Cyber Essentials Plus › Why Plus fails
Cyber Essentials is a self-assessment that we verify. Cyber Essentials Plus is a hands-on audit of the same five controls. The difference is not rigour for its own sake, it is that one tests what you say and the other tests what is true.
Most of the time those match. Where they do not, it is for reasons that are entirely predictable, and knowing them is most of the preparation.
1. The answer was true for the estate you think you have
"All devices receive security updates within fourteen days" is answered from the policy and from the management console, both of which describe devices that are enrolled and reporting. The Plus audit samples from the whole inventory, including the machine that never enrolled properly and the one that stopped checking in four months ago.
The answer was not dishonest. It was true of the managed estate and the managed estate is smaller than the actual estate. That gap is the single largest source of Plus failures.
2. Nobody searched for unsupported software
"All software is supported and receiving security updates" gets answered from general confidence. An authenticated vulnerability scan answers it from the software inventory, and finds the old Java runtime, the browser that has not updated since somebody disabled the updater, the Windows feature version past its servicing date, and the Android phone that stopped getting OS updates in 2024.
Unsupported software is an automatic fail. It is also the finding most likely to need a project rather than an afternoon, which is why finding it two weeks before the audit is materially better than finding it on the day.
3. Local administrator rights, in practice
"Users do not use administrative accounts for day-to-day work" is answered from policy. The audit checks the actual membership of the local administrators group on sampled devices.
The gap is usually created by remote support: somebody was elevated during a screen share to install something, and the elevation was never removed. On an estate of any size, expect to find several.
4. Malware protection is on, except where it is not
The self-assessment asks whether malware protection is in place. The audit tries to download a suspicious file through the browser on a specific machine.
Estates fail this because of exclusions and disabled protection on individual devices, both of which are invisible at policy level and obvious at device level. A broad folder exclusion added to stop a line-of-business application being flagged makes everything in that path unprotected, and nobody revisits it.
5. The cloud service nobody listed
Multi-factor authentication is required on every cloud service for every user. The self-assessment is answered against the services you remembered. The audit samples from the list you provide, and the failure is usually the service that was never on the list at all.
Build that list from evidence rather than memory: enterprise applications in your identity provider, software subscriptions in your expense records, and a direct question to each department head.
What this means for preparation
| Do this | Rather than this |
|---|---|
| Reconcile your device inventory against what management tooling actually reports | Trusting the compliance dashboard |
| Pull a software inventory and search for unsupported versions, mobile included | Assuming everything is current |
| Audit local administrator group membership across the estate | Reading the policy |
| Review malware protection exclusions and per-device status | Confirming the product is deployed |
| Build the cloud service list from evidence | Listing the services you can think of |
The useful reframe
A Plus failure is not an embarrassment, it is the audit doing its job. Every one of the five above represents a real gap between what you believed about your estate and what was true of it, and that gap existed whether or not anybody tested for it.
The organisations that find Plus straightforward are not the ones with the best documentation. They are the ones whose management tooling genuinely reaches every device, which is a different and more useful property.
And the sequencing point
Plus requires a valid Cyber Essentials certificate less than three months old when the audit begins. Doing the self-assessment properly rather than optimistically is therefore the first piece of Plus preparation, because an answer given generously at Cyber Essentials becomes a finding at Plus.
What happens if you have already failed
A Plus failure is not the end of the process and it is not unusual. What follows is a defined route rather than starting again.
You receive a written account of what did not meet the standard and why, specific enough to act on. You then have a period in which to remediate and be retested rather than resubmitting from scratch. The Cyber Essentials certificate is unaffected and remains valid.
Three things decide whether the retest goes well.
Fix the class of problem, not the instance. If a sampled laptop had an unsupported browser, the question is not whether that laptop is now fixed. It is how many others have the same issue, and why your process allowed it. The retest may sample different devices, and fixing only the one that was caught is how organisations fail twice.
Find out why it was missed. Almost every failure traces back to a reporting gap rather than a control gap: a device outside management, an exclusion nobody reviewed, a cloud service nobody listed. Closing the reporting gap prevents the next one; closing the individual finding does not.
Do not rush the retest. Booking it before remediation is genuinely complete produces a second failure, which costs more time than waiting a week would have.
If the deadline has now gone
If the Plus certificate was for a contract date that has now passed, tell the client before they ask. An honest message saying the audit identified specific issues, they are being remediated, and the retest is booked for a stated date is a conversation most buyers handle reasonably. Silence followed by a discovery is not.
Some buyers accept an attestation from the certification body confirming that an audit has taken place and remediation is underway. It is worth asking whether that would satisfy the requirement in the interim.
The reframe worth holding on to
Every Plus failure represents a real gap between what an organisation believed about its estate and what was true of it. That gap existed before the audit and would have existed afterwards if nobody had looked. Finding it in an audit, with a defined remediation route and no attacker involved, is the cheapest way it was ever going to be found.
If we passed Cyber Essentials, why would we fail Plus?
Because the self-assessment tests your answers and the audit tests your estate. The five gaps above are where those differ, and all five are things that were true before anybody tested for them.
Does failing Plus invalidate our Cyber Essentials certificate?
No. The Cyber Essentials certificate stands. A Plus failure means the Plus certificate is not issued yet, and you get an account of what failed and a period to fix it and be retested.
How far in advance should we prepare?
Two weeks of checking and remediation if nothing major surfaces. If unsupported software turns up that needs replacing rather than upgrading, that is a project, and the sensible move is to move the audit rather than hope.
Is a gap analysis worth it before the audit?
If any of the five above sound plausible for your estate, yes. It is cheaper to find an unsupported server in a review than in an audit, and the review does not have a date attached to it that you have promised a client.
Audit slots from late October 2026
Get the Cyber Essentials done now, run the checks above in the meantime, and go into the audit knowing what it will find.