Skip to main content

Cyber Essentials Plus

Remote Testing Instructions

Written by Vincent Priestley

Remote Testing

To begin the remote Cyber Essentials Plus testing, we will request an up-to-date inventory of all devices, including:

• Device hostnames

• Operating Systems (OS), along with their edition, version, and build numbers

The testing process will follow these steps:

1. Device Selection and Test Booking

We will select a sample of devices from the inventory you provide. We will then arrange a pre-engagement call and schedule the testing date.

2. Pre-Engagement Call

During the pre-engagement call, we will:

a. Confirm the final list of sample devices to be tested

b. Our technical support team will provide you with access to the required scanning

agents and assist with installation to ensure the agents are deployed correctly on

the selected sample devices

c. Provide you with access to the Atlas portal. You will be able to conduct daily scans

across your estate for the duration of your assessment period

3. Remediation Period

Following the pre-engagement call, you will have 14 calendar days to address and fix

any identified issues.

4. Testing Day

The formal testing will take place on the 15th day after the pre-engagement call. On this day, we will:

a. Complete the final testing activities (steps 4 and 5 of the Cyber Essentials Plus

process)

b. Issue the Cyber Essentials Plus certificate, subject to successful completion

c. It is mandatory that the sample devices or cloud services selected for testing are

available, accessible, and ready at the agreed start time.

d. If the sample devices and cloud services are not available or prepared for

testing, additional time may be required, and additional charges will apply to

cover the extended testing time.

5. Retest (if required)

If your organisation does not meet the Cyber Essentials Plus requirements during the

initial testing:

• You will be given an additional 14 calendar days to address and resolve the

identified issues.

• A retest will be required to verify that all issues have been corrected.

Important: The retest is chargeable at minimum £500.

Important:

Steps 1, 2, and 3 (inventory submission, sample selection, and the pre-engagement call) must be completed in advance or at the latest by the end of the 14th day.

There are seven main tests we need to complete for the Cyber Essentials Plus certification.

1. Remote Vulnerability Scan

This will scan the breakout point where your network meets the internet. This will make sure that there are no unnecessary services or ports being advertised to the internet, and any unauthenticated requests are blocked by the firewall. This is all completed remotely

2. Internal Authenticated Scan

This will scan the end user devices looking at the security configurations, software

patches, and encryption methods. This will ensure that the device is up to date, and

neither the OS nor software are missing any patches. This is all completed with the

Qualys Agent scanner; instructions to set up can be found on the following page.

3. Malware Protection Test: User Download

This tests the anti-virus, software restriction policies, and permissions. Over a

screenshare with each user from the sample, we will direct them to a website we have configured with various file types. We will then ask the user to download each of the files, to see if any of them can run without requiring user interaction.

4. Malware Protection Test: Email

This tests the email server, and spam filters. We send through various different

attachments, to see if any of them arrive in the inbox, and if they can be executed without warning. This is done against each user in the target sample.

5. MFA Cloud Services Test

This will test that MFA is in place on cloud services. The user is required to try and log in to the in-scope cloud services to display the MFA prompt as evident MFA is in use. This will need to be tested on a standard user and an administrator of the cloud service.

6. Account Separation Check

The user is required to run a command on the device that can only be successful if the user is an admin. When the test fails, this will provide evidence the user is a “standard user” and not logged in as an admin.

7. Mobile Test

We require a sample of the users with mobile devices to screenshot their “about

software” page to display their version number of the OS.

8. Network Segmentation Test

As part of the updated Cyber Essentials Plus assessment requirements, organisations that implement network segmentation to separate in-scope devices from out-of-scope systems must now have their segmentation controls tested.

How We Will Test Network Segmentation:

• During the pre-engagement call, you will be asked to confirm any use of network

segmentation within your environment.

• On the testing day, we will request network diagrams, firewall rules and network

access control lists (ACLs) to verify that the segmentation is properly configured

and enforced.

• If required, we will perform controlled connectivity tests from in-scope devices to

out-of-scope networks or systems.

• This will involve attempting to access resources that should be restricted (e.g.,

attempting to ping or connect to systems outside the defined Cyber Essentials

Plus scope).

• Successful network isolation (i.e., no access possible) will demonstrate that the

segmentation is effective.

• If segmentation controls fail during testing, you will be required to remediate the

issue before certification can be issued.

Important: You must ensure any segmentation rules or firewall controls are

correctly configured and enforced prior to the test day to avoid delays or additional

testing fees.

Sampling

The below table is used to work out the sample sizes. This must be done based on Operating System version/build, e.g.

