Buyer guide
Cyber Essentials Plus audit preparation checklist
Cyber Essentials Plus independently tests the implementation of the same five technical controls used in Cyber Essentials. Preparation should therefore focus on evidence that the controls are operating consistently across the agreed scope.
Before booking the audit
- Confirm the systems, cloud services, locations and users in scope.
- Identify unsupported operating systems or applications and address them appropriately.
- Check firewall and network-device configuration.
- Review user and administrator privileges.
- Confirm multi-factor authentication where current requirements call for it.
- Verify security updates are being deployed within the scheme requirements.
- Confirm malware protection or approved alternative controls are operating.
Do not optimise only for the test day
The strongest preparation is operational: know who owns patching, account management, device inventories and cloud configuration. Use the current NCSC Requirements for IT Infrastructure rather than an old checklist copied from a blog.
Official references: NCSC Cyber Essentials overview and NCSC requirements/resources.