Reference guide · United Kingdom

Cyber Essentials and CE Plus: What Is Actually Assessed on Your External Footprint

By Nathan Hill-Haimes · Published 24 September 2026 Updated

Disclosure

This guide is published by SurfaceLoop, which sells an external attack surface monitoring product and therefore has a commercial interest in the subject. SurfaceLoop is not a Certification Body and cannot certify anyone. Every scheme detail below is stated with a link to the NCSC or IASME source it came from, verified in September 2026; where we could not verify a figure we have described the requirement qualitatively instead. This is a reference page, and the one section about our own product is labelled as such.

Who owns Cyber Essentials, and who assesses you?

Cyber Essentials is a UK government-backed certification scheme owned by the National Cyber Security Centre, which develops and publishes the requirements. Delivery is run by IASME, the NCSC's official Cyber Essentials Delivery Partner, which operates the assessment platform, issues the self-assessment question set, and licenses the network of Certification Bodies that mark assessments, carry out Cyber Essentials Plus audits and award certificates.

That split matters when you are reading advice about the scheme. The technical standard lives in the NCSC's Requirements for IT Infrastructure document -- version 3.3, dated April 2026, is the current one -- and the illustrative test procedure for the audited level lives in the NCSC's Cyber Essentials Plus Test Specification, currently version 3.2 of April 2025. Both are free to download from the NCSC resources page. Everything else -- the wording of the questions, the marking rules, the operational test script your assessor actually follows, the sampling method, the fees -- comes from IASME as Delivery Partner. If a supplier tells you something about the scheme that is not in one of those two NCSC documents or on IASME's site, ask where it came from.

The requirements are revised periodically and the question set is renamed with each revision. IASME has published that the current cycle, paired with Requirements v3.3, took effect on 27 April 2026 and uses the question set named Danzell, which replaced the previous Willow set. Two changes in that revision matter specifically to the external picture: cloud services that hold your data cannot be excluded from scope, and failing to enforce MFA on a cloud service that offers it is an automatic assessment failure. Before you rely on a version number or a date, check the NCSC resources page -- schemes move and this page states what was true in September 2026.

Which of the five control themes are visible from the internet?

The NCSC organises the requirements under five technical controls: Firewalls, Secure Configuration, Security Update Management, User Access Control and Malware Protection. The same five apply at both levels -- Cyber Essentials Plus does not add controls, it adds verification. What follows is an honest map of how much of each theme an outside observer can see, because that boundary is where most confusion about the scheme lives.

The five Cyber Essentials technical control themes and how much of each is observable from the public internet
Control theme Externally observable What the requirement says What an outside view shows What it cannot show
Firewalls Substantial The stated aim is to make sure that only secure and necessary network services can be accessed from the internet. Unauthenticated inbound connections must be blocked by default, inbound rules must be approved and documented with a business need, and access to a firewall's own administrative interface from the internet is only permitted with a clear documented business need plus MFA or a tightly scoped IP allow list. Every TCP and UDP service actually answering on your public addresses, which is the evidence of whether the rule set does what the questionnaire says it does. An administrative interface reachable from the internet is visible from the internet by definition. Whether a rule was approved, by whom, and whether the business need was written down. Software firewalls on laptops used on untrusted networks.
Secure Configuration Partial Default and guessable account passwords must be changed, unnecessary user accounts removed or disabled, and unnecessary software removed or disabled -- explicitly including network services. Services and management interfaces that are running but need not be. Login pages and panels that identify the product and often its version. Default credential pairs on appliances where the vendor default is publicly documented. Local account inventories, auto-run settings, device unlocking credentials, and everything on a device that does not present a listening service to the internet.
Security Update Management Partial, and only for internet-facing software All in-scope software must be licensed and supported, and updates that fix vulnerabilities the vendor calls critical or high risk -- or that carry a CVSS v3 base score of 7 or above, or come with no severity information at all -- must be applied within 14 days of release. Unsupported software must be removed, or removed from scope via a defined sub-set that prevents all traffic to or from the internet. Version information disclosed by internet-facing web servers, mail servers, VPN appliances, CMS platforms and remote-access services, and the known vulnerabilities associated with those versions. Patch level on laptops, servers with no internet-facing service, and anything behind the boundary. That is precisely what CE Plus covers with an authenticated scan instead.
User Access Control Narrow but real MFA must be implemented where available, and authentication to cloud services must always use MFA. Separate accounts must be used for administrative activities, and accounts removed when no longer required. Which cloud and remote-access services you use can often be inferred from DNS and certificate records, so an outside view can tell you where the MFA question will be asked. Whether a given internet-facing login enforces MFA usually cannot be determined without credentials. Account inventories, joiner and leaver process, privilege assignment, administrative account separation.
Malware Protection Essentially none In-scope devices must be protected by one of the scheme's approved malware protection mechanisms. Nothing meaningful. Endpoint protection has no signature that is observable from the public internet. All of it. This theme is evidenced internally and, at CE Plus, by the assessor sending test files to devices by email and through a browser.

