Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

The audit itself

Which of your devices actually gets tested

Plus is a sampled audit, not an audit of everything. Understanding how the sample is drawn tells you what you actually need to have in order.

Cyber Essentials Plus › How the sample is chosen

People preparing for a Cyber Essentials Plus audit often assume one of two things: that every device gets tested, which would be impractical, or that they can present a handful of well-maintained machines, which would make the audit meaningless.

Neither is right. The audit works on a sample, and the way that sample is drawn is the thing worth understanding.

The sample comes from the whole scope

The assessor works from your device inventory, covering everything within the certified scope, and selects from it. You supply the list; you do not select from it.

This is why the inventory is the first thing that matters. An incomplete list is not a shortcut, because the audit tests whether the list is complete as much as whether the devices comply. An assessor who finds a device type in use that does not appear on the inventory has found a more serious problem than an unpatched laptop.

How the sample size works

The sample scales with the size and variety of the estate rather than being a fixed number or a flat percentage. The driver is variety, not headcount.

An organisation with two hundred identically built Windows laptops has one device type and the sample reflects that. An organisation with forty devices across Windows, macOS, iOS, Android, two different build images and a group of bring-your-own-device users has six or seven distinct populations, and the sample has to cover each.

The practical consequence: reducing variety reduces the audit surface. An estate standardised on one build is easier to pass than a smaller estate with six.

What determines the populations

Each of these creates a separate group to sample from
DimensionWhy it splits the sample
Operating system and major versionWindows 11 and Windows 10 are different populations, and so are macOS and Windows.
Device typeLaptops, desktops, servers in scope, mobile devices and tablets.
Build or imageA standard corporate build and a differently configured one are separate, even on the same OS.
Managed versus unmanagedA centrally managed device and a bring-your-own device are not equivalent.
Location or business unitWhere configuration genuinely differs between sites.
User roleWhere privilege or software load differs materially, for example developer machines.

What gets done to the sampled devices

Each sampled device goes through the same checks: an authenticated vulnerability scan looking for missing high and critical patches and unsupported software, a malware protection test, a test of whether malicious files can be downloaded through the browser, a check that everyday accounts do not hold local administrator rights, and confirmation that the account separation and configuration requirements hold in practice rather than in policy.

The scan being authenticated matters. An unauthenticated scan sees what is exposed. An authenticated scan sees what is installed, which is where unsupported software and missing patches actually show up.

Cloud services are sampled too

Not only devices. The assessor checks multi-factor authentication across the cloud services in scope, and this is sampled from the list you provide. The same principle applies: an incomplete list of cloud services is a worse finding than a service with a gap, because it calls the whole submission into question.

Inventory every cloud service in use before the audit, including the ones a single department adopted without telling anybody.

What you can and cannot influence

You cannot choose which devices are tested, exclude a device because it is awkward, or fix a device after it has been selected but before it is tested.

You can reduce the number of distinct populations by standardising builds, ensure the inventory is genuinely complete, make sure every device is actually receiving the policies you think it is, and remove unsupported software before the audit rather than during it.

That last one is worth repeating. The commonest cause of a failed Plus audit is a sampled device running something the vendor no longer supports, on an estate where somebody would have said confidently that everything was current.

Preparing the inventory properly

Two weeks before the audit, produce a list with: every device in scope, its operating system and version, its build or image, whether it is managed, who uses it, and its location. Reconcile that list against what your management tooling actually reports, not against what you believe.

The reconciliation is the useful part. Devices that exist but never enrolled, devices that enrolled and stopped reporting, and devices nobody remembers issuing are all common, and all of them are in scope.

Reducing your audit surface on purpose

Because the sample scales with variety rather than headcount, the amount of work an audit represents is something you can influence in the months beforehand. Four levers, roughly in order of effect.

Standardise the build. Two build images instead of five halves the populations to sample. This is the single largest lever and also the slowest, which is why it belongs in a twelve-month plan rather than a two-week one.

Retire the odd operating system. The three Macs in the design team are a separate population requiring separate evidence. That may be entirely justified, but it is worth knowing it is a cost rather than assuming it is free.

Bring unmanaged devices into management. An unmanaged device is its own population and the hardest to evidence. Every device you enrol reduces both the sample complexity and the risk of a surprise.

Decide about personal devices deliberately. Bring-your-own-device creates a population you do not control. Either manage them properly or restrict organisational data to managed devices. Permitting them and hoping is the position that fails.

What not to do

Do not shrink the scope to shrink the sample. It works, and it produces a certificate whose scope statement a buyer reads and discounts. The certificate is only worth what it covers, and a Plus certificate covering a third of your estate is a harder conversation with a client than no Plus certificate at all.

Do not leave devices off the inventory. The audit tests whether the inventory is complete as much as whether the devices comply, and a device type in use that does not appear on the list is a more serious finding than an unpatched laptop.

A note on new devices

Machines issued in the fortnight before an audit are a recurring cause of avoidable failure. They are in scope, they are often not yet fully enrolled, and they frequently have a locally created account with administrator rights from the setup process.

Either get them fully into management before the audit window, or do not issue them until afterwards. Nothing about a new laptop has to happen in that particular fortnight.

How many devices will be tested?

It depends on the size of the estate and, more importantly, on how many distinct device populations it contains. A standardised estate of two hundred identical laptops has a smaller effective sample than a varied estate of forty.

Can we choose which devices you test?

No. You supply the complete inventory and the assessor selects from it. Being able to nominate the sample would make the audit meaningless, which is precisely why it is not permitted.

What if a device fails?

You get a written account of what failed and a period to fix it and be retested, rather than an outright refusal. Most failures are patch levels, unsupported software or an MFA gap, and most are fixable in days.

Do servers get tested?

Servers within the certified scope can be sampled, yes. The requirements apply somewhat differently to a server with no user browsing from it, but it is not automatically out of scope.

Audit slots from late October 2026

Cyber Essentials is the prerequisite and has to be under three months old when the Plus audit starts, so that is the step to take now.