Cyber Essentials Plus Device Sampling: What Assessors Choose

Cyber Essentials Plus is a sampled audit rather than a full inspection. The assessor selects devices representing each operating system and build in your estate, tests those, and certifies on the basis of what they find. That makes the sample the whole assessment, and it explains why organisations who prepare only the machines they expect to be chosen tend to fail.
How the sample is put together
Assessors work from your device list and pick across platforms rather than at random. Each operating system in use needs representation, so a mixed estate of Windows laptops, Macs, Android and iOS phones produces a broader sample than a uniform one. The size scales with the estate, and remote workers are included since their devices are in scope wherever they sit. Bring your own device is in scope too when those devices access organisational data, which surprises organisations that assumed personal phones were outside the boundary of the assessment entirely.
What gets tested on each device
Four things, and each has a clear pass or fail. Patch status is checked with an authenticated vulnerability scan, and anything scoring 7.0 or above on the CVSS scale that has been available for more than fourteen days is a failure under the NCSC and IASME requirements. Malware protection is tested by sending known test files by email and downloading them through the browser. Account separation is checked to confirm ordinary users do not hold administrative rights. Finally, multi-factor authentication is verified on the cloud services in scope.
“The failures I see are almost never the operating system. They are the third-party applications: a browser two versions behind, a PDF reader nobody updates, a video conferencing client that has not restarted in months. Run an authenticated scan across your whole estate a month before the audit and fix what it finds, because that scan is essentially the one the assessor will run.”
William Fieldhouse, Director, Aardwolf Security Ltd

The cloud services that come with it
Cloud services are in scope where they hold organisational data, which for most businesses means email, file storage and any line-of-business platform. The assessor checks that multi-factor authentication is enabled and enforced, particularly for administrative accounts. This is where organisations discover an old service with local accounts and no second factor, or an administrator excluded from a policy years ago for convenience. Enumerate every cloud service before the audit rather than during it, because the list is always longer than the one in your head. Finance and marketing tools are the ones most often forgotten.
Preparing so the sample does not matter
Treat the whole estate as if it will be selected, which is the only reliable strategy. Run vulnerability scanning and remediation across every device a month ahead, resolve the third-party application backlog, confirm nobody has local administrator rights they should not, and check multi-factor coverage service by service. Working withan accredited testing and certification partner who can run the pre-assessment scan gives you the same picture the assessor will see, in time to act on it rather than to explain it.
Frequently asked questions about Cyber Essentials Plus sampling
These questions come up whenever an organisation books its first Plus assessment.
Can you choose which devices are tested?
No. The assessor selects the sample, and attempting to steer it is a good way to fail the audit. You supply an accurate device list and they choose from it.
What happens if one device fails?
Typically you get a short window to fix the issue and have it re-verified, though the specifics depend on the certification body and the nature of the failure. A systemic problem across the sample usually means a fresh assessment.