Requirement wording above is summarised from the NCSC's Requirements for IT Infrastructure v3.3; read the document itself before you write a scope statement or answer a question on the platform. The practical reading of the table is that an external view is a strong proxy for one theme, a partial proxy for two, and no help at all for two. Any claim that a scan "covers Cyber Essentials" is wrong in both directions: it overstates what scanning reaches and understates how much of the scheme is about process and documentation.

That figure is a Firewalls-theme observation, not a verdict. Exposing a remote-access service to the internet is not automatically a certification failure -- the question is whether the service is necessary, whether the inbound rule was approved and documented with a business need, and whether the software behind it is supported and patched. But it is the sort of thing that is much easier to answer three weeks before an assessment than during one.

What does the self-assessment ask, and what does CE Plus add?

Cyber Essentials at the base level is a verified self-assessment. You register on IASME's assessment platform, agree a scope, answer the question set about how the five themes are implemented across that scope, and a qualified assessor at a Certification Body marks your answers. The controls are technical; the evidence, at this level, is your own declaration. A certificate is valid for twelve months.

Cyber Essentials Plus keeps the same questions and the same controls and then checks them. IASME states that an organisation can complete its Cyber Essentials Plus audit within three months of its last Cyber Essentials certification without repeating the self-assessment stage. Before testing starts, the assessor must hold written permission, confirm that the Plus scope matches the scope on the valid self-assessment certificate, verify by technical means that it matches the networks and systems actually present, and -- where the declared scope is not the whole organisation -- verify that the excluded sub-sets really are segregated. Then five test cases run.

The five Cyber Essentials Plus test cases in the NCSC Test Specification v3.2 and which surface each one examines
Test case Surface What the assessor does What preparation looks like
Remote vulnerability assessment External Identify all of the IP addresses currently in use by the applicant, including IaaS, then scan them on a recommended set of TCP and UDP ports with a tool the Delivery Partner has approved, and reach a pass or fail decision for each internet-accessible service discovered. This is the test you can rehearse yourself. Anything an outside scan finds on your public addresses, the assessor's scan will find too.
Check patching, by authenticated vulnerability scan of devices Internal Run an authenticated scan against sampled end-user devices, servers and IaaS instances, and fail the sub-test where a vulnerability meeting the scheme's critical or high-risk criteria has had a vendor fix available for more than 14 days. External scanning cannot substitute for this. It needs patch management on actual endpoints, evidenced on the devices chosen for the sample.
Check malware protection Internal Verify the malware protection mechanism on each sampled device, including sending test files to it by email and via a web browser from a site the Certification Body hosts. Confirm your mail filtering and browser policy will not block the assessor's test infrastructure outright, and that someone can allow-list it if asked.
Check multi-factor authentication configuration Cloud Observe real users and administrators signing in to each in-scope cloud service from an untrusted device or an incognito session, and confirm an MFA prompt appears before access is granted. Enumerate every cloud service that holds or processes your data, not just the obvious one, and check MFA is enforced rather than merely available.
Check account separation Internal Confirm that standard user accounts cannot perform administrative functions, across sampled devices, user-interactive servers and cloud environments where administrative processes can run. Separate day-to-day and administrative identities before the audit, not during it.

