When the latest Cyber Essentials updates came into effect this year, one change altered how Cyber Essentials Plus assessments are carried out. It didn’t receive the same attention as the stricter multi-factor authentication (MFA) requirements, but for organisations pursuing Cyber Essentials Plus, it is one of the most important developments to understand. The introduction of the Cyber Essentials Plus second-sample rule strengthens how assessors verify that security controls are being applied consistently across an organisation, rather than on a carefully prepared selection of devices.
Several months on from the changes taking effect, we’re finding that many organisations are still unclear about what this means in practice.
So, What Is the Second-Sample Rule?
As part of a Cyber Essentials Plus assessment, a sample of devices is selected for testing. Under the revised methodology, if the initial internal vulnerability scan identifies unfixed high or critical (CVSS 7 or higher, or identified by the vendor as high or critical) vulnerabilities, a second sample of devices is selected for additional testing.
Timing is a key part of the process. The second sample can only be chosen after the first sample has been tested, and the assessor will tell the organisation which devices are in it no more than 72 hours or 3 working days before testing. The second sample must also be tested within the 30-day remediation window that follows a failed first sample, and there is no further remediation window if it fails. An organisation that does not allow the second sample to be tested cannot achieve Cyber Essentials Plus.
The principle behind the change is straightforward. Cyber Essentials Plus is designed to demonstrate that cyber security controls are working across the organisation as a whole. The second-sample process helps establish whether issues identified are isolated incidents or evidence of a wider problem across the environment.
What Does This Mean for Organisations?
In practical terms, organisations need to be confident that security controls are being applied consistently across all in-scope devices. The updated approach places the emphasis firmly on organisation-wide compliance. If vulnerabilities are identified during the first sample, the expectation is that remediation is applied across the wider estate rather than solely to the devices originally selected for testing. This means patch management, vulnerability management and device visibility are more important than ever. Cyber Essentials Plus is increasingly focused on demonstrating that security controls are embedded throughout the organisation, not simply that a sample of devices appears compliant on assessment day.
The short notice period for the second sample makes the assessment more demanding. Applicants need to set aside dedicated time and staff during the assessment window so that the selected devices can be located, made available and connected for testing within 72 hours or 3 working days. For organisations with remote workers, multiple sites or devices that are rarely online, this requires planning well before the assessment begins. For organisations that already maintain effective patch management, accurate asset inventories and regular vulnerability remediation, the change is unlikely to create difficulties. For those relying on a last-minute compliance push before assessment day, the process has become considerably more challenging.
Why This Matters
At Evolve North, we’ve always encouraged clients to view Cyber Essentials as a security framework rather than simply a certification exercise. The strongest Cyber Essentials Plus assessments are often the smoothest because the organisation already understands what devices are in scope, has a clear patch management process, regularly reviews vulnerabilities and treats Cyber Essentials as part of its day-to-day cyber security approach.
The second-sample rule reinforces that approach. Rather than demonstrating that a handful of devices are compliant on a particular day, organisations are being asked to show that good security practices are embedded throughout their environment. Ultimately, that’s beneficial for both organisations and the wider supply chain.
Preparing for Cyber Essentials Plus Today
The conversations we’re having with clients now tend to focus less on assessment-day preparation and more on maintaining readiness throughout the year.
A few areas are particularly worth attention:
- Know What’s in Scope: You can’t secure devices you don’t know exist. Maintaining an accurate inventory of devices and systems is becoming increasingly important as assessments look more closely at how controls are applied across the estate.
- Keep Security Updating Consistent: The second-sample methodology places greater emphasis on patching and security updating discipline across all in-scope devices, not just those selected for testing.
- Review Vulnerability Management Processes: Security updating is only one piece of the puzzle. Organisations should have clear processes for identifying, tracking and resolving vulnerabilities consistently across their environment.
- Plan for the Short Notice Period: If a second sample is required, you will have no more than 72 hours or 3 working days to make the selected devices available. Agree in advance who will coordinate this, how remote or off-site users will be contacted, and how devices will be brought online for testing. Building this time into your assessment plan avoids a scramble that could put certification at risk.
- Don’t Leave It Until Renewal Time: The organisations that tend to have the smoothest Cyber Essentials Plus journeys are those that treat compliance as an ongoing process rather than an annual event.
Working With Evolve North
As both Cyber Essentials and Cyber Essentials Plus assessors, we’ve always focused on helping organisations build sustainable compliance that reflects the reality of how they operate, rather than preparing for a single assessment day. The second-sample rule doesn’t introduce new technical controls, but it does raise the bar when it comes to demonstrating that those controls are being applied consistently across the organisation.
With the right preparation, it isn’t something to worry about. Instead, it encourages the kind of cyber security practices that help organisations reduce risk long after the assessment has been completed. For organisations looking for a deeper understanding of the certification requirements and assessment process, you can also read the official guidance on the Cyber Essentials website.
From Cyber Essentials and Cyber Assurance to supplier due diligence, security questionnaires and broader governance frameworks, we can help. Contact us at info@evolvenorth.com or call 01748 905 002 to find out more.
