Cyber Essentials Plus
Verified by an independent assessor. Not just self-declared.
Cyber Essentials Plus is the higher tier of the UK government's Cyber Essentials certification. Where standard Cyber Essentials is a self-assessment, Plus adds an independent technical audit — a qualified assessor tests your systems hands-on to verify your security controls actually work.
This means real vulnerability scanning against your external infrastructure, live malware testing on your devices, email spoofing tests, and verification that every device is patched, encrypted, and properly configured. It's the difference between saying you're secure and proving it.
We prepare your entire IT environment for the Plus assessment. We run the same tests the assessor will run before they arrive, fix every gap we find, and make sure you pass first time. No surprises, no re-sits.
What the Assessor Tests
The Plus assessment goes beyond paperwork. Here's what gets tested in practice.
Patch Management Verification
The assessor checks that all operating systems, browsers, plugins, and applications are running supported versions with security patches applied within 14 days. Any unsupported or unpatched software is a fail.
Malware Protection Testing
Live malware samples are used to test that anti-malware software detects and blocks threats in real time. The assessor will attempt to download known malware and verify it's quarantined.
External Vulnerability Scan
The assessor runs a vulnerability scan against your internet-facing IP addresses and services to identify exposed ports, outdated services, or misconfigured firewalls.
Email Impersonation Test
Test emails with spoofed addresses and simulated phishing payloads are sent to verify that email filtering, DMARC, and anti-phishing policies are working correctly.
Account & Access Verification
The assessor checks that MFA is enabled, admin accounts are separate from standard accounts, default passwords are changed, and the principle of least privilege is applied.
Device Configuration Checks
A sample of devices is inspected for encryption (BitLocker/FileVault), firewall status, auto-lock settings, and adherence to security baselines.
Cyber Essentials vs Cyber Essentials Plus
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assessment method | Self-assessment questionnaire | Independent technical audit |
| Verification | Answers reviewed by certification body | Systems tested hands-on by assessor |
| Vulnerability scanning | Not included | External infrastructure scanned |
| Malware testing | Not included | Live malware samples tested on devices |
| Email testing | Not included | Spoofing and phishing tests conducted |
| Level of assurance | Baseline | Higher — independently verified |
| Renewal | Annual | Annual (CE must be renewed first) |
Our Plus Preparation Process
Pre-audit
We run the same vulnerability scans, malware tests, and configuration checks the assessor will use. You get a full report of what passes and what needs fixing.
Remediation
We fix every gap — patch management, device configuration, email authentication, access controls, encryption, and endpoint protection. Everything is documented.
Cyber Essentials (standard)
We guide you through the standard Cyber Essentials self-assessment first, since it's a prerequisite for Plus.
Plus assessment day
The independent assessor tests your systems. Because we've already pre-tested everything, there are no surprises. You pass first time.
Ongoing compliance
We maintain your security posture year-round — patching, monitoring, policy enforcement — so annual renewal is straightforward.
Frequently Asked Questions
Cyber Essentials is a self-assessment questionnaire — you answer questions about your security controls and a certification body reviews your answers. Cyber Essentials Plus adds an independent, hands-on technical audit where an assessor tests your actual systems to verify the controls are genuinely in place and working.
Yes. Cyber Essentials Plus builds on Cyber Essentials. You must hold a valid Cyber Essentials certificate before you can undergo the Plus assessment. The Plus assessment must be completed within three months of your Cyber Essentials certification date.
The technical audit itself typically takes 1–2 days depending on the size and complexity of your IT estate. Our preparation work — audit, remediation, and pre-testing — takes 1–3 weeks before the assessor arrives.
If issues are found, you typically have a window to remediate and re-test. With our preparation process, failures are rare — we run the same checks the assessor will run before they arrive, so there are no surprises.
The IASME assessment fee for Cyber Essentials Plus for small businesses typically ranges from £1,500–£3,000 + VAT depending on the size and complexity of your IT estate. Our preparation service is priced separately based on the work needed — contact us for a quote.
Some government and MOD contracts specifically require Cyber Essentials Plus (not just standard). It's also increasingly required by larger private-sector clients who handle sensitive data and want assurance that their supply chain partners are genuinely secure, not just self-assessed.
Need Cyber Essentials Plus?
We'll get you audit-ready and certified, first time.