Three things about that table deserve emphasis. First, only one of the five test cases looks at you from the outside -- so external monitoring is a partial preparation, never a whole one. Second, the internal patching test is authenticated and runs against a sample of devices, which means it sees what an external scan structurally cannot: unpatched software on machines that expose nothing to the internet. Third, and most consequentially, the published specification is unambiguous that any single sub-test failure fails the parent test case and the overall assessment. There is no partial credit. Assessors are nonetheless expected to complete the full assessment so that you receive a complete appraisal, which is worth knowing -- a fail still comes with a usable list of what to fix.

On sampling, be careful with what you read elsewhere. The NCSC specification says the assessor must verify the sample size was calculated using the method described by the Delivery Partner, and that the sample must be genuinely representative of the devices in scope, with evidence of the calculation retained. It does not itself publish the arithmetic, so a specific devices-per-build formula quoted in a blog post is IASME's operational detail rather than the scheme's published standard -- confirm it with your Certification Body. All cloud services must be tested with at least one normal user and one administrative user each.

What counts as your external footprint for scope purposes?

Scope is the part of Cyber Essentials most often got wrong, and it is got wrong early -- in the scope statement, before any control is discussed. The requirements say the assessment should cover the whole of the IT infrastructure used to carry out your business, or if necessary a well-defined and separately managed sub-set, and that you must clearly define the boundary and agree it with your Certification Body before assessment begins. Where you exclude part of the organisation, you have to justify that partial scope to your assessor.

For the external half, three rules from the requirements do most of the work. Anything that can accept incoming network connections from internet-connected devices is in scope. Cloud services that store or process your organisational data must be in scope and cannot be excluded. And a scope that does not include end-user devices is not acceptable at all.

The external test is addressed by IP, not by asset list

This is the detail that catches people. The Cyber Essentials Plus remote vulnerability assessment begins by identifying all of the IP addresses currently in use by the applicant, explicitly including infrastructure-as-a-service, and scans them across a recommended set of TCP and UDP ports. It does not begin from the list of websites you think of as yours. Where dynamic addressing is in use for an internet connection, the specification allows scope to be defined in terms of appropriate DNS entries instead, and warns assessors to take care that carrier-grade NAT does not send assessment traffic to the wrong destination.

The consequence is that everything on an in-scope public address is examined, whether or not you remembered it. A staging host on a spare address, a legacy appliance on the office line, an IaaS instance somebody spun up for a project -- all of it answers the assessor's scan.

You cannot scope what you have not discovered

Which produces the circular problem at the heart of external scoping for small organisations. You are asked to define a boundary and then certify that controls hold across it, but defining the boundary accurately requires an inventory most SMEs do not have. The requirements document is direct about this without making it a control: asset management is not itself a Cyber Essentials control, but effective asset management helps meet all five and should be treated as a core security function.

Practically, build the external side of the inventory from sources that do not depend on anyone's memory: your registrar and DNS zones, certificate transparency logs, your cloud provider's assigned addresses, your ISP's allocations, and an asset discovery pass over your domains. Then reconcile that list against the scope you were about to declare. Discrepancies found at this stage are administrative. The same discrepancies found during a Plus audit are a scoping dispute with a certificate attached to it.

Sub-sets are a real option, and they are verified

A defined sub-set can legitimately narrow scope, and the requirements also allow unsupported software to be taken out of scope by placing it in a defined sub-set that prevents all traffic to or from the internet. This is a genuine route out of an awkward legacy system -- but it is not a paperwork exercise. At Plus, the assessor verifies by technical means that any sub-set excluded from a non-whole-organisation scope has been segregated effectively. Segregation you cannot demonstrate is segregation you do not have.

Which external findings cause trouble at assessment?

The external failures are boringly consistent, which is good news: a short list covers most of them. Each one below maps to a specific requirement rather than to general good practice, so the "why it causes trouble" column is about the scheme, not about our opinion of your estate.

