What tests are carried out in the Cyber Essentials Plus process?

There are 4 stages involved in achieving CE+ certification.

The first stage involves an external vulnerability scan which is conducted remotely and aims to detect any potential vulnerabilities present on external-facing devices (firewalls, routers, servers etc.).

As an added-value service, URM will often run the external scan ahead of the assessment date and provide feedback to its clients to ensure there will be no unforeseen outcomes during the assessment and enable any remediations to be made.

The second stage, which can also be carried out remotely, is the internal vulnerability scan. Here, a vulnerability scanner is connected to the internal network and searches for potential vulnerabilities in the system on sampled devices.

A ‘Malware delivered over email’ test represents the third stage. This test involves URM (or another assessor) sending 3 emails to the audited organisation that go through the same filter as everyday emails would.

The first email is an email with a link, the second email is an email with a notepad document. The goal here is to confirm that your organisation can receive attachments. The third email contains an EICAR file and is designed to test the response of computer antivirus (AV) programs.

The file has malicious signatures, but the file itself is not malicious. As such, it should get picked up by anti-malware without causing any damage to machines. This test is again conducted on the sampled devices.

The fourth and final stage is a ‘Malware delivered over web’ test. This test uses the link from the previous stage (first email) to open a page with multiple links and there is an attempt to try and download malicious files, macros and run remote scripts.

All of these attempts should get blocked either by the operating system or the anti-malware software. Again, this test is carried out on the sampled devices.

URM consulting were fantastic to work with. Their expert support and friendly efficiency made achieving our Cyber Essentials Plus accreditation smooth and stress-free. It's reassuring to know that we have a reliable local consultancy that we can count on for ongoing support.
Technology consultancy
Apply for Cyber Essentials certificationApply for Cyber Essentials Plus

Cyber Essentials Questions Answered: Technical Requirements, BYOD Compliance and the Future of the Scheme

Published on
5 Jun
2026

URM’s blog answers key questions about CE, focusing specifically on its technical requirements, use of BYOD, and how the scheme may change in the future.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
5/6/2026
Complying with Cyber Essentials and Cyber Essentials Plus

URM’s blog answers key technical questions about Cyber Essentials and Cyber Essentials Plus, what’s in scope, CE compliant use of BYOD, and more.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
5/6/2026
Cyber Essentials – What’s Changing in 2025?

URM’s blog discusses upcoming changes to Cyber Essentials, including the changes seen in the Willow Question Set and how they may impact your organisation.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
5/6/2026
Access Control, Administrative Accounts and Password-Based Authentication in the Cyber Essentials SAQ

URM’s blog offers advice on answering questions in the Cyber Essentials SAQ which relate to access control, admin accounts and authentication methods.

Read more
"
Our assessor was brilliant! He was incredibly supportive and knowledgeable and really helped us get through CE+. It was a pleasure working with him.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.