By EJN Labs · 24 Jun 2026 · 8 min read
The most common Cyber Essentials Plus failures are missing security patches on devices or browsers, unsupported operating systems, accounts without multi-factor authentication, weak or default account configurations, and devices that the assessor cannot reach during the audit. Nearly all are fixable before your assessment if you scan your estate early.
Understanding the most frequent Cyber Essentials Plus common failures before your audit day is the single biggest factor in passing first time. The Plus tier adds a hands-on technical audit on top of the self-assessment, so the assessor verifies your controls rather than trusting your answers. This guide walks through the failures our assessors see repeatedly in UK SME estates, why each one trips the audit, and how to clear it before the clock starts.
Why Cyber Essentials Plus catches more organisations out
Cyber Essentials Plus catches more organisations out because it adds an independent assessor to the self-assessment questionnaire. The assessor tests a representative sample of your devices, validates your patching, checks account security and runs an authenticated vulnerability scan, so weaknesses a signed questionnaire would never expose come to light.
Cyber Essentials self-assessment is a questionnaire signed off by your leadership, while Plus keeps the same five control themes and adds the technical audit. Because the standard is governed by IASME, the technical bar does not move between assessors, so the failures are predictable and, almost always, preventable.
The trap is timing. Many organisations book the Plus audit a few days after passing the self-assessment, assuming the work is done. In reality the audit surfaces real-world gaps the questionnaire never asked about: a laptop that missed last month’s patch cycle, a shared admin login, or a phone that nobody remembered was in scope. Scanning your estate two to three weeks ahead gives you room to remediate rather than discovering problems on audit day.
Missing or late security patches
Patching is the most common single cause of a Cyber Essentials Plus failure. The Cyber Essentials Requirements for IT Infrastructure require high-risk and critical vulnerabilities with a CVSS v3 base score of 7.0 or above to be patched within 14 days of a fix being released by the vendor. The assessor runs an authenticated scan and any in-scope, internet-facing or high-severity finding older than that window is an automatic fail for that control theme.
Where organisations slip is the software the IT team forgets. Operating system updates are usually current, but third-party applications are not. The repeat offenders we see are web browsers and their extensions, Adobe Reader, Java runtimes, Zoom, and line-of-business tools that auto-update was never enabled for. Browsers are particularly dangerous because they are treated as in scope and patch frequently. Enable automatic updates everywhere you can, then run your own authenticated scan to confirm nothing is lagging before the assessor does.
Unsupported operating systems and end-of-life software
Any device running software the vendor no longer supports with security updates cannot be in scope and will fail the assessment if it is. This catches organisations with an old server tucked in a cupboard, a Windows installation past its end-of-life date, an unsupported mobile operating system on a director’s personal phone, or a legacy application that pins an old runtime.
The fix is an honest asset inventory. List every device and operating system version that touches organisational data or the internet, then check each against the vendor’s support lifecycle. Anything out of support must be upgraded, replaced, or fully segregated from the scope boundary before the audit. Do not assume a device is fine because it still boots. Mobile devices are frequently overlooked here, and a single unsupported handset can sink an otherwise clean estate.
Multi-factor authentication and weak account configuration
Multi-factor authentication on cloud services is now a firm requirement, and missing MFA is one of the fastest growing reasons businesses fail Cyber Essentials Plus. The standard expects MFA on all administrator accounts and all standard user accounts for cloud services such as Microsoft 365 and Google Workspace. An assessor will check that conditional access or equivalent enforcement is actually applied, not merely available.
Closely related are weak password configurations and default credentials. The Cyber Essentials Requirements for IT Infrastructure require either MFA plus a minimum eight-character password, or a twelve-character minimum, or a password with technical controls that block common and breached passwords. Accounts still using vendor default passwords, service accounts with weak credentials, and disabled account lockout policies all cause failures. Audit your administrator accounts in particular, since a single unprotected admin login is enough to fail the user access control theme.
Firewall, malware protection and account separation gaps
The remaining control themes produce their own recurring failures. On boundary firewalls and internet gateways, assessors find open inbound ports that serve no documented business need, remote administration interfaces exposed to the internet, and default firewall passwords left unchanged. On malware protection, the gap is usually an endpoint with no anti-malware running, out-of-date signatures, or an allow-list approach that has not been properly maintained.
