The short version

Planning your assessment? See our Cyber Essentials Plus assessment prices, from £1,299 + VAT, including Cyber Essentials. We agree the scope and timetable before work starts; any preparation or remediation is scoped separately.

Cyber Essentials Plus is not a harder standard than Cyber Essentials. It is the same five controls, checked independently. The base certification is a self assessment that a certification body reviews. Plus adds an independent technical audit, where an assessor connects to a sample of your devices, runs vulnerability scans, runs the required malware delivery and protection tests, and confirms that what you said in the self assessment is true.

Technical testing can identify gaps such as missing updates, everyday accounts with administrative rights or unmanaged devices accessing business data. A readiness review helps find and address those issues before assessment. The assessor still needs to verify the controls; preparation does not guarantee a pass.

The NCSC scheme overview (opens in new tab) explains Cyber Essentials and Plus. The test specification linked below is the reference for the formal assessment.

  • Plus tests the same five controls as Cyber Essentials, but verifies them on your live systems.
  • Common gaps concern patching, account privileges, unmanaged devices and missing multi factor authentication.
  • Agree time for discovery, remediation and testing. Unsupported systems and complex access arrangements can require more substantial work.

The five controls, and what each one means in practice

Cyber Essentials covers five technical control areas. For Plus, an assessor checks each one on real devices, so it helps to know what each control means once it leaves the questionnaire.

Control What it means What the assessor looks for
Firewalls A boundary between your devices and the internet, configured to block what should be blocked Default passwords changed, no unnecessary services exposed, home workers covered by a firewall or the device's own software firewall
Secure configuration Devices and software set up to reduce risk, not left on their out of the box defaults Unused accounts and software removed, default passwords gone, auto run disabled, a sensible lock screen
Security update management Keeping operating systems and software patched, and removing anything unsupported High and critical updates applied within fourteen days across operating systems, firmware and applications (an automatic fail since April 2026), no end of life software still in use
User access control People have only the access they need, and admin rights are controlled and separate No daily work in an admin account, accounts tied to real people, multi factor authentication on cloud services
Malware protection Protection against malicious software on every device in scope Anti malware active and updating, or approved application controls, on laptops, desktops, and servers

The scope is wider than people expect

Agree the scope before assessment. Include the required end-user devices and cloud services, plus personal devices that access organisational data or services. A phone used only for native calls, native texts or MFA is excluded under the scheme’s specific exception. Home routers supplied by the employee’s ISP are treated differently from routers supplied by the organisation. Record these boundaries with the certification body rather than assuming every personal device or home network is assessed in the same way.

What the assessor checks on the day

The Plus audit is a sampled technical test, usually run remotely now, sometimes on site. An assessor works through a representative sample of your devices and your cloud services. The exact method follows the scheme's current test specification, published by IASME (opens in new tab), but in practice it covers a familiar set of checks.

  • Patch and vulnerability scan. An authenticated scan of sampled devices, looking for missing high and critical updates and known vulnerabilities. Anything unpatched beyond the fourteen day window is a likely fail.
  • Malware and email tests. The assessor sends a set of harmless test files and links to a live user mailbox, by email and over the web, to confirm your protection catches what it should.
  • Account and privilege checks. Confirmation that everyday accounts do not hold admin rights, that admin access is separated, and that required multi factor authentication is enforced, including for cloud administrator sign-ins.
  • Configuration review. A look at how sampled devices are set up: lock screens, account separation, removal of unsupported software, and so on.

The assessor follows the test specification and records the findings. Required controls need to work across the scope, not only on a preferred device. Agree the sample, access arrangements and the terms for further testing before the assessment.

The common blockers, and how to clear them

Use the following checks to organise a readiness review. They are practical control gaps to look for, not a ranked list of assessment failure statistics.

