secure

Cyber Essentials
Plus certification.

The five technical controls, tested on your systems.

From £1,299+ VAT · Cyber Essentials included

An appointed certification body for UK organisations. We agree the scope, test a sample of devices and accounts, and record the assessment outcome.

One-off assessment. Preparation and remediation scoped separately.

Cyber Essentials Plus prices

One-off assessment prices, including the prerequisite Cyber Essentials certification. We confirm the scope and arrangements before you commit.

Cyber Essentials + Plus assessment · prices exclude VAT
OrganisationAssessment price
Micro 1–9 people£1,299 + VAT
Small 10–49 people£1,699 + VAT
Medium 50–249 people£2,199 + VAT
Large 250+ peopleFrom £2,999 + VAT

One assessment route. Both certificates.

  • The Cyber Essentials certification required for Plus
  • Technical testing of an agreed representative sample
  • Written findings and the certification decision

Certification follows a successful assessment. Preparation and remediation are quoted separately; scope changes affecting the price are confirmed before work starts.

Get a Plus assessment quote

Tell us your organisation size, systems and deadline. We reply within one working day.

Already hold Cyber Essentials?Send the certificate and date

We will confirm how your existing scope and certificate date fit the Plus assessment. The published prices above include Cyber Essentials; any different arrangement is confirmed in your quote.

Need help getting ready?Preparation has its own scope

A readiness review identifies gaps before technical assessment. Your team or existing IT provider can make the changes, or DSC can quote separately. Readiness work does not guarantee certification.

Scheme fees and preparation costs
Already a managed IT client?Optional annual planning and control management

Ongoing control management and renewal planning can be agreed as a managed-client add-on. A one-off Plus assessment does not require a managed IT contract.

Optional managed-client add-on

Is your requirement Cyber Essentials rather than Plus? Verified self-assessment starts at £320 + VAT. Check the requested level before choosing technical testing.

Cyber Essentials assessment only
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor scheme Cyber EssentialsAssessor, held by Daniel McClure Fisher

Your appointed Plus certification body

Cyber Essentials Plus certification body

DSC is appointed to assess and certify organisations for both Cyber Essentials and Cyber Essentials Plus. This is separate from holding our own Cyber Essentials Plus certificate.

We define which service you are buying. Readiness support, remediation, technical assessment and certification decisions have separate records and responsibilities.

Our appointments and credentials

The same five controls.
Additional technical testing.

Cyber Essentials uses a verified self-assessment. You complete the question set and a certification body marks the answers. Certification follows a successful assessment.

Cyber Essentials Plus adds independent technical testing of a sample of devices and user accounts against those same controls. You must hold Cyber Essentials before you can hold Plus.

Both certifications last a year. Where a contract requires continuous certification, renewal needs to be planned before expiry.

  • FirewallsControl the network connections into and out of your systems.
  • Secure configurationConfigure devices and software for the required security baseline.
  • Security update managementKeep supported software updated within the required timescales.
  • User access controlControl permissions, account use and authentication.
  • Malware protectionProtect against the execution of malicious software.

What the assessor tests

A representative sample

The assessor samples the device types, operating systems and user accounts in scope. The scope and sample are agreed before scheduling the assessment.

  • Devices
  • Accounts
  • Operating systems

Controls in operation

The assessment checks patch levels, malware protection, account separation and configuration on the sampled systems.

  • Patching
  • Malware protection
  • Access control

Findings and outcome

Certification follows a successful assessment. If a control fails, you receive the findings. You can arrange the remedial work yourselves or ask us for a separate quote. Any retest is planned under the scheme rules.

  • Written findings
  • Separate remediation
  • Retest

Our guide to preparing for Cyber Essentials Plus covers the testing and evidence in more detail.

Cyber Essentials and Plus, explained.

32 seconds · Silent explainer. The route from readiness to assessment.

Two levels of assessment.

Both schemes use the same five technical controls. Cyber Essentials is a verified self-assessment. Plus adds technical testing of devices and accounts.

