Skip to main content

What to expect during your Cyber Essentials Plus Audit

What to expect during your Cyber Essentials Plus Audit


​

Once you have successfully achieved Cyber Essentials, the next step is preparing for and completing your Cyber Essentials Plus (CEP) audit.

This guide explains exactly what will happen, what you need to prepare, and what to expect on the day.

Overview of the New Cyber Essentials Plus Process

Your CEP journey follows these key stages:

  1. Start audit preparation

  2. Share required documentation (asset list and authorisation form)

  3. Install vulnerability scanning tool and begin remediation

  4. Book your audit appointment

  5. Confirm your device sample

  6. Complete your audit appointment

  7. Address any outstanding actions (if required)

  8. Receive your certification

1. Start audit preparation

Once you have signed the declaration for your Cyber Essentials assessment, you can start preparing for your Cyber Essentials Plus audit.

Log in to the CyberSmart Dashboard and select Start Pre-Audit Preparation in the Certificates page.

Your dedicated Audit Support Agent will contact you to begin preparations and guide you through the next steps.

2. Share Required Documentation

Before the audit, you will need to submit:

  • An up-to-date asset list in .xls or .csv format (and keep this updated throughout the process)

  • A signed Audit Authorisation Form, including any external IP addresses that require scanning

Accurate documentation is essential, as your audit sample is selected based on this information.

You can now complete both of these directly in the CyberSmart dashboard, from the CEP Certificates page.

Audit Authorisation Form

The Audit Authorisation form confirms the scope of your vulnerability scan and gives CyberSmart permission to carry it out.

To complete the form:

  1. Go to the CEP Certificates page for your organisation.

  2. Open the Audit Authorisation task.

  3. Enter your in-scope IP addresses and network descriptions.

  4. Confirm your full name and role.

  5. Read and accept the terms, then add your digital signature.

  6. Select Save and submit.

If you don't complete every field, your progress is saved as a draft — you can return and finish it later. Once submitted, the task status changes to Pending Review while our audit team checks it.

Form as it appears with example IP addresses entered

Sharing the form with someone else

If the person who needs to sign doesn't have a CyberSmart login, you can generate a shareable link:

  1. On the Audit Authorisation task, select Share link.

  2. Copy the link and send it to your contact.

  3. They can complete and submit the form without logging in.

The link can be reused if the form needs updating, and remains active until your CEP certificate is issued or failed.

Complete form - to fill in within the dashboard

Share form - to access a shareable link

If your form is pushed back

If our audit team finds something missing or incorrect, the task status changes to Requires Attention and a comment is added explaining what to fix. Update the form and resubmit.

Downloading a copy

Once your form has been reviewed and approved, select Export as PDF from the task to download a copy for your records. The PDF is timestamped to show when it was completed.

Note: once your CEP certificate complete, the form becomes read-only.

Asset List Upload

The asset list tells us which end user devices, servers and mobiles are in scope for your CEP audit.

To upload your asset list:

  1. Go to the CEP Certificates page for your organisation.

  2. Open the Asset List task.

  3. Download the template (available as CSV or XLSX) if you haven't already, and fill it in.

  4. Drag your completed file into the upload area, or select it via Browse.

  5. Select Upload.

File requirements

  • Accepted formats: CSV and XLSX

  • Maximum file size: 50MB

  • Maximum 6 files per organisation

You can upload more than one file if your assets are split across multiple lists — for example, by site or device type.

Managing your files

Each uploaded file shows its name, upload date, and who uploaded it. You can download a file again at any time, or delete it (you'll be asked to confirm first).

Task status

The Asset List task status updates automatically:

  • Awaiting submission — no files uploaded yet

  • Pending review — a file has been added or changed and is waiting for our audit team

  • Requires attention — our audit team has flagged an issue; check the comment for details

If your asset list submission is pushed back

If our audit team finds something missing or incorrect, the task status changes to Requires Attention and a comment is added explaining what to fix. Update the form and resubmit.

Where to get help

If you have questions about what to include in your Asset list or Authorisation form, contact our Audit Support team, who can support you through the process.

3. Install Vulnerability Scanning Tool

A key component of Cyber Essentials Plus is the vulnerability assessment. You can now deploy Qualys yourself, directly from the CEP Certificates page — no need to wait for installers to be emailed to you.

If you're already a CSVM customer, you'll already have Qualys in place and can continue as you do today. If you use a different PCI-DSS approved scanning tool, let us know which one in the dashboard and we'll review this with you offline — you can find a list of approved scanning tools here.