Asset List = 50 Windows 10 Pro 1909, 50 Windows 10 Pro 20H2, 15 Mac Catalina 10.15.7

Sample Size = 4 Windows 10 Pro 1909, 4 Windows 10 Pro 20H2, 3 Mac Catalina 10.15.7

Number devices of each type

Sample size

1

1

2-5

2

6-19

3

20-60

4

61+

5

Your assessor will advise on the specific requirements for selecting the sample machines providing the questionnaire has been submitted.

Please ensure a cloud service administrator is included in the sample for the MFA test.

What We Need from You

• The External IP address(es).

• An agent installing on each device in the sample.

• An email address for each user in the sample (for the email test).

• A screenshot from the mobile devices in the sample displaying the OS version (see ‘helpful tips’ if you’re not sure how to get this).

Setting Up the Agents

Windows

Your assessor will provide you with a link to a customised installer file you can use to install the scanning agents on the required number of machines.

Please note, the installer provided is specific for your organisation and this specific audit.

It should not be used for any other audits you may be involved in.

Command Line Installation

If you prefer, your assessor can provide you with details on how to install this via the Windows command line via an administrator command prompt. Please advise your assessor if you wish to take this route. From experience most customers will prefer the dedicated installer route as it is a lot simpler to install and can be managed by non-technical users if they have access to an administrator account.

Deployment using Microsoft Intune

You can use Microsoft intune to deploy Qualys Cloud Agent for Windows on remote assets.

Click this link for install guide: Deployment using Microsoft Intune

MacOS

1. Log into the Mac with an account that has sudo privileges.

2. Open the terminal program on the Mac (from the ‘applications’ folder

3. Run the following command, replacing the ###s with the activationID provided by your assessor:

curl -sSL

kt4ry9 mkzxnrg | bash -s ########-####-####-####

############

(This command is all one line)

IMPORTANT NOTE: If you wish to see the contents of the script that is going to be run on your machine before running it, you can download it to inspect it here:

Your assessor will provide either the activationID, or the full command to use for the installation

Linux

Linux x64 systems

Download the installation package from: https://mitigate.box.com/v/qualys-agent-deb

Then run the following commands to install the agent from an account with sudo privileges.

sudo dpkg – install QualysCloudAgent.deb

sudo /usr/local/qualys/cloud-agent/bin/qualys-cloud

agent.sh ActivationID=########-####-####-####

############

CustomerID=913c985b-55db-c858-8375-cf586f7d3085

Your assessor will provide either the activationID, or the full command to use for the installation

Red Hat Based Distributions:

Download the installation package from: https://mitigate.box.com/v/qualys-agent-rpm

Then run the following commands to install the agent from an account with sudo privileges.

sudo rpm -ivh QualysCloudAgent.rpm

sudo /usr/local/qualys/cloud-agent/bin/qualys-cloud

agent.sh ActivationId=########-####-####-####

############

CustomerId=913c985b-55db-c858-8375-cf586f7d3085

Your assessor will provide either the activationID, or the full command to use for the installation

Troubleshooting

If your assessor advises that the agents are not reporting into the server after you have installed them, there are some simple steps to check.

1. Is the agent correctly installed?

On Windows, check for the presence of this path C:/Program Files/Qualys/QualysAgent which will indicate the agent is installed correctly.

Also check if the service is running by opening up your ‘services’ control applet (type ‘services’ into the Windows 10/11 search box) and looking in the list presented for an entry like this that shows the service exists and is currently Running.

On a Mac, check for the presence of an application called QualysCloudAgent in the MacOS Applications folder, which indicates the Agent installed correctly.

2. Can the agents communicate with the server to report results?

The agents needs to be able to report on port 443 (the standard secure communications port) to this web address (URL): https://qagpublic.qg2.apps.qualys.eu/CloudAgent/

If you are ‘egress filtering’ for port 443 specifically or URLs in general you will need to allow an entry for port 443 on the URL above in your outbound allow list for the firewall. Your assessor will tell you when you can remove the entry following test completion.

You can test the connectivity using the following troubleshooting guide:

Step 1: Identify Qualys EU Endpoints

Resolve the IP addresses for the agent gateway:

1. Open PowerShell as Admin and run:py

nslookup gateway.qg2.apps.qualys.eu

Note the IP addresses returned (e.g., 193.28.170.xx).

