APaaS AssureModules › Cyber Essentials Plus
Module · Cyber Essentials Plus

Cyber Essentials Plus, every day. Not once a year.

The assessor sees your estate for one day. Assure scores every device against the five controls every night, holds every exposure to the 14-day clock, reports the configuration changes that would fail you the next morning, and keeps the evidence so the assessment is a formality rather than a discovery.

Book a demo Open the interactive demo
v3.3 DanzellFive controls14-day clockConfiguration driftAssessor sampleEvidence packIntune and ConfigMgr
assure.apaas.org / ce-plus
CE+ Assessment: 8 of 11 criteria passing, the assessment would fail today, with a four-step path to compliance
Overview

Would you pass today? One page answers it.

The assessment page reads top to bottom the way an assessor would. A pass or fail position against the eleven measurable criteria of Cyber Essentials Plus v3.3, the failing criteria named, a path to compliance in the order that gets you there fastest, the devices that fail and exactly why, each control with its evidence, and the device sample the assessor will draw from, grouped by OS build.

It is the same data the rest of Assure runs on. When Security Patches closes an exposure or Packaging deploys the fix, the assessment moves the same night. Nothing is re-keyed and nothing is a screenshot from last quarter.

8 / 11criteria passing on the demo estate this morning
63devices with a CVSS 7.0+ flaw beyond 14 days, a v3.3 auto-fail
4 stepson the path to compliance, in priority order
Nightlyrescore, with the 14-day clock on every exposure
Illustrative demo estate. Ashcroft Water is fictional. Every screen on this page is the live console rendering invented data, so what you see is the product, not a mock-up.
Why continuous

Certification is a point in time. Your estate is not.

Cyber Essentials Plus tests five things: firewalls, secure configuration, security updates, user access control and malware protection. Four of them are configuration state, and all five change every week in a real estate. A firewall profile is switched off during troubleshooting. An installer adds a Defender exclusion. A contractor is added to local Administrators. A vendor tool disables the Windows Update service and the device looks fine for twelve days.

Each of those is a failure on the day it happens. Without monitoring it is found at the next assessment, by an incident, or by an attacker. Assure finds it the next morning, tells you whether it matters, and gives you the fix.

  • The 14-day rule is an auto-fail in v3.3A CVSS 7.0 or higher vulnerability unpatched beyond 14 days fails the assessment outright. Assure puts a clock on every one from the moment the CVE is published, refreshed every four hours against NIST NVD and CISA KEV.
  • Over 100 new CVEs a dayCorrelated to what is actually installed, not a generic feed. Chrome and Edge alone can put an estate outside the window in a fortnight.
  • Configuration drifts quietlyForty-eight security-relevant facts per device, snapshotted every morning, compared with yesterday, and reported only when the change reduces compliance.
  • The sample is where estates failThe assessor tests a sample of devices per OS build. Assure shows you the same sample groups, and which device in each would fail, before they pick.
  • Evidence beats assertionEvery control carries its evidence line, every fix its audit trail. The assessment day becomes a review of a record, not an investigation.
What it checks

The five controls, tested the way the assessor tests them

Each control is scored from what the agent, Intune, Configuration Manager and Microsoft Graph report, and each carries its evidence line. Ticks are pass or fail checks; dots are configuration facts watched daily for change.

Control 1

Firewalls

  • Boundary firewall confirmed at every site, no permissive inbound rules
  • Host firewall enabled on every in-scope device
  • Domain, private and public profiles on
  • Default inbound action is Block
  • No inbound rule open to any address on any port
Control 2

Secure configuration

  • Default accounts and passwords removed
  • AutoRun disabled and screen lock within 15 minutes
  • Unsupported software removed from scope
  • UAC on, SMBv1 off, Guest disabled, BitLocker on
  • Privileged services, scheduled tasks and folder permissions
Control 3

Security update management

  • High and critical patches applied within 14 days
  • Missing Windows updates per device, with the fix
  • End-of-life products flagged and removed
  • Windows Update service healthy
  • Quality update deferral of 7 days or fewer
Control 4

User access control

  • Administrator accounts separate from daily accounts
  • Leavers removed promptly
  • MFA enforced on cloud services
  • Local Administrators membership, every day
  • New local accounts and non-expiring passwords
Control 5

Malware protection

  • Anti-malware active on every in-scope device
  • Signatures current within 24 hours
  • Real-time and tamper protection on
  • Path, process and extension exclusions
  • Third-party anti-malware noted

Assessor-day tests (the email and browser malware tests and the authenticated vulnerability scan) are performed by the assessor. Assure shows them as such, and makes sure the sample devices are ready for them.

In the console

Six screens, one story

Click any screen to see it full size. All of them show the same demo estate on the same morning, so the numbers agree with each other.

