Cyber Essentials Plus

Cyber Essentials Plus is the audited tier of the same government scheme. It covers the same five technical controls as Cyber Essentials, but an assessor tests a sample of your devices and accounts rather than taking your word for it. We are an appointed certification body, so we can assess and certify you. Preparation, remediation and formal assessment are separate pieces of work, quoted separately.

Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor Cyber EssentialsAssessor, held by Daniel McClure Fisher
Cyber Essentials Plus / 01 · What it is

The same five controls, verified instead of declared.

Plus is not a longer list of requirements. It is the same list, checked by someone independent.

Cyber Essentials is a self assessment. You answer the question set, a certification body marks it, and you certify. Cyber Essentials Plus adds a technical audit on top: an assessor tests a sample of your devices and user accounts against the same five controls and confirms they work in practice. You cannot hold Plus without holding Cyber Essentials, so the two are sequential rather than alternative.

The five controls are firewalls, secure configuration, security update management, user access control and malware protection. Our guide to the Cyber Essentials requirements sets out what each one asks for.

Certification lapses after a year, so Plus is a recurring commitment rather than a one-off. Where a contract requires it, it usually requires it continuously.

Cyber Essentials Plus / 02 · The audit

What actually happens on the day.

A sample of devices and accounts, tested against the controls you already declared.

01Sample

Your estate, not all of it

The assessor tests a sample drawn across your device types and operating systems. Scope decides the sample, which is why scope is settled before anything is booked.

DevicesAccountsOperating systems
02Test

Controls in operation

Patch levels, malware protection, account separation and configuration are checked as they actually run, rather than as they were described in the self assessment.

PatchingMalwareAccess
03Report

Pass, or a list

You either certify or you get a written list of what failed. Remediation is quoted separately and you decide whether we do it or you do. You get the findings either way.

FindingsRemediation quoteRetest

For the control by control detail of what is checked and what evidence is expected, see our guide to preparing for Cyber Essentials Plus.

Cyber Essentials Plus / 03 · What it costs

Published prices, by organisation size.

One-off and excluding VAT. Each includes the Cyber Essentials certification Plus requires. If you would rather have it managed monthly, that route is priced on our pricing page.

1–9Micro£1,299 + VAT, includes the Cyber Essentials certification
10–49Small£1,699 + VAT, includes the Cyber Essentials certification
50–249Medium£2,199 + VAT, includes the Cyber Essentials certification
250+LargeFrom £2,999 + VAT, scoped and quoted in writing before we start

Remediation, where it is needed, is quoted separately. If scope changes what you owe, we say so in writing before we start. Our guide to what Cyber Essentials costs breaks down the scheme fee against the work to get ready.

Cyber Essentials Plus / 04 · How long it takes

Four to eight weeks, when you start prepared.

The variable is remediation, not assessment. The audit itself is short.

01

Scope and review

We agree what is in scope and review you against the five controls, so you know what would fail before you book an assessment.

02

Close the gaps

The findings get fixed. You do it, or you ask us to quote for it. This is the step that decides the timeline.

03

Certify at base

The Cyber Essentials self assessment is completed and marked. Plus cannot proceed without it.

04

The Plus audit

An assessor tests the sample and confirms the controls operate. On a pass, the certificate is issued.

Cyber Essentials Plus / 05 · Where it goes wrong

Most failures are found before the assessor arrives.

Which is the argument for a review first, rather than booking the audit and finding out.

The recurring blockers are unpatched software inside the required window, unsupported operating systems still in scope, multi-factor authentication missing on cloud services, and accounts with more privilege than the control allows. None of them are obscure. They fail assessments because nobody checked before the day.

Our guide to why businesses fail Cyber Essentials Plus covers the failure patterns in detail, including what changed with the current question set.

Cyber Essentials Plus / 06 · Who needs it

When a contract asks for Plus specifically.

Plus appears where a buyer wants the controls verified rather than declared. That includes parts of the public sector, some insurers, and prime contractors passing a requirement down their supply chain.

If you supply the Ministry of Defence, note that every level of Defence Cyber Certification requires Cyber Essentials, and DCC Levels 2 and 3 require Cyber Essentials Plus as well. If you need both, start with the DCC route rather than buying them separately.

Weighing Plus against a full management system? Our comparison of Cyber Essentials vs ISO 27001 sets out which one a given clause is actually asking for, and our ISO 27001 support takes over where a contract wants the larger framework.

FAQ

Common questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?

The requirements are the same five controls. Cyber Essentials is a self assessment that a certification body marks. Cyber Essentials Plus adds a technical audit in which an assessor tests a sample of your devices and accounts to confirm the controls operate. Plus is verification, not a longer list.

Do I need Cyber Essentials before Cyber Essentials Plus?

Yes. You cannot hold Plus without holding Cyber Essentials. Our published Plus prices include the Cyber Essentials certification for that reason.

How much does Cyber Essentials Plus cost?

From £1,299 + VAT for organisations of one to nine people, rising by size, with each price including the Cyber Essentials certification. The full ladder is published above. Remediation, where it is needed, is quoted separately.

How long does Cyber Essentials Plus take?

Four to eight weeks for a well prepared organisation. The audit itself is short. What moves the timeline is how much remediation the initial review finds.

What happens if we fail?

You get a written list of what failed. Remediation is quoted separately and you choose whether we carry it out or you do. You receive the findings either way, and the assessment is repeated once the gaps are closed.

Can you prepare us and assess us?

Preparation, remediation and formal assessment are three separate pieces of work, quoted separately. Where separation of duties matters to you or to your customer, we will say so and keep the roles apart.

Book a Cyber Essentials Plus review

Book a review against the five controls, or send us the clause you need to satisfy and we will tell you which tier it is asking for.

Reading, Berkshire  /  Cyber Essentials certification body  /  reply within one working day