Skip to main content

Elite IT Team

Cyber Essentials Plus: Requirements, Cost & How to Pass

Cyber Essentials Plus: Requirements, Cost & How to Pass

Cyber Essentials Plus requirements

Key Takeaways

  • Cyber Essentials Plus is independently verified. Unlike standard Cyber Essentials, it includes hands-on testing by an IASME-accredited assessor to confirm your security controls are working in practice. 
  • A valid Cyber Essentials certification is required first. You must successfully complete the self-assessment before you can progress to the Cyber Essentials Plus audit.
  • The audit focuses on real-world security. Assessors perform vulnerability scans, test a representative sample of devices, verify secure configurations, and confirm effective malware protection and user access controls.
  • Most failures are preventable. Common issues include missing security patches, unsupported software, weak MFA, excessive administrator privileges, and firewall misconfigurations, all of which can be resolved with proper preparation.
  • Costs vary by organisation size and complexity. While Cyber Essentials Plus requires a larger investment than the standard certification, it can unlock government contracts, satisfy cyber insurance requirements, and strengthen customer trust.
  • Preparation is the key to passing. Running an internal vulnerability scan, ensuring systems are fully patched, enforcing MFA, and clearly defining the audit scope significantly improve your chances of first-time success.
  • Certification is an ongoing commitment. Cyber Essentials Plus is valid for 12 months, and organisations are expected to maintain their security controls continuously.

Your company has reached the final stage of a government contract. The proposal scored well. The pricing is competitive. The relationship with the procurement team feels strong.

Then an email arrives: “Can you provide evidence of Cyber Essentials Plus certification?”

Suddenly the opportunity stalls, not because your services aren’t good enough, but because you can’t demonstrate that your cybersecurity controls have been independently verified. It’s an increasingly common moment, where public sector buyers, insurers, and larger commercial clients now expect suppliers to prove their cybersecurity maturity before doing business, not just claim it.

This guide walks through exactly what Cyber Essentials Plus involves: how it differs from standard Cyber Essentials, what an assessor actually tests, what it costs in 2026, why organisations fail their first attempt, and how to prepare so certification becomes a formality rather than a scramble.

Why Cyber Essentials Plus Matters More Than Ever

Cyber Essentials was created by the UK government after analysis found that a small set of basic technical controls would have stopped the vast majority of common cyber attacks reaching organisations. It remains centred on five control areas designed to block the most frequent internet-based threats.

Standard Cyber Essentials is self-assessed: an organisation completes a questionnaire, a senior leader signs a declaration, and a qualified assessor reviews the answers. It’s a valuable baseline, but it relies on trust.

Cyber Essentials Plus removes the guesswork. An independent, IASME-accredited assessor tests your systems directly like scanning your network, sampling your devices, and confirming the controls you claimed are actually working. That distinction is exactly why more contracts, cyber insurance policies, and framework agreements now name Cyber Essentials Plus specifically rather than the base-level certification.

Cyber Essentials vs Cyber Essentials Plus: What’s the Difference?

Both certifications assess the same five technical control areas. The difference is how compliance is verified and that difference is what gives Cyber Essentials Plus its credibility with procurement teams, insurers, and regulators. 

Aspect Cyber Essentials Cyber Essentials Plus
Assessment method Self-assessment questionnaire (SAQ) Independent technical audit by an accredited assessor
Verification level Answers reviewed for consistency Controls actively tested on live systems
Vulnerability scanning Not required Internal and external vulnerability scans performed
Device sampling Not applicable Representative sample of devices tested
Prerequisite None Valid Cyber Essentials certificate required first
Typical use case Baseline hygiene, smaller contracts Government contracts, insurers, higher-assurance clients

 

Did You Know?

You cannot apply for Cyber Essentials Plus in isolation. IASME requires a valid, passed Cyber Essentials self-assessment first, which is usually completed within three months of the Plus audit, because the Plus audit verifies controls that Cyber Essentials assumes are already in place.

What the Assessor Actually Tests

A Cyber Essentials Plus audit is evidence-based, not paperwork-based. It’s normally carried out remotely by a qualified assessor from an IASME-accredited certification body, although larger or more complex environments sometimes involve an on-site visit.

The assessor runs authenticated and unauthenticated vulnerability scans against every internet-facing IP address within scope, checking for missing patches, insecure services, misconfigured boundary devices, and exposed administrative interfaces. Any vulnerability scoring 7.0 or above on the CVSS v3 scale is treated as a failure unless you can demonstrate it’s a false positive.