Account separation is the quiet one. Cyber Essentials requires that administrator accounts are not used for everyday tasks such as email and web browsing. When an assessor finds staff signed into a privileged account to read email, that is a finding. Give administrators a separate standard account for daily work and reserve the privileged account for administration only. Secure your default device configuration too: remove unused software, disable auto-run, and ensure no device ships into production with factory settings intact.
Devices the assessor cannot reach or sample
A failure that surprises many organisations is purely logistical. The Plus audit samples a cross-section of your devices, and remote or home-working machines must be available for testing on the day. If a laptop is switched off, a remote worker is unreachable, or a BYOD phone in scope cannot be enrolled in the test, the assessor cannot validate the control and the assessment stalls or fails.
Plan the audit logistics as carefully as the technical remediation. Confirm which devices the assessor will sample, make sure remote staff are online and reachable during the window, and verify that the scanning tooling can connect to every in-scope endpoint. A well-prepared estate with a poorly coordinated audit day still ends in a re-test, which costs you time and momentum.
How EJN Labs approaches Cyber Essentials Plus
EJN Labs is a CREST-accredited UK firm holding Cyber Essentials, Cyber Essentials Plus, ISO 27001 and ISO 9001, so we hold the certification we help clients achieve. Our approach to the Plus audit is to remove the surprises. We run an authenticated pre-assessment scan of your estate first, give you a prioritised remediation list mapped to the five control themes, and confirm patch, MFA and configuration status before any formal audit date is set. Testing is delivered by our senior and principal assessors, never juniors, and our pricing is fixed against an agreed scope rather than open-ended day rates. If a control needs a re-test after remediation, the verification is included, so you are not penalised for fixing what we found. You can review indicative figures on our penetration testing cost page and see the wider programme on our Cyber Essentials and CE+ testing page.
Frequently Asked Questions
What is the most common reason businesses fail Cyber Essentials Plus?
Missing or late security patches are the most common single cause of failure. The Cyber Essentials Requirements for IT Infrastructure require high-risk and critical vulnerabilities scoring 7.0 or above on CVSS v3 to be patched within 14 days of a vendor fix, and organisations that miss that window fail the assessment.
Third-party applications such as browsers, PDF readers and conferencing tools are the usual culprits, because automatic updating is often not enabled for them.
Does Cyber Essentials Plus require multi-factor authentication?
Yes. Cyber Essentials requires MFA on all administrator accounts and on all standard user accounts for cloud services such as Microsoft 365 and Google Workspace. The assessor checks that enforcement is actually applied through conditional access or an equivalent control, not simply that a policy exists on paper.
Missing MFA on cloud accounts is now one of the fastest growing reasons organisations fail the user access control theme.
What happens if I fail the Cyber Essentials Plus audit?
You receive the assessor’s findings, remediate the gaps, and the failed controls are re-tested. Failure is not the end of the process, and with a good assessor the failed items are scoped tightly, so you re-verify only what changed rather than repeating the whole audit.
Prevention is better still. Running an authenticated scan two to three weeks before your audit date is the best way to avoid a failure in the first place.
Can an unsupported operating system fail my whole assessment?
Yes, an unsupported operating system can fail your whole assessment if the device is in scope. A single end-of-life server, an out-of-support Windows machine or an unsupported mobile handset is enough to cause a failure, because software no longer receiving vendor security updates cannot remain inside your scope boundary.
Before the audit, an honest asset inventory and a check of every device against vendor support lifecycles is essential.
How long should I allow to prepare for Cyber Essentials Plus?
Allow at least two to three weeks between your readiness scan and the audit date. That window gives you time to patch lagging software, enable MFA, fix account configuration issues, and replace or segregate any unsupported devices before the assessor arrives.
Organisations that book the Plus audit immediately after the self-assessment are the ones most likely to be caught out by gaps the questionnaire never tested.
Get a fixed-price Cyber Essentials Plus assessment
If you want to pass first time, start with a readiness scan that surfaces these failures before audit day. Our senior assessors will map your estate against all five control themes and give you a clear remediation path. Explore our full range on the services overview, learn more about our Cyber Essentials and CE+ testing, or request a fixed-price quote and we will scope your assessment within one working day.




Leave a Reply