Cyber Essentials Plus secure configuration is one of the five technical control themes an assessor tests directly, through hands-on technical testing rather than a questionnaire. Getting it right means your servers and endpoints are genuinely hardened, not just documented as such, and as of April 2026, getting it wrong can mean an automatic fail rather than a deduction.
For context: Cyber Essentials is a UK Government-backed scheme overseen by the National Cyber Security Centre (NCSC) Cyber Essentials Plus is the higher of its two tiers, adding an independent, hands-on technical assessment on top of the standard self-assessed version. It’s increasingly a contractual requirement for UK public sector work and is spreading through private-sector supply chains as larger organisations start requiring it of their suppliers.
Where hardening fits in Cyber Essentials Plus (and where it doesn’t)
Cyber Essentials Plus certification is bigger than any one piece of software can solve. You still need a completed self-assessment questionnaire and a hands-on technical audit from an IASME-licensed Certification Body. IASME owns the scheme on the NCSC’s behalf, but it’s the network of licensed Certification Bodies who actually carry out assessments and issue certificates.
What hardening automation does is make sure the servers and endpoints underneath that paperwork are actually configured the way the scheme requires, specifically against the Secure Configuration control, and supports the evidence you need for Patch and Update Management. It removes unused services and insecure defaults, enforces a defined baseline, and flags drift before an assessor’s technical testing finds it. If your self-assessment says default accounts are removed and configurations are locked down, hardening is what keeps that true on every device, every day, not just on assessment day.
This is the gap that catches a lot of organisations out. The questionnaire is filled in. The intent is genuine. Nobody’s verifying that the actual configuration matches what was declared, until an assessor starts sampling devices.
What the April 2026 update changes
The Cyber Essentials Requirements for IT Infrastructure v3.3, known as the “Danzell” question set, took effect on 27 April 2026. If your assessment account was created before that date, you have until 26 October 2026 to certify under the previous rules; after that, everyone is assessed against v3.3.
The headline change is enforcement, not the controls themselves. The five technical control themes haven’t changed, but two of them now carry automatic failure conditions where previously a gap might only cost you points:
- Patch and update management: critical and high-risk security updates must still be applied within 14 days, but the scope has been pushed further into firmware, including routers, firewalls, and VPN appliances. This matters: actively exploited vulnerabilities in VPN appliances from major vendors have made firmware patching a live risk, not a theoretical one, and it’s an area organisations commonly overlook because it sits outside the usual Windows and cloud patching cycle.
- User access control: MFA gaps, particularly on cloud services and administrative accounts, are now treated as a serious failure rather than a deduction.
In practical terms, an organisation that could previously pass with a documented gap and a plan to fix it can now fail outright for the same gap. That changes what “good enough” looks like heading into an assessment.
How Cyber Essentials Plus assessments actually get failed
It’s rarely a missing policy. It’s almost always a gap between what the self-assessment claims and what an assessor finds when they actually look.
A firewall’s firmware hasn’t been updated in eight months because nobody added it to the regular patch cycle. A default admin account on a network switch was never disabled. A server rebuilt after an incident never had the hardening baseline reapplied. None of this shows up in a questionnaire. All of it shows up the moment an assessor samples devices directly, which is the entire point of the Plus tier.
That’s the part most preparation misses: a completed questionnaire proves intent. A hardened, monitored configuration proves it’s actually happening.
Cyber Essentials Plus secure configuration checklist
Use this as a starting point for what your Secure Configuration and patch management evidence should actually cover. For the full picture, including exact baseline settings by OS, our hardening configuration spreadsheet below goes much deeper than any checklist on a page can.
- Defined, documented configuration baseline applied across all in-scope servers and endpoints
- Default accounts, credentials, and unnecessary services removed or disabled
- Critical and high-risk patches applied within 14 days, including firmware on routers, firewalls, and VPN appliances
- Configuration changes logged, timestamped, and attributable to a person
- Drift detection so a baseline that’s been changed gets flagged, not discovered during assessment
- Administrative access restricted and auditable
- MFA enforced across cloud services and administrative accounts
- Evidence organised and ready to hand an assessor, not reconstructed under deadline pressure
For MSPs and IT providers managing Cyber Essentials Plus for clients
If you’re managing infrastructure for multiple clients pursuing certification, or supporting an organisation through annual recertification, manually verifying configuration and patch status across every device doesn’t scale, and it definitely doesn’t hold up to an assessor’s technical testing. With auto-fail criteria now in place for two of the five controls, a single overlooked device can fail an entire assessment.
The providers that handle this well aren’t checking configuration device by device before each assessment window. They’re enforcing a consistent baseline continuously, getting alerted the moment something drifts, and producing assessment-ready evidence on demand rather than scrambling in the weeks before a renewal.
How CalCom Hardening Suite helps
CalCom Hardening Suite (CHS) helps organisations meet the Secure Configuration control behind Cyber Essentials Plus, and supports the evidence you need for Patch and Update Management, without the downtime that usually comes with hardening production systems.
- Enforces a documented, consistent configuration baseline across servers and endpoints
- Detects and flags unauthorised configuration changes in real time, instead of waiting for an assessment to find them
- Logs every configuration change with full attribution, so the evidence is already there when an assessor asks
- Shows you the impact of a hardening change before it goes live, so you’re not choosing between security and uptime
- Maintains the baseline continuously, not just in the run-up to assessment
If you’re working through a Cyber Essentials Plus readiness project and want a second opinion on where your actual gaps are before an assessor finds them, talk to us. We’ll walk through your environment with you, not just hand you a feature list.