Cyber Essentials Plus

Verified by an independent assessor. Not just self-declared.

Cyber Essentials Plus is the higher tier of the UK government's Cyber Essentials certification. Where standard Cyber Essentials is a self-assessment, Plus adds an independent technical audit — a qualified assessor tests your systems hands-on to verify your security controls actually work.

This means real vulnerability scanning against your external infrastructure, live malware testing on your devices, email spoofing tests, and verification that every device is patched, encrypted, and properly configured. It's the difference between saying you're secure and proving it.

We prepare your entire IT environment for the Plus assessment. We run the same tests the assessor will run before they arrive, fix every gap we find, and make sure you pass first time. No surprises, no re-sits.

What the Assessor Tests

The Plus assessment goes beyond paperwork. Here's what gets tested in practice.

Patch Management Verification

The assessor checks that all operating systems, browsers, plugins, and applications are running supported versions with security patches applied within 14 days. Any unsupported or unpatched software is a fail.

Malware Protection Testing

Live malware samples are used to test that anti-malware software detects and blocks threats in real time. The assessor will attempt to download known malware and verify it's quarantined.

External Vulnerability Scan

The assessor runs a vulnerability scan against your internet-facing IP addresses and services to identify exposed ports, outdated services, or misconfigured firewalls.

Email Impersonation Test

Test emails with spoofed addresses and simulated phishing payloads are sent to verify that email filtering, DMARC, and anti-phishing policies are working correctly.

Account & Access Verification

The assessor checks that MFA is enabled, admin accounts are separate from standard accounts, default passwords are changed, and the principle of least privilege is applied.

Device Configuration Checks

A sample of devices is inspected for encryption (BitLocker/FileVault), firewall status, auto-lock settings, and adherence to security baselines.

Cyber Essentials vs Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
Assessment methodSelf-assessment questionnaireIndependent technical audit
VerificationAnswers reviewed by certification bodySystems tested hands-on by assessor
Vulnerability scanningNot includedExternal infrastructure scanned
Malware testingNot includedLive malware samples tested on devices
Email testingNot includedSpoofing and phishing tests conducted
Level of assuranceBaselineHigher — independently verified
RenewalAnnualAnnual (CE must be renewed first)

Our Plus Preparation Process

1

Pre-audit

We run the same vulnerability scans, malware tests, and configuration checks the assessor will use. You get a full report of what passes and what needs fixing.

2

Remediation

We fix every gap — patch management, device configuration, email authentication, access controls, encryption, and endpoint protection. Everything is documented.

3

Cyber Essentials (standard)

We guide you through the standard Cyber Essentials self-assessment first, since it's a prerequisite for Plus.

4

Plus assessment day

The independent assessor tests your systems. Because we've already pre-tested everything, there are no surprises. You pass first time.

5

Ongoing compliance

We maintain your security posture year-round — patching, monitoring, policy enforcement — so annual renewal is straightforward.

Frequently Asked Questions

Cyber Essentials is a self-assessment questionnaire — you answer questions about your security controls and a certification body reviews your answers. Cyber Essentials Plus adds an independent, hands-on technical audit where an assessor tests your actual systems to verify the controls are genuinely in place and working.

Yes. Cyber Essentials Plus builds on Cyber Essentials. You must hold a valid Cyber Essentials certificate before you can undergo the Plus assessment. The Plus assessment must be completed within three months of your Cyber Essentials certification date.

The technical audit itself typically takes 1–2 days depending on the size and complexity of your IT estate. Our preparation work — audit, remediation, and pre-testing — takes 1–3 weeks before the assessor arrives.

If issues are found, you typically have a window to remediate and re-test. With our preparation process, failures are rare — we run the same checks the assessor will run before they arrive, so there are no surprises.

The IASME assessment fee for Cyber Essentials Plus for small businesses typically ranges from £1,500–£3,000 + VAT depending on the size and complexity of your IT estate. Our preparation service is priced separately based on the work needed — contact us for a quote.

Some government and MOD contracts specifically require Cyber Essentials Plus (not just standard). It's also increasingly required by larger private-sector clients who handle sensitive data and want assurance that their supply chain partners are genuinely secure, not just self-assessed.

Other Services

Need Cyber Essentials Plus?

We'll get you audit-ready and certified, first time.

Get Started