Cyber Essentials Plus Readiness Check: would you survive the hands-on audit?
Would you pass the Cyber Essentials Plus hands-on audit? Free UK check covering vulnerability scanning, patching, MFA and access controls. Results in minutes.
Would you pass the Cyber Essentials Plus hands-on audit? Free UK check covering vulnerability scanning, patching, MFA and access controls. Results in minutes.
Cyber Essentials Plus covers the same five controls as Cyber Essentials (firewalls, secure configuration, user access control, malware protection and security update management), but an assessor verifies them hands-on through external vulnerability scans and an authenticated test of a sample of your devices. This tool walks you through each requirement and flags where you are likely to fail the audit.
Certification fees vary by assessor and the size of your estate, and the bigger cost is usually the remediation work needed to pass. This readiness check is free and shows you that remediation list first, so you only book the paid audit when you are genuinely ready and not paying twice.
The assessor runs an external vulnerability scan, then an internal authenticated scan on a representative sample of devices, checks that malware protection and account separation work, and confirms high and critical updates are applied within 14 days. Most failures come from missed updates, leftover local admin rights and unmanaged devices. This tool tests against those same checks.
Cyber Essentials Plus is the independently audited version of Cyber Essentials. An IASME-licensed certification body performs hands-on technical testing of your IT systems to verify that the controls you described in the self-assessment questionnaire actually work in practice. It tests the same five themes: firewalls, secure configuration, security update management, user access control, and malware protection.
Cyber Essentials is a verified self-assessment: you answer questions and an assessor reviews your answers. Cyber Essentials Plus adds hands-on technical testing by an independent auditor. The same five themes are tested but the auditor verifies the controls on your real systems, which is where the gap between what organisations believe and what an auditor finds tends to emerge.
Because self-assessment and technical testing reveal different things. Secure configuration alone accounts for roughly 40% of Plus failures: organisations believe devices are configured correctly, but audit testing finds exceptions, legacy devices out of policy, or controls that work in principle but not for every machine in scope. The Plus audit is designed to find exactly those gaps.
No. This is a readiness signal, not a certificate. Cyber Essentials Plus certification comes only through an IASME-licensed certification body. A PASS prediction here means your self-assessed answers, including the audit-grade checks, are consistent with passing the technical testing. It is the honest picture before you commission the audit.
You answer across the five themes, including the additional audit-grade checks, and receive a pass or fail prediction at theme level, the exact findings an auditor would write up for every non-pass answer, and a prioritised remediation list.
Ideally the person who knows your IT estate in detail, not just believes it. That may be your IT manager, your outsourced support provider working with you, or your internal IT lead. The audit-grade checks require honest answers about patch state, device lists, and MFA coverage across the whole scope.