Protection

The Cyber Essentials Plus readiness checklist for MSPs

Most providers treat the CE Plus audit like an exam they cram for the week before, and it shows. Here is what the assessor actually tests, the five gaps that fail MSPs first time, and how to walk in ready, for your own business and your clients.

By Nathan Carroll21 September 20269 min read

The first time I put an MSP through Cyber Essentials Plus, I made the classic mistake. I treated it as a certificate to acquire rather than a standard to meet. We booked the audit, then went looking for the gaps. The assessor found them faster than we did.

That is the wrong way round, and it is the way most providers still do it. The irony is hard to miss: MSPs sell security for a living, and yet a surprising number fail CE Plus on the first attempt, on exactly the basics they would flag inside a client's estate without thinking.

There is more riding on this than a badge for your website now. Your clients are being told by their own customers, their insurers and, increasingly, their regulators to prove their security posture, and that pressure flows straight to your desk. You are also a target in your own right. An MSP holds privileged access to dozens of businesses at once, which makes you the single most valuable key on the ring. Passing CE Plus is partly about the certificate and mostly about not being the weak link in someone else's supply chain.

Here is what the assessment actually involves, the five gaps that catch providers out first time, and how to walk in ready.

What the assessment actually involves

Cyber Essentials and Cyber Essentials Plus test the same five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The difference is who checks. Standard Cyber Essentials is a self-assessment questionnaire, verified but largely taken on trust. Cyber Essentials Plus is that same questionnaire backed by hands-on testing from an independent assessor, and that is where "we think we're fine" meets reality.

In practice the assessor does four things: an external vulnerability scan of your internet-facing addresses, an authenticated scan and hands-on check of a sample of your user devices, a test of whether your systems actually block malicious files and web content, and a check that multi-factor authentication is enforced on your cloud services. You do not get to hand-pick the perfect machine to show them. They sample. And the clock matters: CE Plus has to be completed within three months of your Cyber Essentials certification, so you cannot let remediation drift for a quarter and hope.

Now the gaps, roughly in the order they catch people.

1.Unsupported software still lurking in the estate

This is the number one first-time failure, and it is almost always something nobody remembered. An end-of-life operating system on a machine in the corner. A line-of-business application the vendor stopped patching two years ago. Firmware on a firewall or a switch that has quietly aged out of support. The scan finds it in minutes, and unsupported software in scope is an automatic fail, however good everything else looks.

The fix is unglamorous, and it is inventory. You cannot certify what you cannot see. Before you book anything, build a complete list of every operating system, application and piece of firmware in scope, and check each one against its support lifecycle. Anything end-of-life gets upgraded, removed, or genuinely segregated out of scope. Not the week before the audit. Now.

2.MFA gaps, especially on your own admin tooling

Multi-factor authentication is now required on cloud services, and this is where MSPs, of all people, get caught. Rarely on the client-facing logins, those are usually covered. It is the privileged tooling that runs your own business that slips: the RMM, the PSA, the Microsoft 365 admin centre, the domain registrar, the backup console. These are the exact accounts an attacker wants most, and they are too often behind a password alone because "it's only us who use it."

A break-glass account with no second factor, a shared service account, an admin who switched MFA off because it nagged during a late-night job: any one of these will fail you, and each is a real risk quite apart from the audit. Enforce MFA everywhere, including and especially on administrative and cloud consoles. Use separate identities for admin work. If you genuinely need a break-glass account, document it, lock it down, and monitor it.

You would flag every one of these in a client's estate in your first week. The audit simply asks whether you hold your own house to the same standard.

3.Default configuration and services left open

Secure configuration and firewalls are meant to work together to shrink your attack surface, and the classic failures are things left switched on that should have been turned off. Default or weak credentials on a device or an application. Unnecessary services and accounts still enabled. And the perennial killer, a management protocol like RDP exposed straight to the internet because it was convenient once and never closed again.

The external scan will find any open port you have forgotten about. Before the audit, close every inbound service that does not have a cast-iron reason to be reachable, put remote access behind a VPN or a properly controlled gateway, change every default password, and disable the accounts and features you are not using. If something has to be exposed, be able to say why and show how it is protected.

4.Patching that covers most devices, not all

Cyber Essentials expects high-risk and critical security updates to be applied within fourteen days of release. Most MSPs are genuinely good at this, which is exactly why the failure stings. Your patch compliance sits in the high nineties, and CE Plus does not grade on a curve. The assessor samples a device, finds the one laptop that has been in a drawer for a month or the server under a change freeze, and that single machine is enough to fail the assessment.

The answer is not to patch harder, it is to patch completely and be able to prove it. Report patch compliance as a percentage, then chase the tail that the percentage hides: the machines that are rarely online, the ones carved out of automation, the "we'll get to it" server. Automate updates where you safely can, and have a defined process for the stragglers so there is no device you cannot account for.

5.Scope drawn carelessly

The last one is not a control at all, it is a decision, and getting it wrong quietly undoes everything else. You declare what is in scope, and the assessment tests against that declaration. Draw it too loosely and you sweep in things you cannot stand behind: a home worker's personal laptop, an unmanaged phone syncing company mail, a cloud service nobody is really administering. Draw it too cleverly, carving out the awkward corners, and you end up with a certificate that means little to the security-conscious client who asks the obvious follow-up question.

Decide scope deliberately and early. Account for home and remote workers, for every device that touches company data, for the cloud services in daily use, and for anything brought in under BYOD. For an MSP specifically, whole-organisation scope is usually the right call, because a partial certificate is a hard thing to explain to the exact kind of client you most want to win.

The part most MSPs miss

Everything above is about passing the audit for your own business, and you should, before you say another word to a client about theirs. But readiness is not only a hurdle. It is an offer.

The commercial angle

Here is the reframe. You are already doing this work to certify yourself: inventory, MFA enforcement, configuration hardening, patch discipline, deliberate scope. That is precisely what every one of your clients now needs, and most of them have no idea where to start.

Packaged as a service, it is a readiness assessment up front, a remediation project to close the gaps, the certification itself, then an annual renewal with monitoring in between. One-off revenue that matures into recurring revenue, on a requirement your clients increasingly cannot avoid.

The audit you have to pass anyway is also the service your competitors are still giving away for free.

That is the whole difference between treating compliance as a cost you absorb and treating it as a line of business. The providers who move first here are safer, and they are building a moat while everyone else is still filing security under overhead.

Where to start

If you take one thing from this, take this: do the inventory and set the scope before you book anything. Almost every first-time failure traces back to something that was never on anyone's list, or a boundary nobody had actually drawn. You cannot secure, certify or sell against an estate you cannot fully see.

Would you pass a CE Plus audit tomorrow?

  • Is there a single unsupported operating system, application or piece of firmware anywhere in scope? One is enough to fail.
  • Is MFA enforced on every cloud and admin console, including your RMM, PSA and Microsoft 365?
  • Can you show critical patches applied within fourteen days across every device, not just most of them?
  • Do you know exactly what is in scope, including home workers, cloud services and BYOD?
  • Is anything, RDP or another management service, exposed to the internet without a clear reason?

If any of those made you pause, that is your remediation list. And it is the same list your clients need. Far better you find it than the assessor does.

Nathan Carroll

Protection is one of the three levers I score

Not sure you'd pass, or how to sell it?

Book a free Scale Audit and I'll give you an operator-to-operator read on your Platform, Protection and Profit, with a one-page action plan you keep either way. Thirty minutes, no pitch.