Remote Testing
To begin the remote Cyber Essentials Plus testing, we will request an up-to-date inventory of all devices, including:
• Device hostnames
• Operating Systems (OS), along with their edition, version, and build numbers
The testing process will follow these steps:
1. Device Selection and Test Booking
We will select a sample of devices from the inventory you provide. We will then arrange a pre-engagement call and schedule the testing date.
2. Pre-Engagement Call
During the pre-engagement call, we will:
a. Confirm the final list of sample devices to be tested
b. Our technical support team will provide you with access to the required scanning
agents and assist with installation to ensure the agents are deployed correctly on
the selected sample devices
c. Provide you with access to the Atlas portal. You will be able to conduct daily scans
across your estate for the duration of your assessment period
3. Remediation Period
Following the pre-engagement call, you will have 14 calendar days to address and fix
any identified issues.
4. Testing Day
The formal testing will take place on the 15th day after the pre-engagement call. On this day, we will:
a. Complete the final testing activities (steps 4 and 5 of the Cyber Essentials Plus
process)
b. Issue the Cyber Essentials Plus certificate, subject to successful completion
c. It is mandatory that the sample devices or cloud services selected for testing are
available, accessible, and ready at the agreed start time.
d. If the sample devices and cloud services are not available or prepared for
testing, additional time may be required, and additional charges will apply to
cover the extended testing time.
5. Retest (if required)
If your organisation does not meet the Cyber Essentials Plus requirements during the
initial testing:
• You will be given an additional 14 calendar days to address and resolve the
identified issues.
• A retest will be required to verify that all issues have been corrected.
• Important: The retest is chargeable at minimum £500.
Important:
Steps 1, 2, and 3 (inventory submission, sample selection, and the pre-engagement call) must be completed in advance or at the latest by the end of the 14th day.
There are seven main tests we need to complete for the Cyber Essentials Plus certification.
1. Remote Vulnerability Scan
This will scan the breakout point where your network meets the internet. This will make sure that there are no unnecessary services or ports being advertised to the internet, and any unauthenticated requests are blocked by the firewall. This is all completed remotely
2. Internal Authenticated Scan
This will scan the end user devices looking at the security configurations, software
patches, and encryption methods. This will ensure that the device is up to date, and
neither the OS nor software are missing any patches. This is all completed with the
Qualys Agent scanner; instructions to set up can be found on the following page.
3. Malware Protection Test: User Download
This tests the anti-virus, software restriction policies, and permissions. Over a
screenshare with each user from the sample, we will direct them to a website we have configured with various file types. We will then ask the user to download each of the files, to see if any of them can run without requiring user interaction.
4. Malware Protection Test: Email
This tests the email server, and spam filters. We send through various different
attachments, to see if any of them arrive in the inbox, and if they can be executed without warning. This is done against each user in the target sample.
5. MFA Cloud Services Test
This will test that MFA is in place on cloud services. The user is required to try and log in to the in-scope cloud services to display the MFA prompt as evident MFA is in use. This will need to be tested on a standard user and an administrator of the cloud service.
6. Account Separation Check
The user is required to run a command on the device that can only be successful if the user is an admin. When the test fails, this will provide evidence the user is a “standard user” and not logged in as an admin.
7. Mobile Test
We require a sample of the users with mobile devices to screenshot their “about
software” page to display their version number of the OS.
8. Network Segmentation Test
As part of the updated Cyber Essentials Plus assessment requirements, organisations that implement network segmentation to separate in-scope devices from out-of-scope systems must now have their segmentation controls tested.
How We Will Test Network Segmentation:
• During the pre-engagement call, you will be asked to confirm any use of network
segmentation within your environment.
• On the testing day, we will request network diagrams, firewall rules and network
access control lists (ACLs) to verify that the segmentation is properly configured
and enforced.
• If required, we will perform controlled connectivity tests from in-scope devices to
out-of-scope networks or systems.
• This will involve attempting to access resources that should be restricted (e.g.,
attempting to ping or connect to systems outside the defined Cyber Essentials
Plus scope).
• Successful network isolation (i.e., no access possible) will demonstrate that the
segmentation is effective.
• If segmentation controls fail during testing, you will be required to remediate the
issue before certification can be issued.
Important: You must ensure any segmentation rules or firewall controls are
correctly configured and enforced prior to the test day to avoid delays or additional
testing fees.
Sampling
The below table is used to work out the sample sizes. This must be done based on Operating System version/build, e.g.
