Skip to main content

Cyber Essentials Plus — manual (interactive) tests - What happens on the day

What happens on the day

T
Written by Tom Singleton
Updated over 2 months ago

Who is tested

  • We test sampled end-user devices only (laptops and desktops used by staff).

  • We do not test servers or headless machines.

How access works

  • The user shares their screen via Microsoft Teams when it is their turn.

  • We do not need the user’s credentials.

  • The user may close or hide any confidential windows before sharing.

  • Each device takes about five to ten minutes.


Order and logic of the manual tests

  1. Account separation (first)

    • We try to perform an administrative task from a standard user account.

    • This confirms least privilege is enforced.

  2. Malware protection (second — only if test 1 passes)

    • We send a safe test email attachment and attempt to download safe test files from the web.

    • This confirms endpoint protection blocks malicious files.

    • Only run this test if Account separation passed.

  3. MFA check (independent)

    • We attempt to sign in to cloud services to confirm multi-factor authentication is enforced.

    • The account owner must be present to approve any MFA prompt.

    • This test can be done at any time; it does not depend on the other checks.

Did this answer your question?