Common externally visible findings, the Cyber Essentials theme each falls under, and why each causes problems at assessment
Finding Theme Why it causes trouble What to do about it
An unpatched internet-facing service Security Update Management A VPN appliance, mail server, CMS or web framework reachable from the internet, running a version with a known critical or high-risk vulnerability whose fix has been out for more than a fortnight. This is the single most direct way to fail the external test, because it is exactly the condition the test case is written to detect. Patch it, or take it off the internet. Appliances are the usual culprit because their updates are not covered by whatever patches your laptops.
Software the vendor no longer supports Security Update Management Unsupported software cannot be patched, so it cannot meet the requirement. The scheme does not accept a compensating control indefinitely: unsupported software has to be removed, or placed in a defined sub-set with no internet traffic in either direction, which the assessor then verifies by technical means. Inventory end-of-life dates before you scope, not after. An old PHP or Windows Server version on a public host is a certification problem, not a housekeeping one.
Default or guessable credentials on an exposed device Secure Configuration and Firewalls Vendor defaults for routers, NAS boxes, cameras, printers and building systems are published. If the device answers from the internet and still holds its factory password, the finding is trivially reproducible by an assessor and by anyone else. Change the credential and then ask the harder question: why is the interface reachable at all?
An exposed administrative interface Firewalls and Secure Configuration Firewall, router and hypervisor management panels, database consoles, CMS and webmail admin paths. For firewall administrative interfaces specifically, internet access is only acceptable with a clear and documented business need plus MFA or a narrow IP allow list -- so an exposed panel with neither is a direct requirement gap, and one with both still needs the paperwork to exist. Restrict to a VPN or an allow list, enforce MFA, and write down the business need for anything that has to stay reachable.
A service nobody knew was listening Firewalls Remote desktop, SSH, database ports, management protocols and test environments left reachable by a rule that was added for a weekend. The control's aim is that only secure and necessary services are accessible from the internet, and 'we did not know it was open' is not a business need. Scan your own public addresses and reconcile the result against your firewall rules. Remove rules that are no longer needed.
MFA missing on a cloud service User Access Control Authentication to cloud services must always use MFA where the service offers it, and from the April 2026 requirements update IASME has said that failure to implement MFA on cloud services means automatically failing the assessment. At CE Plus, an assessor watches a real sign-in, so 'MFA is available and we encourage it' does not survive the test. Enforce it tenant-wide, including administrators, service desk accounts and any third-party support access -- and check the services nobody thinks of as cloud services.
Assets outside the scope you declared Scope A forgotten subdomain, an old marketing microsite, a supplier-built staging host on your domain. Scope must be agreed with the Certification Body before assessment, and at CE Plus the assessor verifies by technical means that the declared scope matches the systems actually there. A discovery gap becomes a scoping dispute at the worst possible moment. Build the asset list from DNS, certificate transparency logs and your registrar before you write the scope statement, not from memory.

The theme in the second column is our reading of which requirement a finding bears on, not a quotation from the scheme documents. Where a finding sits on the line -- an exposed interface that does have MFA and a documented business need, say -- your Certification Body's view is the one that counts, and asking before the audit is free.

That cohort was not made up of organisations preparing for certification, so read the number as a base rate for UK small business estates rather than a failure rate for Cyber Essentials. It is still the reason the exposed panel and unpatched service categories dominate this list: in a typical estate they are what is actually there.

What should you check before you submit or book the audit?

This covers the external half only. Work through it before you write the scope statement, not after, and keep the output -- most of it is the evidence you will want if a question is queried.