Asset List = 50 Windows 10 Pro 1909, 50 Windows 10 Pro 20H2, 15 Mac Catalina 10.15.7
Sample Size = 4 Windows 10 Pro 1909, 4 Windows 10 Pro 20H2, 3 Mac Catalina 10.15.7
Number devices of each type | Sample size |
1 | 1 |
2-5 | 2 |
6-19 | 3 |
20-60 | 4 |
61+ | 5 |
Your assessor will advise on the specific requirements for selecting the sample machines providing the questionnaire has been submitted.
Please ensure a cloud service administrator is included in the sample for the MFA test.
What We Need from You
• The External IP address(es).
• An agent installing on each device in the sample.
• An email address for each user in the sample (for the email test).
• A screenshot from the mobile devices in the sample displaying the OS version (see ‘helpful tips’ if you’re not sure how to get this).
Setting Up the Agents
Windows
Your assessor will provide you with a link to a customised installer file you can use to install the scanning agents on the required number of machines.
Please note, the installer provided is specific for your organisation and this specific audit.
It should not be used for any other audits you may be involved in.
Command Line Installation
If you prefer, your assessor can provide you with details on how to install this via the Windows command line via an administrator command prompt. Please advise your assessor if you wish to take this route. From experience most customers will prefer the dedicated installer route as it is a lot simpler to install and can be managed by non-technical users if they have access to an administrator account.
Deployment using Microsoft Intune
You can use Microsoft intune to deploy Qualys Cloud Agent for Windows on remote assets.
Click this link for install guide: Deployment using Microsoft Intune
MacOS
1. Log into the Mac with an account that has sudo privileges.
2. Open the terminal program on the Mac (from the ‘applications’ folder
3. Run the following command, replacing the ###s with the activationID provided by your assessor:
curl -sSL
kt4ry9 mkzxnrg | bash -s ########-####-####-####
############
(This command is all one line)
IMPORTANT NOTE: If you wish to see the contents of the script that is going to be run on your machine before running it, you can download it to inspect it here:
Your assessor will provide either the activationID, or the full command to use for the installation
Linux
Linux x64 systems
Download the installation package from: https://mitigate.box.com/v/qualys-agent-deb
Then run the following commands to install the agent from an account with sudo privileges.
sudo dpkg – install QualysCloudAgent.deb
sudo /usr/local/qualys/cloud-agent/bin/qualys-cloud
agent.sh ActivationID=########-####-####-####
############
CustomerID=913c985b-55db-c858-8375-cf586f7d3085
Your assessor will provide either the activationID, or the full command to use for the installation
Red Hat Based Distributions:
Download the installation package from: https://mitigate.box.com/v/qualys-agent-rpm
Then run the following commands to install the agent from an account with sudo privileges.
sudo rpm -ivh QualysCloudAgent.rpm
sudo /usr/local/qualys/cloud-agent/bin/qualys-cloud
agent.sh ActivationId=########-####-####-####
############
CustomerId=913c985b-55db-c858-8375-cf586f7d3085
Your assessor will provide either the activationID, or the full command to use for the installation
Troubleshooting
If your assessor advises that the agents are not reporting into the server after you have installed them, there are some simple steps to check.
1. Is the agent correctly installed?
On Windows, check for the presence of this path C:/Program Files/Qualys/QualysAgent which will indicate the agent is installed correctly.
Also check if the service is running by opening up your ‘services’ control applet (type ‘services’ into the Windows 10/11 search box) and looking in the list presented for an entry like this that shows the service exists and is currently Running.
On a Mac, check for the presence of an application called QualysCloudAgent in the MacOS Applications folder, which indicates the Agent installed correctly.
2. Can the agents communicate with the server to report results?
The agents needs to be able to report on port 443 (the standard secure communications port) to this web address (URL): https://qagpublic.qg2.apps.qualys.eu/CloudAgent/
If you are ‘egress filtering’ for port 443 specifically or URLs in general you will need to allow an entry for port 443 on the URL above in your outbound allow list for the firewall. Your assessor will tell you when you can remove the entry following test completion.
You can test the connectivity using the following troubleshooting guide:
Step 1: Identify Qualys EU Endpoints
Resolve the IP addresses for the agent gateway:
1. Open PowerShell as Admin and run:py
nslookup gateway.qg2.apps.qualys.eu
Note the IP addresses returned (e.g., 193.28.170.xx).