Installing Qualys

To set this up yourself from the CEP Certificates page:

  1. Select Qualys as your scanner.

  2. Your Customer ID, Activation Key and Server URI will be generated for you.

  3. Choose your installation method — Individual (single devices) or Centralised (multiple devices at once).
    ​

  4. Select your operating system (Windows, macOS or Linux) and download the relevant installer package.

Once Qualys is deployed, your vulnerability results will appear directly on your CEP Certificate page - no need to wait to receive Qualys reports

You'll see:

  • A summary count of Critical and High severity vulnerabilities across your estate

  • A detailed view you can explore by vulnerability or by device

  • Device-level detail including host name, OS, last user, IP address and last scan result

We strongly recommend installing Qualys as soon as possible to:

  • Avoid technical delays ahead of your audit

  • Begin receiving daily vulnerability reports

  • Remediate any High or Critical vulnerabilities (CVSSv3 score 7.0 or above) older than 14 days before your audit

All High and Critical vulnerabilities with a published date older than 14 days must be resolved before certification can be issued.

4. Book your audit

Before booking your audit we ask you to complete all your pre-audit commitments. This means:

  • Share relevant documentation

  • Deploy Qualys on all requested device types and quantities

  • Remediate all issues highlighted in the daily Qualys report

Remediating issues before your audit date will help reduce delays and improve the likelihood of a smooth certification process.

When you are satisfied you are ready, you can book your audit in the certificates page in the CyberSmart Dashboard.

5. Confirm Device Sampling

No sooner than three days before your audit, we will confirm the final sample of devices that will be assessed.

You must:

  • Confirm these devices will be available during the audit appointment

  • Notify us immediately if any device will not be available so we can select an alternative

Devices are selected by the auditor to ensure the sample is representative of your environment. You cannot select your own devices for assessment.

Once confirmed, your Qualys report will be updated to show only the devices in scope for the audit.

Do not remove Qualys from the devices not selected for the audit — your auditor may need to use these later.

6. What Happens on the Day of the Audit

Your audit appointment will involve a combination of automated scans and live verification checks.

  1. Vulnerability Scanning

  • Internal credentialed patch audit scan of sampled devices (via Qualys or your approved PCI-DSS scanner)

  • External vulnerability scan of publicly facing IP addresses and services

  1. User Device Security Tests (via Screen Sharing) We will require access to user devices in scope. The real user email address associated with the device must be provided — generic or test accounts cannot be used.

We will:

  • Test how email attachments are processed

  • Test how devices handle file downloads from controlled test websites

  1. Endpoint & Mobile Protection Checks

  • Verify installation and configuration of anti-virus software

  • Perform iOS/mobile checks (if mobile devices are in scope)

  1. Access Control & Authentication Checks

  • Perform Multi-Factor Authentication (MFA) tests on all listed cloud services

  • Confirm MFA is enabled for both Admin and User accounts

  • Verify separation between Admin and standard User accounts

7. After the Audit Appointment

It is common for there to be some outstanding actions following the audit. This does not automatically mean failure.

Outstanding actions may include:

  • Remediation of remaining vulnerabilities before CEP deadline lapses

  • Submission of additional evidence (e.g. screenshots of mobile configurations)

Your auditor will clearly outline:

  • What is required

  • How to submit evidence

  • The deadline for completion

If there are vulnerabilities present with a CVSSv3 Base Score of 7 and above that are older than 14 days, you will be required to remediate these before your audit deadline.

If you are certifying on the new Danzell 2026 standard:

Your assessor will also need to check a sample of devices. If vulnerabilities identified in Sample 1 are also found in Sample 2, these will need to be remediated before the audit deadline. As per the Cyer Essentials scheme, failure to do so will result in the failure of the Cyber Essentials Plus, and the revocation of Cyber Essentials. More information on this process can be found in the linked Knowledge Base articles below.

All requested documentation and remediation evidence must be submitted by replying to the existing audit email thread.

Deadlines & Certification

Your certificate must be issued to you within 90 days of completing your Cyber Essentials or 1 month from your audit date (whichever is sooner). Please be mindful of the certification deadline communicated to you.

If all required evidence is not received before the deadline, the assessment may be marked as failed and would need to be rebooked. You may also be required to re-take your Cyber Essentials.

Once the auditor is satisfied that all requirements have been met:

  • Your details will be uploaded to the IASME portal

  • Your Cyber Essentials Plus certificate will be issued

Once your certificate has been issued, your assessor will automatically remove Qualys from your devices and stop the automated reports.

Need Support?

If you have any questions at any stage of the process:

  • Ask your dedicated Audit Support Agent by responding within the initial email thread

  • Contact your Account Manager

  • Or reach out to our CX team via Live Chat

We are here to support you throughout your Cyber Essentials Plus journey.

Did this answer your question?