  • Domain admin rights for daily work. Staff, and sometimes the owner, signing in to their everyday laptop with an administrator account. This fails user access control. Give people standard accounts for daily work and separate, named admin accounts for admin tasks only.
  • Unpatched VPN head ends and firewalls. The device at the edge of your network is in scope, and an unpatched VPN gateway or firewall is both a route in and a clear fail. Confirm the firmware on every internet facing device is current and supported before the audit.
  • Personal devices on Microsoft 365. A personal phone or laptop accessing work data is normally in scope and needs the applicable controls. Management tooling and encryption may support wider security needs, but they are not universal standalone Cyber Essentials requirements. Agree how compliance is evidenced or restrict work access appropriately.
  • Missing multi factor authentication. Inventory cloud services and check that MFA is enforced for the required accounts, including administrators. The April 2026 Danzell question set (opens in new tab) is the account-level reference. FIDO2 passkeys with user verification can satisfy MFA; a biometric or hardware key is not automatically multifactor in every configuration.
  • Unsupported software still in use. An old operating system, an unsupported database, or a line of business application past its end of life will fail security update management. Either upgrade it, replace it, or remove it from the devices in scope.

A typical timeline

The sequence below illustrates a four-to-six-week preparation plan for a small business with limited remediation. It is not a promised completion time. Actual dates depend on scope, the work required and assessment availability; unsupported systems or complex access arrangements can take longer.

Stage Illustrative timing What happens
Gap review Week one Define the scope, list the devices and cloud services, and find the gaps against the five controls
Remediation Weeks two to four Fix the blockers: patching, admin rights, MFA, device management, and any unsupported software
Pre assessment check Week four or five A check against the assessment tests to identify remaining gaps
The Plus audit Week five or six The assessor runs the tests; certification follows a successful assessment under the scheme rules

Cyber Essentials certification is a prerequisite for Plus. You can plan both within one engagement, completing Cyber Essentials before the Plus certification. A readiness review helps identify work needed before technical testing; the formal assessment remains a separate decision.

The current NCSC requirements (opens in new tab) also require security updates within 14 days where severity is critical/high, CVSS v3 is at least 7, or no severity detail is supplied. IASME allows reuse of a CE self-assessment achieved less than three months before Plus certification; agree the dates with the assessor.

How we approach it

We are an appointed Cyber Essentials and Cyber Essentials Plus certification body, and Daniel McClure Fisher is a qualified Cyber Essentials assessor. Preparation and formal assessment are separate pieces of work, described and priced separately. Preparation is the gap review, then the remediation, then a check of the work against the scheme's tests before the assessment is booked. You can have that preparation done by us or by anyone else, and the assessment stands on its own either way. We are not interested in a certificate that does not reflect reality, because a badge that does not match your systems helps no one when an incident or a contract puts it to the test. The aim is a pass that reflects reality, and a setup that stays passable next year.

FAQ

Common questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?

They cover the same five technical controls. Cyber Essentials is a self assessment that a certification body reviews. Cyber Essentials Plus adds an independent technical audit, where an assessor connects to a sample of your devices, runs vulnerability scans, and tests your email and malware protection to confirm the controls are in place. Both levels involve assessment by a certification body; Plus adds technical verification.

How long does Cyber Essentials Plus take to prepare for?

The four-to-six-week sequence in this guide is an illustrative plan for limited remediation, not a completion promise. Discovery, required changes, access and assessor availability determine the actual timetable. Confirm the Cyber Essentials and Plus dates together.

Why do businesses fail Cyber Essentials Plus?

Common blockers include missing required updates, everyday accounts with administrative rights, unmanaged devices, missing multi factor authentication and unsupported software. Plus tests controls on sampled systems, so the answers and the actual configuration must align. The written findings explain the specific gaps in an assessment.

How much does Cyber Essentials cost?

Certification fees start at £320 + VAT for a micro organisation, set by IASME (opens in new tab), the scheme's delivery partner, and reviewed 13 September 2026. Scheme fees change, so the current fee is confirmed in writing before you place an order. The figure rises with the size of your organisation, and Cyber Essentials Plus is priced separately because it includes an independent technical audit. Your first year cost also depends on any remediation needed to pass, which a short gap review will tell you.

Does multi factor authentication have to be on everything for Cyber Essentials?

MFA is required where available, and cloud authentication must use it. Check all cloud services and required accounts rather than enabling it for only some staff. Confirm technical exceptions against the current question set. FIDO2 passkeys with user verification can meet MFA; not every passwordless method does so on its own.

Are personal devices and home working in scope?

Agree the scope before assessment. Include the required end-user devices and cloud services, plus personal devices that access organisational data or services. A phone used only for native calls, native texts or MFA is excluded under the scheme’s specific exception. Home routers supplied by the employee’s ISP are treated differently from routers supplied by the organisation. Record these boundaries with the certification body rather than assuming every personal device or home network is assessed in the same way.