Agree the scope, address gaps and complete the formal assessment. Certification follows a successful result.

Read the service explanation

Cyber Essentials or Plus? The same five controls, with different levels of verification.

Cyber Essentials is a verified self-assessment. An assessor checks your answers.

Plus adds technical testing of devices and accounts. Cyber Essentials comes first.

Agree the scope and address any gaps. Preparation and formal assessment are separate steps.

Certification follows a successful assessment. Dead Simple Computing. Talk to our certification team.

Planning your assessment

  1. Scope and review

    Agree the environment in scope and review the five controls. Establish any readiness work and confirm the assessment arrangements.

  2. Close the gaps

    Address the findings internally, or commission a separate remediation engagement. The work needed determines the preparation time.

  3. Complete Cyber Essentials

    Complete the verified self-assessment and obtain Cyber Essentials certification before Plus.

  4. Technical assessment

    The assessor tests the sample against the controls. A successful assessment leads to certification.

Allow an indicative four to eight weeks for a prepared organisation. Actual timing depends on scope, remediation and assessment availability. Tell us your contract deadline and any existing Cyber Essentials certificate date when we scope the work.

Common assessment blockers

A readiness review can identify gaps before the assessment. The work often concerns patching, supported software, authentication and access permissions.

Why businesses fail Cyber Essentials Plus explains the failure patterns and the current question set.

  • Updates outside the required windowSecurity patches have not been applied within the scheme timescales.
  • Unsupported operating systemsSoftware or devices still in scope no longer receive the required support.
  • Missing multi-factor authenticationCloud services lack the authentication controls required by the scheme.
  • Excessive account privilegesUser accounts have more access than the controls allow.

When your contract asks for Plus

Some public-sector buyers, insurers and prime contractors ask specifically for Plus because it adds technical verification. Send us the relevant clause if the required certification level is unclear.

Every level of Defence Cyber Certification requires Cyber Essentials. DCC Levels 2 and 3 also require Cyber Essentials Plus, as set out in IASME's DCC guidance. Our DCC certification-body appointment is for Level 0. If you need both schemes, review the DCC route before buying them separately.

A requirement for ISO 27001 asks for a full information security management system. Our comparison of Cyber Essentials vs ISO 27001 explains the difference, and our ISO 27001 support covers that framework.

Common questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both assess the same five technical controls. Cyber Essentials is a verified self-assessment marked by a certification body. Plus adds technical testing of a sample of your devices and accounts to check the controls operate in practice.

Do I need Cyber Essentials before Cyber Essentials Plus?

Yes. You must hold Cyber Essentials before you can hold Plus. Our published Plus prices include the Cyber Essentials certification. Tell us if you already hold a certificate so we can confirm the scope and timing.

How much does Cyber Essentials Plus cost?

From £1,299 + VAT for organisations of one to nine people, with each price including Cyber Essentials certification. Small organisations pay £1,699 + VAT, medium organisations £2,199 + VAT, and large organisations from £2,999 + VAT. The full size bands are above. Preparation and remediation, where needed, are scoped and quoted separately.

How long does Cyber Essentials Plus take?

Allow an indicative four to eight weeks for a prepared organisation. The actual timing depends on scope, remediation and assessment availability. Tell us your required completion date and the date of any existing Cyber Essentials certificate when we scope the assessment.

What happens if we fail?

You receive the written findings. You can arrange the remediation yourselves or ask us for a separate quote. A retest is planned once the gaps are addressed, within the scheme's assessment and remediation rules.

Can you prepare us and assess us?

Preparation, remediation and formal assessment are separate pieces of work, quoted separately. Their responsibilities and records are kept separate, and the engagement follows the scheme's impartiality requirements. Certification depends on a successful assessment.

Get your Plus assessment quote.

Tell us your organisation size, the systems in scope and any deadline. If a customer has requested certification, send the clause you need to satisfy.

We will confirm the relevant assessment, what preparation is needed and the price before work starts.

0118 359 2220

Reading, Berkshire.
Reply within one working day.