  1. Build the public address and asset list from records, not memory. Registrar and DNS zones, certificate transparency logs, cloud provider address assignments, ISP allocations, and a discovery pass over every domain you own. Include IaaS. Date the list.
  2. Scan your own public addresses across a broad TCP and UDP port range. The assessor's remote vulnerability assessment works this way, so replicate it. Reconcile every service that answers against your firewall rule set.
  3. Justify or close every open service. For each one, write down the business need and who approved it. Remove the rules you cannot justify. The requirement is that only secure and necessary services are reachable, and the documentation is part of the requirement, not an optional extra.
  4. Hunt administrative interfaces specifically. Firewall, router, hypervisor, NAS, database, CMS and webmail management paths. Anything that must stay reachable needs a documented business need plus MFA or a narrow IP allow list; the rest belongs behind a VPN.
  5. Check versions and support status on every internet-facing service. Confirm each product is licensed and still supported by its vendor, note the vendor's end-of-support date, and confirm nothing critical or high risk has had a fix available for more than fourteen days. Appliances and third-party-managed hosts are the usual blind spots.
  6. Change every default credential on anything exposed, then ask why it is exposed. Both halves matter. A changed password on an interface that should not be public is a half-finished job.
  7. Enumerate cloud services and enforce MFA on all of them. Every service that stores or processes your data, including ones nobody thinks of as cloud services, and including administrator, service-desk and third-party support accounts. At Plus an assessor watches a real sign-in, and under the April 2026 requirements update a missing cloud MFA enforcement is an automatic failure.
  8. Decide your scope and prove any sub-set boundary. Whole organisation is simplest and gives the best assurance. If you are excluding a sub-set, be able to demonstrate the segregation technically, because that is how it will be checked.
  9. Re-scan after remediation, and keep both reports. A dated before-and-after pair is the cleanest evidence that a change was made and took effect, and it is useful well beyond this assessment -- insurers and clients ask for the same thing.
  10. Ask your Certification Body the judgement calls in advance. Borderline services, unusual architectures, sub-set boundaries, legacy systems. They mark the assessment; a five-minute conversation now is worth more than a confident guess.

Then stop. The rest of the scheme -- account inventories, joiner and leaver process, administrative account separation, endpoint patching, malware protection -- is internal work that no external view reaches, and it is the majority of the remaining effort.

How does continuous external monitoring help before assessment?

About our product
This section is about SurfaceLoop, so treat it as what it is. Everything above applies whatever tooling you use, including none.

The generic case for continuous external monitoring in a certification context is narrow and honest: it automates steps one, two, five and nine of the checklist above, and it keeps doing them after you certify. Certification is a point-in-time judgement with a twelve-month validity, while the external surface changes whenever someone publishes a subdomain, renews a certificate, opens a firewall rule or stands up an instance. Monitoring is how the posture you certified stays true in month seven.

It does not help with the other four Cyber Essentials Plus test cases, it cannot see endpoint patch levels, it cannot tell you whether MFA is enforced on a service it has no credentials for, and it cannot write your scope statement. Any vendor implying otherwise is selling past the evidence. The realistic claim is that it removes the class of surprise that arrives from outside, which happens to be the class that an assessor tests first.

SurfaceLoop is one option in that category, aimed at UK SMEs and the MSPs who prepare them: it discovers internet-facing assets, scans them continuously, writes findings in plain English with the remediation attached, and exports dated reports you can keep as evidence. Our Cyber Essentials preparation page sets out what it does and does not cover control by control, and the EASM buyer's guide gives you a vendor-neutral rubric to score us and everyone else against. If you would rather just look at your own estate, the trial runs on your own domains. Alternatively, run a port scan of your public addresses yourself with free tooling, which is genuinely better than doing nothing and costs a morning.

What can an external view never tell you about Cyber Essentials?

Worth stating plainly, because the honest limits are what make the rest of the guide usable. From outside your perimeter, nothing can establish: whether your firewall rules were approved and documented by an authorised person with the business need recorded; whether unnecessary local accounts have been removed; whether laptops and non-internet-facing servers are patched inside the fourteen-day window; whether malware protection is present and working; whether administrators use separate accounts; whether leavers have been offboarded; or whether MFA is actually enforced rather than merely offered on a service the observer cannot log in to.

Nor can any scan, report or subscription certify you. Certification comes from a Certification Body licensed by IASME, and the assessment is of your controls, not of a vendor's output. An external report is useful preparation and useful evidence of remediation. It is not a pre-assessment, a pass, or a substitute for reading the requirements document -- which is short, free, and the only authoritative statement of what you are being asked to do.

For the adjacent question of how to choose external monitoring tooling at all, including what to ask vendors and how the pricing models differ, see the UK EASM buyer's guide. For definitions of the individual terms used here, see the glossary.

