What to expect during your Cyber Essentials Plus Audit
Once you have successfully achieved Cyber Essentials, the next step is preparing for and completing your Cyber Essentials Plus (CEP) audit.
This guide explains exactly what will happen, what you need to prepare, and what to expect on the day.
Overview of the New Cyber Essentials Plus Process
Your CEP journey follows these key stages:
Start audit preparation
Share required documentation (asset list and authorisation form)
Install vulnerability scanning tool and begin remediation
Book your audit appointment
Confirm your device sample
Complete your audit appointment
Address any outstanding actions (if required)
Receive your certification
1. Start audit preparation
Once you have signed the declaration for your Cyber Essentials assessment, you can start preparing for your Cyber Essentials Plus audit.
Log in to the CyberSmart Dashboard and select Start Pre-Audit Preparation in the Certificates page.
Your dedicated Audit Support Agent will contact you to begin preparations and guide you through the next steps.
2. Share Required Documentation
Before the audit, you will need to submit:
An up-to-date asset list in .xls or .csv format (and keep this updated throughout the process)
A signed Audit Authorisation Form, including any external IP addresses that require scanning
Accurate documentation is essential, as your audit sample is selected based on this information.
You can now complete both of these directly in the CyberSmart dashboard, from the CEP Certificates page.
Audit Authorisation Form
The Audit Authorisation form confirms the scope of your vulnerability scan and gives CyberSmart permission to carry it out.
To complete the form:
Go to the CEP Certificates page for your organisation.
Open the Audit Authorisation task.
Enter your in-scope IP addresses and network descriptions.
Confirm your full name and role.
Read and accept the terms, then add your digital signature.
Select Save and submit.
If you don't complete every field, your progress is saved as a draft — you can return and finish it later. Once submitted, the task status changes to Pending Review while our audit team checks it.
Form as it appears with example IP addresses entered
Sharing the form with someone else
If the person who needs to sign doesn't have a CyberSmart login, you can generate a shareable link:
On the Audit Authorisation task, select Share link.
Copy the link and send it to your contact.
They can complete and submit the form without logging in.
The link can be reused if the form needs updating, and remains active until your CEP certificate is issued or failed.
Complete form - to fill in within the dashboard
Share form - to access a shareable link
If your form is pushed back
If our audit team finds something missing or incorrect, the task status changes to Requires Attention and a comment is added explaining what to fix. Update the form and resubmit.
Downloading a copy
Once your form has been reviewed and approved, select Export as PDF from the task to download a copy for your records. The PDF is timestamped to show when it was completed.
Note: once your CEP certificate complete, the form becomes read-only.
Asset List Upload
The asset list tells us which end user devices, servers and mobiles are in scope for your CEP audit.
To upload your asset list:
Go to the CEP Certificates page for your organisation.
Open the Asset List task.
Download the template (available as CSV or XLSX) if you haven't already, and fill it in.
Drag your completed file into the upload area, or select it via Browse.
Select Upload.
File requirements
Accepted formats: CSV and XLSX
Maximum file size: 50MB
Maximum 6 files per organisation
You can upload more than one file if your assets are split across multiple lists — for example, by site or device type.
Managing your files
Each uploaded file shows its name, upload date, and who uploaded it. You can download a file again at any time, or delete it (you'll be asked to confirm first).
Task status
The Asset List task status updates automatically:
Awaiting submission — no files uploaded yet
Pending review — a file has been added or changed and is waiting for our audit team
Requires attention — our audit team has flagged an issue; check the comment for details
If your asset list submission is pushed back
If our audit team finds something missing or incorrect, the task status changes to Requires Attention and a comment is added explaining what to fix. Update the form and resubmit.
Where to get help
If you have questions about what to include in your Asset list or Authorisation form, contact our Audit Support team, who can support you through the process.
3. Install Vulnerability Scanning Tool
A key component of Cyber Essentials Plus is the vulnerability assessment. You can now deploy Qualys yourself, directly from the CEP Certificates page — no need to wait for installers to be emailed to you.
If you're already a CSVM customer, you'll already have Qualys in place and can continue as you do today. If you use a different PCI-DSS approved scanning tool, let us know which one in the dashboard and we'll review this with you offline — you can find a list of approved scanning tools here.
Installing Qualys
To set this up yourself from the CEP Certificates page:
Select Qualys as your scanner.
Your Customer ID, Activation Key and Server URI will be generated for you.
