Your estate, not all of it
The assessor tests a sample drawn across your device types and operating systems. Scope decides the sample, which is why scope is settled before anything is booked.
Cyber Essentials Plus is the audited tier of the same government scheme. It covers the same five technical controls as Cyber Essentials, but an assessor tests a sample of your devices and accounts rather than taking your word for it. We are an appointed certification body, so we can assess and certify you. Preparation, remediation and formal assessment are separate pieces of work, quoted separately.
Plus is not a longer list of requirements. It is the same list, checked by someone independent.
Cyber Essentials is a self assessment. You answer the question set, a certification body marks it, and you certify. Cyber Essentials Plus adds a technical audit on top: an assessor tests a sample of your devices and user accounts against the same five controls and confirms they work in practice. You cannot hold Plus without holding Cyber Essentials, so the two are sequential rather than alternative.
The five controls are firewalls, secure configuration, security update management, user access control and malware protection. Our guide to the Cyber Essentials requirements sets out what each one asks for.
Certification lapses after a year, so Plus is a recurring commitment rather than a one-off. Where a contract requires it, it usually requires it continuously.
A sample of devices and accounts, tested against the controls you already declared.
The assessor tests a sample drawn across your device types and operating systems. Scope decides the sample, which is why scope is settled before anything is booked.
Patch levels, malware protection, account separation and configuration are checked as they actually run, rather than as they were described in the self assessment.
You either certify or you get a written list of what failed. Remediation is quoted separately and you decide whether we do it or you do. You get the findings either way.
For the control by control detail of what is checked and what evidence is expected, see our guide to preparing for Cyber Essentials Plus.
One-off and excluding VAT. Each includes the Cyber Essentials certification Plus requires. If you would rather have it managed monthly, that route is priced on our pricing page.
Remediation, where it is needed, is quoted separately. If scope changes what you owe, we say so in writing before we start. Our guide to what Cyber Essentials costs breaks down the scheme fee against the work to get ready.
The variable is remediation, not assessment. The audit itself is short.
We agree what is in scope and review you against the five controls, so you know what would fail before you book an assessment.
The findings get fixed. You do it, or you ask us to quote for it. This is the step that decides the timeline.
The Cyber Essentials self assessment is completed and marked. Plus cannot proceed without it.
An assessor tests the sample and confirms the controls operate. On a pass, the certificate is issued.
Which is the argument for a review first, rather than booking the audit and finding out.
The recurring blockers are unpatched software inside the required window, unsupported operating systems still in scope, multi-factor authentication missing on cloud services, and accounts with more privilege than the control allows. None of them are obscure. They fail assessments because nobody checked before the day.
Our guide to why businesses fail Cyber Essentials Plus covers the failure patterns in detail, including what changed with the current question set.
Plus appears where a buyer wants the controls verified rather than declared. That includes parts of the public sector, some insurers, and prime contractors passing a requirement down their supply chain.
If you supply the Ministry of Defence, note that every level of Defence Cyber Certification requires Cyber Essentials, and DCC Levels 2 and 3 require Cyber Essentials Plus as well. If you need both, start with the DCC route rather than buying them separately.
Weighing Plus against a full management system? Our comparison of Cyber Essentials vs ISO 27001 sets out which one a given clause is actually asking for, and our ISO 27001 support takes over where a contract wants the larger framework.
The requirements are the same five controls. Cyber Essentials is a self assessment that a certification body marks. Cyber Essentials Plus adds a technical audit in which an assessor tests a sample of your devices and accounts to confirm the controls operate. Plus is verification, not a longer list.
Yes. You cannot hold Plus without holding Cyber Essentials. Our published Plus prices include the Cyber Essentials certification for that reason.
From £1,299 + VAT for organisations of one to nine people, rising by size, with each price including the Cyber Essentials certification. The full ladder is published above. Remediation, where it is needed, is quoted separately.
Four to eight weeks for a well prepared organisation. The audit itself is short. What moves the timeline is how much remediation the initial review finds.
You get a written list of what failed. Remediation is quoted separately and you choose whether we carry it out or you do. You receive the findings either way, and the assessment is repeated once the gaps are closed.
Preparation, remediation and formal assessment are three separate pieces of work, quoted separately. Where separation of duties matters to you or to your customer, we will say so and keep the roles apart.
Book a review against the five controls, or send us the clause you need to satisfy and we will tell you which tier it is asking for.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.