FACGFACG
Cyber Essentials Plus: the 12 things that fail organisations on first attempt
All insights
Compliance February 2026 7 min read

Cyber Essentials Plus: the 12 things that fail organisations on first attempt

We have led over 60 CE Plus assessments. These are the recurring failures we see, ranked by how often they sink an audit, with practical fixes you can apply this afternoon.

By FACG GRC team

Cyber Essentials Plus (CE+) is the technical assessment of the same five controls covered by Cyber Essentials, but verified by a hands-on assessor on a sample of devices. We pass the vast majority of organisations we prepare. The ones that fail tend to fail on the same things every time. Here are the top 12, ranked.

1. Out-of-support operating systems on a sampled device

Windows 10 builds before 22H2, macOS more than two major versions behind, Ubuntu LTS that has fallen out of standard support. The assessor will sample devices including BYOD if BYOD is in scope. One out-of-support device on a sampled machine is a fail. Fix: hard cut-off date for OS upgrades, MDM baseline that blocks non-compliant devices from corporate resources.

2. Browser auto-update disabled

Group Policy or MDM policy that disables Chrome/Edge/Firefox auto-update is a recurring failure. Often a legacy GPO from 2018 that nobody remembers setting. Fix: enable auto-update across all in-scope browsers, verify on the sample.

3. Office macros enabled by default with no signing requirement

Microsoft now blocks macros from the internet by default, but only on supported and patched Office versions. Fix: enforce 'block macros from the internet' via Group Policy or Intune across all in-scope users.

4. Local admin rights for standard users

Standard users running with local admin rights is a near-instant fail. The fix is unpopular but necessary: standard users get standard rights, with a self-service elevation tool (Intune Endpoint Privilege Management, BeyondTrust, AdminByRequest) for the cases that genuinely need it.

5. MFA missing on a single externally-accessible service

All cloud services accessible from the internet must have MFA. The usual culprit is a forgotten legacy SaaS (an old timesheet system, a niche LOB tool) where MFA is available but not enforced. Fix: full inventory of internet-facing services, MFA enforced on every one.

6. Default credentials on a network device

An unmanaged switch with admin/admin still set, or a printer with the factory default. Cleared up in five minutes once found. Fix: nightly scan for default credentials on the internal network, document fixes.

7. Software inventory does not match what is on the device

The assessor will run a script that lists installed applications and compare against your declared inventory. Old apps that nobody removed (Java 8, Adobe Flash for some reason still installed, abandoned Chrome extensions) appear and you cannot account for them. Fix: monthly software inventory reconciliation, automated removal of unapproved apps via MDM.

8. Patching SLA breached on a sample device

The standard requires high-risk patches applied within 14 days. The assessor will sample devices and check the actual patch state. Fix: report on patch compliance weekly, escalate any device 10+ days behind on a critical patch before the cycle ends.

9. EICAR test fails to trigger AV

The assessor will drop an EICAR test string on the device and verify that the AV detects it. AV that has been disabled, paused, exclusion-list-bypassed or just not running will fail. Fix: verify AV health daily via your endpoint console, alert on any device with AV disabled or out of date.

10. BYOD without an enrolment baseline

If you allow BYOD for email or company data, the personal devices come into scope. They have to meet the same baseline (OS, AV, MFA, screen lock, encryption). Fix: enrol BYOD via app-based MDM (Intune App Protection Policies, Workspace ONE) with the baseline enforced; or move to corporate-owned devices for the in-scope users.

11. SaaS admin accounts without MFA

User MFA is on, but the dedicated admin account in a SaaS tool is not (because admin uses a service account that 'cannot do MFA'). The assessor will check. Fix: every admin account on every in-scope SaaS has MFA, including service accounts where the SaaS supports it.

12. Firewall rule for 'temporary remote access' that is two years old

An any/any rule, a port-forward to a remote desktop machine, an old VPN concentrator with weak configuration. Fix: quarterly firewall rule review, document business justification for every external-facing rule, remove anything without one.

Have a question on this?

Book a 30 minute discovery call. We answer questions in plain English, with or without a follow-on engagement.