A representative sample of end-user devices like laptops, desktops, and increasingly mobile devices, is then tested with credentialed access, confirming that patching, malware protection, and secure configuration are genuinely applied at the device level, not just described in policy documents. The assessor also observes how real users interact with email and web browsing to confirm malware protection behaves as expected.

Organisations with firewalls, VPNs, or segmented networks in scope should expect close attention to configuration. Businesses relying on legacy or unmanaged network hardware often benefit from a review by a partner offering managed network security services before booking the audit, since boundary misconfiguration is one of the most common technical failure points.

The Five Security Controls 

1. Firewalls and Internet Gateways

Every device connecting to the internet must sit behind a correctly configured firewall or gateway, with default administrative passwords changed and unnecessary services closed off.

2. Secure Configuration

Devices and software must be configured to reduce vulnerabilities — removing unused accounts and software, disabling auto-run features, and applying authentication before access is granted.

3. User Access Control

Access to data and services should be limited to what each user needs. Administrative accounts must be tightly controlled, and multi-factor authentication is increasingly expected wherever a cloud service supports it.

4. Malware Protection

Anti-malware software, application allow-listing, or sandboxing must be in place across all in-scope devices, actively protecting against malicious code.

5. Security Update Management

All software, operating systems, and firmware must be kept up to date, with vendor-supplied patches applied promptly. Devices that can no longer receive security updates fall out of scope and typically need replacing or isolating.

Together, these five controls are designed to stop the vast majority of common, opportunistic internet-based attacks, not sophisticated, targeted intrusions, but the everyday phishing, malware, and exploitation attempts that account for most breaches affecting UK SMEs. 

Step-by-Step Cyber Essentials Plus Audit Process

The audit itself is more structured than most business owners expect. Knowing the sequence in advance removes much of the anxiety around assessment day.

Step What Happens
1. Scoping You and the certification body agree exactly which devices, networks, and cloud services are within scope.
2. Pre-audit self-assessment A valid, passed Cyber Essentials certificate must already be in place.
3. Vulnerability scanning Authenticated and unauthenticated scans of internet-facing IP addresses in scope.
4. Device sampling A representative sample of laptops, desktops, and servers is tested with credentialed access.
5. User behaviour checks Assessor observes malware protection and browsing/email behaviour on sampled devices.
6. Evidence review Assessor reviews findings against the CE+ test specification and CVSS scoring thresholds.
7. Result & certificate Pass, or a defined remediation window to fix and retest specific failures.

 

✅ Best Practice

Run your own internal vulnerability scan roughly two weeks before the official audit. It surfaces exactly the same categories of issue the assessor will find, giving you time to patch before assessment day rather than during it.

Common Reasons Businesses Fail

Most first-time failures aren’t caused by weak security strategy,  they’re caused by small,overlooked gaps that scanning tools catch immediately. Organisations preparing for certification often begin with professional audit and compliance services to identify these gaps through a structured readiness assessment before the formal audit, rather than discovering them on the day.

Failure Area Typical Cause
Missing patches Devices or software not updated within the expected timeframe before assessment
Unsupported software Operating systems or applications that no longer receive vendor security updates
Weak or missing MFA Multi-factor authentication not enabled on cloud services that support it
Excessive admin rights Standard users retaining local administrator privileges unnecessarily
Unscoped devices Personal or BYOD devices accessing company data without being included in scope
Firewall misconfiguration Default credentials left unchanged, or unnecessary ports left open
⚠ Common Mistake

IASME’s 2026 scheme update specifically flags organisations ‘applying selective updates’ immediately before assessment, patching only the sampled devices rather than the whole estate. Assessors are now scoping and evidencing this more closely, so partial preparation is increasingly easy to spot.

How Much Does Cyber Essentials Plus Cost?

Organisation Size Typical Cyber Essentials Plus Cost (ex. VAT)
Micro (0–9 employees) From roughly £1,300–£1,500
Small (10–49 employees) From roughly £1,500–£2,000
Medium (50–249 employees) From roughly £2,000–£3,500
Large (250+ employees) Custom quote based on scope and device count; often £3,500–£8,000+

Unlike standard Cyber Essentials, where IASME sets a fixed, published assessment fee, Cyber Essentials Plus pricing is set individually by each accredited certification body, based on the size and complexity of your environment. Costs typically scale with organisation size, device count, and network complexity. This figure sits on top of the standard Cyber Essentials self-assessment fee, which remains a prerequisite. Beyond the certification fee itself, many organisations underestimate remediation costs like patching legacy systems, replacing unsupported devices, or enabling MFA across cloud services, which can meaningfully exceed the audit fee if security hygiene has been neglected.

How Long Does Certification Take?

