The short version

Ready to arrange technical testing? Review our Cyber Essentials Plus assessment prices and inclusions. Prices start at £1,299 + VAT, including Cyber Essentials. Preparation is scoped separately, and certification depends on a successful assessment.

Cyber Essentials Plus is the audited version of Cyber Essentials. Same five controls, but an assessor verifies them on your real devices in addition to reviewing the self-assessment. That difference is why firms that sailed through the self assessment can still stumble on Plus. The badge on paper and the state of your machines are not always the same thing.

The control areas below provide a practical starting point for a readiness review. Some gaps need configuration changes; others require replacement software, new devices or changes to working practices. The scope and findings determine the work required.

  • The audit tests live systems, so a clean self assessment does not guarantee a pass.
  • Review the common control gaps early enough to plan any technical or operational changes.
  • A gap review and pre-assessment checks reduce uncertainty; they do not guarantee the assessment outcome.

What changed in April 2026: the Danzell question set

IASME uses the Danzell question set for purchases from 27 April 2026, aligned to NCSC requirements v3.3. The five control areas remain the same. Cloud services are explicitly in scope; cloud MFA and timely security updates need to be implemented, not merely planned. These are current requirements, rather than entirely new controls introduced in April. Use the IASME question set (opens in new tab) and NCSC requirements v3.3 (opens in new tab) for the assessment account you are using.

The NCSC’s Cyber Essentials overview (opens in new tab) explains the two assessment levels. Use this checklist to prepare; it does not replace the current requirements or the assessor’s formal tests.

  • Multi factor authentication (MFA) is mandatory wherever a cloud service offers it. It no longer matters whether multi factor authentication is free, bundled, or a paid add on. If the service can do it and you have not enabled it for every user, the assessment fails automatically.
  • Late security updates are an automatic fail. Critical and high risk updates must be applied within fourteen days across operating systems, firmware, and applications. Miss that on either count and you fail, regardless of how well the rest scores.
  • Check the passwordless method. The requirements recognise FIDO2 passkeys with user verification as MFA. A biometric or security key used as a single factor does not automatically provide two factors.

IASME distinguishes purchases before 27 April 2026, using Willow, from purchases on or after that date, using Danzell. Use the version assigned to your account and confirm its submission deadline with your certification body. Do not assume a single late-October deadline applies to every earlier purchase.

The real reasons businesses fail

Take these in turn. For each, here is what the assessor sees, why it fails, and how to fix it before the day.

1. Missing security updates

Missing required updates can prevent certification. Check operating systems, applications and firmware, including devices that were offline during a patch cycle. Apply security updates and vulnerability fixes within 14 days of release where the vendor rates the vulnerability critical or high risk, its CVSS v3 base score is at least 7, or the vendor provides no severity information. Keep in-scope software licensed and supported. A pre-assessment vulnerability scan can help find issues before formal testing.

How to fix it. Confirm automatic updates are on across every device in scope, including phones, and that they are completing. Check third party software too, because browsers, document readers, and Java style runtimes are frequent culprits. Run your own scan before the audit so you find the gaps first.

2. Everyday accounts with admin rights

Many people, owners included, do their daily work signed in as a local or domain administrator. It feels convenient, and it fails user access control. The risk is real: if malware runs in an admin session, it can do far more damage. The assessor will check whether everyday accounts hold admin rights, and whether admin access is held in separate, named accounts.

How to fix it. Give everyone a standard account for day-to-day work. Create separate, named administrator accounts used only for admin tasks, and only when needed. This single change resolves one of the most frequent failures and lowers your risk.

3. Personal and unmanaged devices on company data

A personal phone reading company email or a home laptop accessing Microsoft 365 or other organisational data is normally in scope. Check its applicable controls, supported software and access arrangements. Lack of management software or disk encryption is not, by itself, a universal Cyber Essentials failure; the question is whether the scheme’s actual controls are met.

How to fix it. Either bring those devices under management, with the basic controls applied and enforced, or stop company data reaching unmanaged devices in the first place. Both are valid. What is not valid is an unmanaged device with full access to company email and no controls at all.

4. Missing or partial multi factor authentication

The current requirements call for MFA where available and require cloud authentication to use it. Review interactive access to every cloud service, including administrators. Distinguish sign-in accounts from shared mailboxes and non-interactive service identities; ask the assessor how the question set applies to any unusual account design.

How to fix it. Enforce the required MFA, remove unnecessary interactive sign-ins and document the access design. FIDO2 passkeys with user verification are one option; do not assume every biometric or token alone is multifactor.

5. Unsupported software and operating systems

An operating system or application past its end of life can no longer receive security updates, so it fails security update management outright. An old server quietly running an unsupported version, a legacy line of business application, or a machine still on a retired operating system will all stop a certificate.

How to fix it. Identify anything unsupported well ahead of the audit. Upgrade it, replace it, or remove it from the devices in scope. If a legacy application genuinely cannot move yet, that is a conversation to have early, because it shapes your scope and your timeline.

