What tests are carried out in the Cyber Essentials Plus process?

There are 4 stages involved in achieving CE+ certification.

The first stage involves an external vulnerability scan which is conducted remotely and aims to detect any potential vulnerabilities present on external-facing devices (firewalls, routers, servers etc.).

As an added-value service, URM will often run the external scan ahead of the assessment date and provide feedback to its clients to ensure there will be no unforeseen outcomes during the assessment and enable any remediations to be made.

The second stage, which can also be carried out remotely, is the internal vulnerability scan. Here, a vulnerability scanner is connected to the internal network and searches for potential vulnerabilities in the system on sampled devices.

A ‘Malware delivered over email’ test represents the third stage. This test involves URM (or another assessor) sending 3 emails to the audited organisation that go through the same filter as everyday emails would.

The first email is an email with a link, the second email is an email with a notepad document. The goal here is to confirm that your organisation can receive attachments. The third email contains an EICAR file and is designed to test the response of computer antivirus (AV) programs.

The file has malicious signatures, but the file itself is not malicious. As such, it should get picked up by anti-malware without causing any damage to machines. This test is again conducted on the sampled devices.

The fourth and final stage is a ‘Malware delivered over web’ test. This test uses the link from the previous stage (first email) to open a page with multiple links and there is an attempt to try and download malicious files, macros and run remote scripts.

All of these attempts should get blocked either by the operating system or the anti-malware software. Again, this test is carried out on the sampled devices.

We have been a partner with URM Consulting for many years. They offer a great service and are a team of real experts in all things cyber security.
IT support company
Apply for Cyber Essentials certificationApply for Cyber Essentials Plus

Cyber Security Case Study: The Human and Organisational Cost of a Breach

Published on
21 Nov
2025

URM’s blog shares a Managing Director’s account of navigating & recovering from a major cyber attack, with a focus on the human impact of the breach.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
7/11/2025
Cyber Essentials Requirements Update

URM’s blog breaks down the latest changes to the Cyber Essentials requirements and outlines why these updates matter for organisations seeking certification.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
6/11/2025
Building Cyber Security Resilience Against Phishing

URM’s blog explores the different forms of phishing attacks, the strategies used to exploit human vulnerabilities, & how to protect against these attacks.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
31/10/2025
Deconstructing the EU Cyber Resilience Act

URM’s blog breaks down the new EU Cyber Resilience Act, what products/entities are in scope, the security requirements it imposes on organisations, and more.

Read more
"
I know many Cyber Essentials providers are rigid to the point of not understanding the goal of CE, but we haven’t found that with URM. We are extremely happy with the service we’ve received – our Cyber Essentials recertifications are always painless and straightforward. The different assessors we’ve had have all been great and pitch to the right level, as well as having an extremely strong knowledge of the subject matter. The account management side is also excellent. Our Account Manager checks in with us on a regular basis, and is very approachable and credible, with a comprehensive understanding of Cyber Essentials.
CISO at University of Surrey
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.