Assessment

The position, and the path out of it

The banner says whether you would pass today and which criteria are failing. Underneath, the path to compliance puts the work in the order that clears the most risk soonest: patch the 63 devices carrying the KEV-listed flaw (packages already built and staged), remove the 148 end-of-life installs, split the 11 shared administrator accounts, then re-run.

  • Pass or fail against all eleven measurable criteria
  • The auto-fail named, with the count behind it
  • Each step linked to the module that does the work
assure.apaas.org / ce-plus
Assessment banner and path to compliance
Device findings

Which devices fail, and exactly why

Not a score. The device, the status and the reason in plain words: the CVE, the days unpatched, the KEV flag, the pending reboot, the shared administrator account. Every line is something an engineer can act on the same day and an assessor would recognise.

  • Fail and warn separated so the urgent list stays short
  • Every reason traceable to its source module
  • Filter to a site, an OS build or the assessor's sample
assure.apaas.org / ce-plus #findings
Device findings table
Controls and evidence

Every control, with the line the assessor will read

Each criterion carries its evidence sentence, generated from the data rather than typed: "8,317 of 8,317 reachable devices report the host firewall enabled" is a fact the assessor can check, and so is "63 devices carry a CVSS 7.0+ vulnerability beyond the 14-day window".

  • Pass, fail and warn per criterion
  • Evidence regenerated every night
  • Exported into the report with one click
assure.apaas.org / ce-plus #controls
Firewalls passing and security update management failing, each with evidence lines
Security patches

The 14-day clock, per device

Missing Windows updates and application patches from the agent, matched to NVD and CISA KEV, each with the days remaining before the criterion fails. The fix is a package built to your standards and staged to Intune or Configuration Manager from the same screen.

  • KEV-listed items first, always
  • Found, installed and percentage improvement in the report
  • Breaches raised into Proactive AI as proposals
assure.apaas.org / security-patches
Security Patches
Proactive AI

The proposals that close the gaps

Every night the agent reads the assessment, the risk register and device health, and proposes the handful of actions that would move the score most, with its reasoning written out: what it saw, why it matters, what changes if you approve. Nothing runs without a person clicking approve, and only catalogue actions can run at all.

  • Confidence and impact stated on each proposal
  • Approve, reject or hold, all recorded
  • Advisory tier by default
assure.apaas.org / proactive-ai
Proactive AI proposals
Assessor sample

The sample the assessor will draw, before they draw it

Cyber Essentials Plus samples devices per OS build. Assure groups your estate the same way, shows the suggested sample size for each group and the devices in it, and flags any device in a group that has not reported its checks. No surprises on the day.

  • Grouped by OS build, as the scheme requires
  • Devices without checks called out
  • Malware protection and Defender state per sampled device
assure.apaas.org / ce-plus #sample
Assessor device sample by OS build
New in the module

Configuration drift: the change you would have found at the assessment

Every morning at 06:30 the agent reads 48 configuration facts on each device, every one of them mapped to a Cyber Essentials Plus criterion, and compares them with the day before. A change that moves a device out of the standard is raised. A change that fixes something is recorded quietly. A change that does neither is noted and nothing more.

The list is short on purpose. Forty-eight facts, not tens of thousands of registry values, which is why the alerts are readable: not "registry value changed" but "tamper protection was turned off on LON-0142, which fails criterion 3.1".

  • Reported the next morningRegressions at or above your severity threshold become findings with a 14-day deadline where a criterion fails. Everything else sits in the device timeline.
  • Lists compared by membershipAn account added to local Administrators or a path added to Defender exclusions is reported by name. A list that comes back in a different order is not a change.
  • Planned changes declared in advanceA rollout window silences expected changes with your change reference attached. Nothing is silently dropped, and silence is never treated as compliance.
Configuration drift · Ashcroft Waterlast 24 hours · 20 devices reporting · 3 findings

Compliance position by control live

20/20Firewalls
18/20Secure config
19/20Updates
19/20User access
20/20Malware

What changed since yesterday worst first

DeviceChangeControlSeverity
ASH-LON-0142Local Administrators membership changed
Added: ASH\contractor
4.1 User accessCritical
ASH-MAN-0225Windows Update service start type changed and no longer meets the standard
Automatic to Disabled · deadline 19 Sep
2.1 UpdatesCritical
ASH-BRS-0087Defender path exclusions changed
Added: C:\Program Files\LegacyLOB\
3.1 MalwareHigh
ASH-LEE-0063Remote Desktop changed and no longer meets the standard
Disabled to Enabled
6.1 Secure configMedium
ASH-BRS-0241Real-time protection is back within the standard
Off to On · resolved
3.1 MalwareInfo

Illustrative feed. The console page is in preview with pilot clients; the engine, the daily digest and the findings are part of the module.