Timelines depend far more on your starting point than on the audit itself. A well-prepared organisation with modern, well-patched infrastructure can move through the entire process in a matter of weeks. An organisation with legacy systems or inconsistent patching may need several months of remediation first. 

 

Stage Typical Duration
Scoping and preparation 1–3 weeks
Cyber Essentials self-assessment 1–3 days once submitted
Remediation of known gaps 1–8 weeks, depending on legacy systems
Cyber Essentials Plus audit booking 1–2 weeks lead time with most certification bodies
Audit and scanning 1–3 days
Retest window (if needed) Typically within 30 days of initial findings

Organisations with distributed or remote workforces, or infrastructure hosted across Microsoft 365, Azure, or AWS, sometimes need additional time to confirm cloud-based controls are configured correctly under the shared responsibility model before booking their audit date. A review from a partner delivering cloud security services can shorten this stage considerably by confirming MFA, conditional access, and configuration baselines are already aligned with CE+ expectations.

Preparing Your Business Before the Audit

Preparation is where certification is genuinely won or lost. The checklist below reflects the areas assessors consistently test.

Area Checklist Item
Devices Confirm every in-scope device is patched, supported, and correctly configured
Access Remove unused accounts; enforce MFA on all supporting cloud services
Firewalls Change default credentials; close unnecessary ports and services
Malware protection Confirm anti-malware or allow-listing is active on all endpoints
Scope Document exactly which devices, networks, and cloud services are in scope
Evidence Prepare configuration screenshots and policy evidence for the assessor

 

🔒 Security Tip

Don’t wait for audit week to check MFA coverage. Run a coverage report across Microsoft 365 or Google Workspace admin consoles now, it’s the single fastest way to spot accounts that will fail assessment.

 

Maintaining Certification After You Pass

Cyber Essentials Plus is valid for 12 months, and re-certification requires the full process again, there’s no discounted renewal fee, and controls must be demonstrably maintained throughout the certification period, not just on assessment day.

Recent scheme updates have reinforced this expectation directly: the declaration signed by a board member or director now explicitly acknowledges ongoing responsibility for maintaining every control throughout the year, not simply at the point of assessment.

  •     Keep patch management continuous, not just pre-audit.
  •     Review MFA and access control coverage quarterly.
  •     Reassess scope whenever new devices, cloud services, or remote staff are added.
  •     Track vendor end-of-life dates so unsupported software is retired before it becomes a liability.

Is Cyber Essentials Plus Worth the Investment?

For organisations bidding on government contracts, working with regulated industries, or simply wanting independently verified proof of their security posture, the answer is almost always yes. Beyond opening procurement doors, the preparation process itself typically closes real security gaps — inconsistent patching, excessive admin rights, missing MFA — that would otherwise sit unnoticed until exploited.

Certification isn’t a substitute for a full security strategy, but it’s a strong, independently verified foundation. Organisations exploring what comes next often look at Website Security to build on the momentum certification creates.

Final Thoughts: Certification as a Foundation, Not a Finish Line

Cyber Essentials Plus is more than a certification, it’s independent proof that your organization takes cybersecurity seriously. By strengthening security controls before the audit, businesses not only improve their chances of passing certification but also reduce cyber risk, build customer trust, and create a stronger foundation for long-term growth.

Elite IT Team helps organizations prepare secure, compliant IT environments that support both certification success and ongoing resilience. 

Frequently Asked Questions

What is Cyber Essentials Plus?

Cyber Essentials Plus is the higher tier of the UK government's Cyber Essentials scheme, administered by IASME on behalf of the NCSC. An independent, accredited assessor tests your organisation's IT systems directly, rather than relying on self-reported answers.

Is Cyber Essentials Plus mandatory?

It isn't mandated across all UK businesses, but it's frequently required by public sector contracts, larger commercial clients, and cyber insurers as a condition of doing business.

How much does Cyber Essentials Plus cost?

Pricing is set individually by each accredited certification body and typically scales with organisation size and device count, sitting on top of the standard Cyber Essentials self-assessment fee. Request a fixed quote based on your specific scope for an accurate figure.

Who performs the audit?

A qualified assessor from an IASME-accredited certification body carries out the audit, following the official Cyber Essentials Plus test specification.

Can small businesses get certified?

Yes. The scheme is explicitly tiered by organisation size, and a large proportion of certified organisations are SMEs, sole traders, and micro-businesses.

Get our stories delivered From
us to your inbox weekly.

Get a response tomorrow if you submit by 9pm today. If we received
after 9pm will get a reponse the following day.

Subcribe to our Newsletter

Subscribe for Updates: Stay informed about the latest investor updates, financial
results, and announcements by subscribing to our newsletter.