Step 2: Check Connectivity to Qualys

Verify communication with Qualys’ agent gateway:

1. Test HTTPS (Port 443):

Test-NetConnection -ComputerName gateway.qg2.apps.qualys.eu -Port 443

2. Test Agent Port (Port 7443):

Test-NetConnection -ComputerName gateway.qg2.apps.qualys.eu -Port 7443

If these tests fail, proceed to configure the firewall rules below.

Step 3: Configure Firewall Rules for Agent Communication

Run these commands in PowerShell as Admin:

Copy

# Allow HTTPS (Port 443) to Qualys agent gateway

New-NetFirewallRule -DisplayName "Qualys Agent Outbound HTTPS (443)" -Direction

Outbound -Protocol TCP -RemotePort 443 -Action Allow

# Allow Agent-Specific Port (TCP 7443)

New-NetFirewallRule -DisplayName "Qualys Agent Outbound TCP 7443" -Direction Outbound -Protocol TCP -RemotePort 7443 -Action Allow

# Allow DNS (UDP 53) for domain resolution

New-NetFirewallRule -DisplayName "Qualys Agent Outbound DNS" -Direction Outbound -Protocol UDP -RemotePort 53 -Action Allow

Step 4: Optional Security Refinements

For stricter rules, restrict traffic to Qualys’ resolved IPs (from Step 1):

# Replace "193.28.170.0/24" with actual Qualys IP ranges

New-NetFirewallRule -DisplayName "Qualys Agent Restricted Outbound" -Direction Outbound -Protocol TCP -RemotePort 443,7443 -RemoteAddress "193.28.170.0/24" -Action Allow

Step 5: Verify Firewall Rules

Confirm the rules are active:

Get-NetFirewallRule -DisplayName "Qualys Agent*" | Format-Table DisplayName, Enabled,Direction, Action

Troubleshooting Tips:

• If connectivity issues persist, share the output of Step 1 and Step 2 for further analysis.

• Ensure no third-party firewalls (e.g., McAfee, Norton) are blocking traffic.

3. Are you using a proxy?

On a Mac, you can set up automatic proxy by going to Mac System Preferences > Network > Advanced > Proxies Tab. Select ‘Automatic Proxy Configuration’ and provide the pac file.

On Windows, you may need to manually provide the proxy details to the agent. The agent installer included an application for you to do that.

Run an administrator command prompt and change directory (cd) to the following location:

C:/Program Files/Qualys/QualysAgent

Construct a command to run based on the following table to set the proxy details as necessary for your environment:

For example: QualysProxy /u https://url.of.proxy / n username /p the_p@55w0rd!

Edit the 3 parameters of proxy URL, username, and password as appropriate for your set up.

MacOS “Operation Not Permitted” Error in the Terminal

Later versions of MacOS need a setting making before you can perform disk operations. If you are seeing “Operation Not Permitted” and you have Sudo permissions on your account, please try the following:

1. Pull down the Apple menu and choose “System Preferences”.

2. Choose “Security & Privacy” control panel.

3. Now select the “Privacy” tab, then from the left-side menu, select “Full Disk Access”.

4. Click the lock icon in the lower left corner of the preference panel and authenticate

with an admin level login.

5. Now click the plus [+] button to add an application with full disk access.

6. Navigate to the ‘/Applications/Utilities/’ folder and choose “Terminal” to grant

Terminal with Full Disk Access privileges.

7. Relaunch Terminal, the “Operation not permitted” error messages should be gone.

Helpful Tips

To Get Public IP Address

• In your search engine, input: “what is my IP?”

• Alternatively, enter either of the following into the command line:

o curl icanhazip.com

o curl ifconfig.me

Putting Mac install agent on USB

If you have placed the installagent script on a USB drive, you might do the following:

cd /Volumes <enter>

ls <enter> (read the contents shown and find the USB stick name, you’ll need it in the next command)

cd USB-STICK-NAME <enter> (change the name of the USB stick as appropriate).

You can use the command ls <enter> to confirm you can see the install script and continue the installation.

Running CMD on Windows as Admin

Press Windows Key + R, and type in CMD. Then press CTRL + SHIFT + ENTER.

Alternatively, use the screenshot below:

Getting Mobile OS Version

Android: This should be found in: ‘Settings’ > ‘About Phone’. This varies between phone manufacturers – if you are unsure, please speak to your assessor.

Screenshot = Press the ‘power’ and ‘volume down’ button at the same time.

iPhone: This should be found in: ‘Settings’ > ‘About Phone’. If you are unsure, please speak to your assessor.

Screenshot = Press the ‘lock button’ and ‘volume up’ button at the same time.

Did this answer your question?