6. Scope drawn too narrowly, or wrongly

Agree the scope before assessment. Include the required end-user devices and cloud services, plus personal devices that access organisational data or services. A phone used only for native calls, native texts or MFA is excluded under the scheme’s specific exception. Home routers supplied by the employee’s ISP are treated differently from routers supplied by the organisation. Record these boundaries with the certification body rather than assuming every personal device or home network is assessed in the same way.

How to fix it. Map your scope honestly at the start: every device, every cloud service, every person with access. It is far better to find the awkward device in week one than to have it surface on audit day.

The pattern behind the failures

Set the list side by side and a theme appears. None of these are advanced attacks or obscure rules. They are the gap between what a busy business assumes is true and what is configured on its machines. The self-assessment must reflect reality, and technical testing provides an additional check. Review the configuration before signing the declaration.

Failure cause Why it fails The fix before the audit
Missing updates High and critical patches not applied within fourteen days (an automatic fail since April 2026) Confirm auto updates complete on every device, scan first
Admin rights for daily work Everyday accounts hold administrator privileges Standard accounts for work, separate named admin accounts
Unmanaged personal devices Company data on devices with no controls Manage the device, or keep company data off it
Partial MFA MFA not enabled on a cloud service that offers it (an automatic fail since April 2026) Enforce it on every cloud service that offers it, including admin accounts
Unsupported software End of life systems can no longer be patched Upgrade, replace, or remove from scope
Wrong scope A device that should be in scope was left out Map scope honestly at the start

How to prepare for the assessment

Start with discovery so you can plan the work before formal assessment.

  • Start with a gap review. Define the scope, list every device and cloud service, and check each against the five controls. This is where the blockers surface, while you still have time to fix them.
  • Fix the blockers. Patching, admin rights, MFA, device management, and unsupported software. Do the work, not just enough to look right on the day, because the audit tests the machines themselves.
  • Run a dry run. Test your own devices the way the assessor will: a vulnerability scan, the email and malware checks, the account and privilege checks. Use the results to address remaining gaps before formal testing.
  • Then book the assessment. Agree the date when the known gaps have been addressed. The assessor independently determines whether the requirements are met.

Cyber Essentials certification is required before Plus. Plan the verified self-assessment and technical testing in the right order, allowing time for any work needed between them.

How we approach it

We are an appointed Cyber Essentials and Cyber Essentials Plus certification body, and Daniel McClure Fisher is a qualified Cyber Essentials assessor. Preparation and formal assessment are separate pieces of work, described and priced separately. Preparation is the gap review, the remediation, and a check of the work against the scheme's tests before the day, to identify gaps before formal assessment. You can have that preparation done by us or by anyone else. The formal assessment checks the controls in scope. Certification is a point-in-time result and does not replace ongoing security management.

FAQ

Common questions

What is the most common reason for failing Cyber Essentials Plus?

Missing required security updates are an important blocker, but we do not publish a ranked failure dataset. Review patches, user privileges, MFA, supported software and scope. The assessor’s findings identify the actual reason for an unsuccessful assessment.

What happens if you fail Cyber Essentials Plus?

The assessor records the findings. You arrange the remedial work, and any retest follows the scheme rules and the agreed assessment terms. Remediation, further testing and delays can add costs; confirm these arrangements in the quote. Certification is issued only after a successful assessment.

Can preparation guarantee a first-time pass?

No. A readiness review and pre-assessment tests help identify gaps, but the formal assessor still needs to verify the requirements. Map the scope, review the five controls, address the findings and keep the supporting evidence. Agree any retest arrangements before the assessment.

Did the Cyber Essentials rules change in 2026?

Yes. IASME introduced Danzell for purchases from 27 April 2026, aligned to NCSC requirements v3.3. Check explicit cloud scope, required MFA and security update compliance. These remain five technical control areas. Use the question set and deadline assigned to your assessment account rather than assuming a general transition date.

How long does it take to prepare for Cyber Essentials Plus?

The four-to-six-week sequence is illustrative for a small business needing limited remediation. Actual timing depends on scope, changes, access and assessment availability. Unsupported systems or complex access arrangements may take longer. Review these before booking.

How much does Cyber Essentials cost?

Certification fees start at £320 + VAT for a micro organisation, set by IASME (opens in new tab), the scheme's delivery partner, and reviewed 13 September 2026. Scheme fees change, so the current fee is confirmed in writing before you place an order. The figure rises with the size of your organisation, and Cyber Essentials Plus is priced separately because it includes an independent technical audit. Your real first year cost also depends on any remediation needed to pass, which a short gap review will tell you.

Can I do Cyber Essentials Plus without the basic Cyber Essentials first?

You must hold Cyber Essentials before you can hold Plus. Both can be planned within one engagement, but the verified self-assessment and Cyber Essentials certification come first. Tell us the scope and date of any current certificate so we can agree the Plus assessment arrangements.