Step 2: Check Connectivity to Qualys
Verify communication with Qualys’ agent gateway:
1. Test HTTPS (Port 443):
Test-NetConnection -ComputerName gateway.qg2.apps.qualys.eu -Port 443
2. Test Agent Port (Port 7443):
Test-NetConnection -ComputerName gateway.qg2.apps.qualys.eu -Port 7443
If these tests fail, proceed to configure the firewall rules below.
Step 3: Configure Firewall Rules for Agent Communication
Run these commands in PowerShell as Admin:
Copy
# Allow HTTPS (Port 443) to Qualys agent gateway
New-NetFirewallRule -DisplayName "Qualys Agent Outbound HTTPS (443)" -Direction
Outbound -Protocol TCP -RemotePort 443 -Action Allow
# Allow Agent-Specific Port (TCP 7443)
New-NetFirewallRule -DisplayName "Qualys Agent Outbound TCP 7443" -Direction Outbound -Protocol TCP -RemotePort 7443 -Action Allow
# Allow DNS (UDP 53) for domain resolution
New-NetFirewallRule -DisplayName "Qualys Agent Outbound DNS" -Direction Outbound -Protocol UDP -RemotePort 53 -Action Allow
Step 4: Optional Security Refinements
For stricter rules, restrict traffic to Qualys’ resolved IPs (from Step 1):
# Replace "193.28.170.0/24" with actual Qualys IP ranges
New-NetFirewallRule -DisplayName "Qualys Agent Restricted Outbound" -Direction Outbound -Protocol TCP -RemotePort 443,7443 -RemoteAddress "193.28.170.0/24" -Action Allow
Step 5: Verify Firewall Rules
Confirm the rules are active:
Get-NetFirewallRule -DisplayName "Qualys Agent*" | Format-Table DisplayName, Enabled,Direction, Action
Troubleshooting Tips:
• If connectivity issues persist, share the output of Step 1 and Step 2 for further analysis.
• Ensure no third-party firewalls (e.g., McAfee, Norton) are blocking traffic.
3. Are you using a proxy?
On a Mac, you can set up automatic proxy by going to Mac System Preferences > Network > Advanced > Proxies Tab. Select ‘Automatic Proxy Configuration’ and provide the pac file.
On Windows, you may need to manually provide the proxy details to the agent. The agent installer included an application for you to do that.
Run an administrator command prompt and change directory (cd) to the following location:
C:/Program Files/Qualys/QualysAgent
Construct a command to run based on the following table to set the proxy details as necessary for your environment:
For example: QualysProxy /u https://url.of.proxy / n username /p the_p@55w0rd!
Edit the 3 parameters of proxy URL, username, and password as appropriate for your set up.
MacOS “Operation Not Permitted” Error in the Terminal
Later versions of MacOS need a setting making before you can perform disk operations. If you are seeing “Operation Not Permitted” and you have Sudo permissions on your account, please try the following:
1. Pull down the Apple menu and choose “System Preferences”.
2. Choose “Security & Privacy” control panel.
3. Now select the “Privacy” tab, then from the left-side menu, select “Full Disk Access”.
4. Click the lock icon in the lower left corner of the preference panel and authenticate
with an admin level login.
5. Now click the plus [+] button to add an application with full disk access.
6. Navigate to the ‘/Applications/Utilities/’ folder and choose “Terminal” to grant
Terminal with Full Disk Access privileges.
7. Relaunch Terminal, the “Operation not permitted” error messages should be gone.
Helpful Tips
To Get Public IP Address
• In your search engine, input: “what is my IP?”
• Alternatively, enter either of the following into the command line:
o curl icanhazip.com
o curl ifconfig.me
Putting Mac install agent on USB
If you have placed the installagent script on a USB drive, you might do the following:
cd /Volumes <enter>
ls <enter> (read the contents shown and find the USB stick name, you’ll need it in the next command)
cd USB-STICK-NAME <enter> (change the name of the USB stick as appropriate).
You can use the command ls <enter> to confirm you can see the install script and continue the installation.
Running CMD on Windows as Admin
Press Windows Key + R, and type in CMD. Then press CTRL + SHIFT + ENTER.
Alternatively, use the screenshot below:
Getting Mobile OS Version
Android: This should be found in: ‘Settings’ > ‘About Phone’. This varies between phone manufacturers – if you are unsure, please speak to your assessor.
Screenshot = Press the ‘power’ and ‘volume down’ button at the same time.
iPhone: This should be found in: ‘Settings’ > ‘About Phone’. If you are unsure, please speak to your assessor.
Screenshot = Press the ‘lock button’ and ‘volume up’ button at the same time.