Choose your installation method — Individual (single devices) or Centralised (multiple devices at once).
Select your operating system (Windows, macOS or Linux) and download the relevant installer package.
Once Qualys is deployed, your vulnerability results will appear directly on your CEP Certificate page - no need to wait to receive Qualys reports
You'll see:
A summary count of Critical and High severity vulnerabilities across your estate
A detailed view you can explore by vulnerability or by device
Device-level detail including host name, OS, last user, IP address and last scan result
We strongly recommend installing Qualys as soon as possible to:
Avoid technical delays ahead of your audit
Begin receiving daily vulnerability reports
Remediate any High or Critical vulnerabilities (CVSSv3 score 7.0 or above) older than 14 days before your audit
All High and Critical vulnerabilities with a published date older than 14 days must be resolved before certification can be issued.
4. Book your audit
Before booking your audit we ask you to complete all your pre-audit commitments. This means:
Share relevant documentation
Deploy Qualys on all requested device types and quantities
Remediate all issues highlighted in the daily Qualys report
Remediating issues before your audit date will help reduce delays and improve the likelihood of a smooth certification process.
When you are satisfied you are ready, you can book your audit in the certificates page in the CyberSmart Dashboard.
5. Confirm Device Sampling
No sooner than three days before your audit, we will confirm the final sample of devices that will be assessed.
You must:
Confirm these devices will be available during the audit appointment
Notify us immediately if any device will not be available so we can select an alternative
Devices are selected by the auditor to ensure the sample is representative of your environment. You cannot select your own devices for assessment.
Once confirmed, your Qualys report will be updated to show only the devices in scope for the audit.
Do not remove Qualys from the devices not selected for the audit — your auditor may need to use these later.
6. What Happens on the Day of the Audit
Your audit appointment will involve a combination of automated scans and live verification checks.
Vulnerability Scanning
Internal credentialed patch audit scan of sampled devices (via Qualys or your approved PCI-DSS scanner)
External vulnerability scan of publicly facing IP addresses and services
User Device Security Tests (via Screen Sharing) We will require access to user devices in scope. The real user email address associated with the device must be provided — generic or test accounts cannot be used.
We will:
Test how email attachments are processed
Test how devices handle file downloads from controlled test websites
Endpoint & Mobile Protection Checks
Verify installation and configuration of anti-virus software
Perform iOS/mobile checks (if mobile devices are in scope)
Access Control & Authentication Checks
Perform Multi-Factor Authentication (MFA) tests on all listed cloud services
Confirm MFA is enabled for both Admin and User accounts
Verify separation between Admin and standard User accounts
7. After the Audit Appointment
It is common for there to be some outstanding actions following the audit. This does not automatically mean failure.
Outstanding actions may include:
Remediation of remaining vulnerabilities before CEP deadline lapses
Submission of additional evidence (e.g. screenshots of mobile configurations)
Your auditor will clearly outline:
What is required
How to submit evidence
The deadline for completion
If there are vulnerabilities present with a CVSSv3 Base Score of 7 and above that are older than 14 days, you will be required to remediate these before your audit deadline.
If you are certifying on the new Danzell 2026 standard:
Your assessor will also need to check a sample of devices. If vulnerabilities identified in Sample 1 are also found in Sample 2, these will need to be remediated before the audit deadline. As per the Cyer Essentials scheme, failure to do so will result in the failure of the Cyber Essentials Plus, and the revocation of Cyber Essentials. More information on this process can be found in the linked Knowledge Base articles below.
All requested documentation and remediation evidence must be submitted by replying to the existing audit email thread.
Deadlines & Certification
Your certificate must be issued to you within 90 days of completing your Cyber Essentials or 1 month from your audit date (whichever is sooner). Please be mindful of the certification deadline communicated to you.
If all required evidence is not received before the deadline, the assessment may be marked as failed and would need to be rebooked. You may also be required to re-take your Cyber Essentials.
Once the auditor is satisfied that all requirements have been met:
Your details will be uploaded to the IASME portal
Your Cyber Essentials Plus certificate will be issued
Once your certificate has been issued, your assessor will automatically remove Qualys from your devices and stop the automated reports.
Need Support?
If you have any questions at any stage of the process:
Ask your dedicated Audit Support Agent by responding within the initial email thread
Contact your Account Manager
Or reach out to our CX team via Live Chat
We are here to support you throughout your Cyber Essentials Plus journey.