Questions, answered

Something else? Email hello@surfaceloop.com and a person replies.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment questionnaire covering five technical control themes, submitted on the scheme's assessment platform and marked by a qualified assessor at a Certification Body. Cyber Essentials Plus assesses the same five themes but adds independent technical verification: the assessor tests a representative sample of devices, runs an authenticated vulnerability scan against them, performs an external vulnerability scan against the organisation's public IP addresses, watches real users sign in to cloud services to confirm MFA, and checks account separation. The controls do not change between the two levels; the evidence standard does.

Does Cyber Essentials Plus include an external vulnerability scan?

Yes. The NCSC's published Cyber Essentials Plus Test Specification opens with a remote vulnerability assessment whose purpose is to test whether an internet-based opportunist attacker could get in using typical low-skill methods. The assessor identifies all IP addresses currently in use by the applicant, including infrastructure-as-a-service, and scans them on a recommended set of TCP and UDP ports using a tool the scheme's Delivery Partner has approved. Each internet-accessible service discovered is then passed or failed individually.

What is in scope for the external part of Cyber Essentials?

Scope should cover the whole of the IT infrastructure used to run the organisation, or a well-defined and separately managed sub-set, and it must be agreed with the Certification Body before assessment begins. For the external side, that means every internet-facing service on every public IP address you use -- including cloud-hosted infrastructure you run yourself. Cloud services that store or process your data cannot be excluded from scope at all, and a scope that leaves out end-user devices is not acceptable. Where dynamic addressing is in use, the published specification allows scope to be defined in terms of appropriate DNS entries instead.

Which Cyber Essentials controls can an external scan actually evidence?

Three of the five themes have externally observable components. Firewalls is the strongest fit: an external port scan shows which services are genuinely reachable, which is the direct evidence of whether the boundary configuration matches what was declared. Secure Configuration is partly visible through exposed management interfaces, unnecessary services and default credentials on internet-facing devices. Security Update Management is visible only for software that faces the internet. User Access Control is barely visible from outside, and Malware Protection is not visible at all.

Can external scanning fail you at Cyber Essentials Plus on its own?

Yes. Under the published test specification, a single sub-test failure makes the parent test case a fail and the overall assessment a fail. The remote vulnerability assessment passes only if every internet-accessible service tested passes. One unpatched public-facing appliance is therefore enough to stop the certificate, which is why running your own external scan weeks before the audit is worth more than any other single piece of preparation.

How long after Cyber Essentials can you do Cyber Essentials Plus?

IASME states that an organisation can complete its Cyber Essentials Plus audit within three months of its last Cyber Essentials certification, and that certifying to Plus within that window means the self-assessment question stage does not have to be repeated. Leave it longer and you go through the questionnaire again. Certification itself is valid for twelve months, so both levels are annual exercises rather than one-off projects.

Is external monitoring required for Cyber Essentials?

No. The scheme sets requirements for controls, not for tools, and nothing in the requirements document obliges you to buy continuous external monitoring. What the scheme does require is that only secure and necessary services are reachable from the internet, that internet-facing software is supported and patched inside the stated window, and at Plus that an assessor's own external scan finds nothing that fails. Knowing your external footprint is therefore a practical necessity even though no specific product is mandated.

Who issues Cyber Essentials certificates?

Certificates are issued through Certification Bodies licensed by IASME, which is the NCSC's official Cyber Essentials Delivery Partner. The NCSC owns the scheme and publishes the requirements; IASME runs delivery, the assessment platform, the question set and the network of Certification Bodies that assess and certify. No software vendor, consultancy or managed service provider can certify you unless it is itself a licensed Certification Body.

Published 24 September 2026 · Last updated 24 September 2026 · Written by Nathan Hill-Haimes, co-founder of AMVIA and SurfaceLoop. Scheme details are taken from the NCSC's Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026) and Cyber Essentials Plus Test Specification v3.2 (April 2025), and from IASME's published guidance on the difference between the two levels and the April 2026 scheme changes, all verified in September 2026. The scheme is revised periodically -- check ncsc.gov.uk and iasme.co.uk for the current documents before relying on a version number or a date. No fee figures are quoted here because fees are set by IASME and Certification Bodies and change; ask for a quote. First-party statistics are drawn from the UK SME External Exposure Snapshot, September 2026, whose methodology is public. Nothing here is legal or certification advice. This guide may be quoted with attribution to SurfaceLoop.