lockout disabled to reduce help desk calls
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.