Why self-assessment fails the Cyber Essentials Plus test
Cyber Essentials is a self-assessment. Cyber Essentials Plus adds an independent technical test. Here is exactly where self-assessed applications fall apart on audit day, and how to pass first time.
Cyber Essentials and Cyber Essentials Plus are not the same thing, and the difference is where most businesses come unstuck. Cyber Essentials is a self-assessment questionnaire. You answer the questions about your own systems, sign a declaration, and a certification body issues the certificate. Cyber Essentials Plus keeps the questionnaire but adds an independent technical test, a qualified assessor comes to your environment (or tests it remotely) and checks that what you said on the form is actually true.
That extra step is the whole point. A self-assessment is your own word for it. The Plus test is someone else verifying it. If you have only ever done the self-assessment, you have never actually been tested.
Where self-assessed applications fall apart
When an independent assessor runs the technical test, they are not looking for a reason to pass you. They are looking for the one thing that proves your self-assessment was not accurate. It rarely takes long to find. These are the failures we see again and again.
- One unpatched device. A laptop, a server, or a network switch that missed a patch cycle is enough to fail, even if everything else is fully up to date.
- One unapproved administrator account. A local admin account nobody documented, or a shared account with no named owner, breaks the user access control requirement.
- A firewall rule that does not match the questionnaire. If your form says a port is closed but the assessor can reach it, the self-assessment is wrong and the certificate is refused.
- Malware protection that is installed but not actually running. The software shows in your inventory, but real-time protection is disabled on a handful of machines.
- A device that was in scope but was not tested. Forgetting to include a branch office or a remote worker's laptop in the assessment scope is an automatic fail.
The pattern is always the same
It is almost never a fundamental security failure. It is one small thing that drifted out of compliance between filling in the form and the assessor arriving. Self-assessment has no mechanism to catch that drift.
Why a one-off scan before the audit is not enough
Some IT providers run a single vulnerability scan a few days before the certification body is due, fix what it finds, and call the business ready. The problem is timing. A scan on Monday tells you what your environment looked like on Monday. It tells you nothing about the patch that fails to install on Wednesday, the new device added on Thursday, or the firewall change a contractor makes on Friday. By the time the assessor tests you the following week, the picture has moved.
This is why Freshcyber runs continuous vulnerability scanning year-round on the Managed Cyber Essentials Plus package, using industry-standard vulnerability management tooling. We are not waiting for audit day to find out where you stand. We know where you stand every month, which means nothing drifts out of compliance between audits and renewal is never a last-minute scramble.
How to pass first time
The businesses that pass Cyber Essentials Plus first time do one thing differently. They treat the independent test as the real assessment, not the self-assessment. That means running the same kind of technical checks the assessor will run, before the assessor runs them.
- Run a pre-audit technical assessment across every device in scope, not just the obvious ones. Include remote workers and branch sites.
- Check all five technical controls, not just the ones you are confident about. Firewalls, secure configuration, security update management, user access control, and malware protection each get tested.
- Document every administrator account and every firewall rule, then verify the documentation matches reality. The assessor will.
- Fix what you find, then retest to prove the fix held. A finding that comes back after remediation is the same as never fixing it.
100% pass rate, and why
Every Cyber Essentials and CE+ engagement Freshcyber has delivered has passed first time. The reason is simple. We pre-audit before the independent assessor arrives, so there are no audit-day surprises. By the time the real test happens, we have already run it.
If a tender names Cyber Essentials, check the wording
One last thing that catches businesses out. If a tender or framework simply says Cyber Essentials, do not assume the self-assessment will do. Most NHS and public sector frameworks mean Cyber Essentials Plus specifically, even when the shorthand reads differently. Check the wording, and if you are unsure, a fifteen-minute scoping call will confirm which one actually applies to your contract.
Either way, the Managed Cyber Essentials Plus package always delivers the fully verified CE+ certificate, never just your own word for it. That is the version procurement teams and insurers actually want to see.
Written by
Gary Sinnott
Founder & IT Business Consultant
Freshcyber helps UK regulated SMEs achieve and maintain Cyber Essentials Plus, with a 100% pass rate across every engagement delivered.
Keep reading
Penetration testing vs vulnerability management: what is the difference?
A one-off penetration test and continuous vulnerability management solve different problems. Here is which one your business actually needs, and why the best programmes use both.
ReadHow Cyber Essentials Plus requirements appear in tenders
CE+ is no longer a nice-to-have. NHS Supply Chain, MOD frameworks, and corporate supply chains now name it as a qualifying requirement. Here is how it shows up, and what to do before the deadline bites.
Read