Evidence

What you hand the assessor

The assessment is a review of a record you already hold. Everything below is generated from the platform's own data, dated, and exportable.

The assessment report

One click from the assessment page. Position, failing criteria, path to compliance, device findings and the sample, as a dated PDF for the board or the certification body.

Evidence per criterion

The sentence under each control, regenerated nightly from the data, with the counts behind it. What the assessor asks you to prove is already written down.

The patch record

Found, installed and percentage improvement per device and per update, with the date each exposure closed against its 14-day clock.

The configuration timeline

For any device, what changed and when, what it was before, and who acknowledged it. The answer to "what changed?" without archaeology.

The decision trail

Every rationalisation, governance and remediation decision with the person, the time and the reason. Proactive AI proposals with their approval or rejection.

The compliance journey

Month by month: firewall changes, application upgrades and CVEs cleared, so the improvement is visible as a line, not a claim.

How it works

From connection to a pass, and staying there

  1. Hour 1

    Connect

    Intune, Configuration Manager and the APaaS Assure agent. Outbound only over HTTPS. Nothing opened inbound. Read-only Microsoft Graph for MFA and licence state.

  2. Night 1

    Assess

    Every device scored against the five controls. The first position is usually uncomfortable and always useful: it is what the assessor would have found.

  3. Every 4 hours

    Correlate

    NIST NVD and CISA KEV matched to what is actually installed. The 14-day clock starts on publication, not on discovery.

  4. Every morning

    Watch

    Forty-eight configuration facts per device compared with yesterday. Regressions raised, fixes recorded, noise kept out by design.

  5. Continuously

    Fix and prove

    Packages to your standards, Proactive AI proposals you approve, Workplace Automation for the rest. Every action on the audit trail, every control with its evidence.

See it work

Three short films

Recorded in the console against the demo estate. No slides.

Requirements

What it needs from your environment

Almost nothing new, because the module runs through the agent and connections the rest of Assure already uses.

RequirementWhat it meansNeeded?
APaaS Assure agentRuns as SYSTEM on each device, deployed through your existing Intune or Configuration Manager. Collects inventory, patch state, protection state and the daily configuration snapshot. Read-only unless you approve an action.Required
Outbound HTTPS on 443The agent calls the platform. Nothing is opened inbound on your network. Signed requests, UK-hosted endpoint.Required, usually already allowed
Intune or Configuration ManagerFor deployment of the fixes and for device and compliance data. Either or both; co-management is understood.One of them
Microsoft Graph, read-onlyConditional Access and MFA state, Microsoft 365 licence usage. Reuses your Intune connection.For the MFA criterion
Your standardsPackaging conventions, approved exceptions (the Defender exclusion a line-of-business application genuinely needs), and any folders or services to watch beyond the defaults.Agreed during onboarding
"The assessor asked for evidence on the 14-day rule and we opened the page. He read it, checked two devices from the sample, and moved on. That used to be the afternoon."Head of IT · UK infrastructure consultancy · illustrative quote pending customer approval
FAQ

Questions we get asked

Does this replace the certification?

No. Cyber Essentials Plus is awarded by a certification body after an assessment. Assure is how you know you would pass before they arrive, how you get there, and how you stay there between assessments. The assessor still assesses; they just find what you already know.

Which version of the scheme does it follow?

Cyber Essentials v3.3 (the Danzell question set), including the 14-day auto-fail for CVSS 7.0 and above. When the scheme changes, the criteria and the evidence lines change with it.

Does the agent change anything on my devices?

Not on its own. Detection is read-only. Fixes run only when a person approves them, only from the catalogue of actions APaaS has written and pinned by hash, and every one is recorded. Configuration drift monitoring is entirely read-only.

How noisy is configuration drift?

Deliberately quiet. Only 48 facts are watched, each mapped to a criterion, changes toward compliance are recorded rather than alerted, and lists are compared by membership. The target after a two-week tuning period is two to four recorded changes per device per month, and only the ones that reduce compliance become findings.

We are a service provider with many clients. Does it scope?

Yes. Every read and every action is scoped to the clients a user is entitled to see, per client. The Executive Overview rolls the position up across the client base; the assessment page shows one client at a time.

What leaves the device?

Inventory, patch and protection state, and configuration facts: on and off states, counts, and names where a fact is a list (account names in local Administrators, exclusion paths, rule names). Never documents, file contents, browsing history, email or keystrokes. Signed in transit, UK-hosted.

Find out whether you would pass today.

Connect a pilot group and see your own position within a week. UK-based onboarding, no procurement friction.

Book a demo