
Your company has reached the final stage of a government contract. The proposal scored well. The pricing is competitive. The relationship with the procurement team feels strong.
Then an email arrives: “Can you provide evidence of Cyber Essentials Plus certification?”
Suddenly the opportunity stalls, not because your services aren’t good enough, but because you can’t demonstrate that your cybersecurity controls have been independently verified. It’s an increasingly common moment, where public sector buyers, insurers, and larger commercial clients now expect suppliers to prove their cybersecurity maturity before doing business, not just claim it.
This guide walks through exactly what Cyber Essentials Plus involves: how it differs from standard Cyber Essentials, what an assessor actually tests, what it costs in 2026, why organisations fail their first attempt, and how to prepare so certification becomes a formality rather than a scramble.
Cyber Essentials was created by the UK government after analysis found that a small set of basic technical controls would have stopped the vast majority of common cyber attacks reaching organisations. It remains centred on five control areas designed to block the most frequent internet-based threats.
Standard Cyber Essentials is self-assessed: an organisation completes a questionnaire, a senior leader signs a declaration, and a qualified assessor reviews the answers. It’s a valuable baseline, but it relies on trust.
Cyber Essentials Plus removes the guesswork. An independent, IASME-accredited assessor tests your systems directly like scanning your network, sampling your devices, and confirming the controls you claimed are actually working. That distinction is exactly why more contracts, cyber insurance policies, and framework agreements now name Cyber Essentials Plus specifically rather than the base-level certification.

Both certifications assess the same five technical control areas. The difference is how compliance is verified and that difference is what gives Cyber Essentials Plus its credibility with procurement teams, insurers, and regulators.
| Aspect | Cyber Essentials | Cyber Essentials Plus |
| Assessment method | Self-assessment questionnaire (SAQ) | Independent technical audit by an accredited assessor |
| Verification level | Answers reviewed for consistency | Controls actively tested on live systems |
| Vulnerability scanning | Not required | Internal and external vulnerability scans performed |
| Device sampling | Not applicable | Representative sample of devices tested |
| Prerequisite | None | Valid Cyber Essentials certificate required first |
| Typical use case | Baseline hygiene, smaller contracts | Government contracts, insurers, higher-assurance clients |
| Did You Know?
You cannot apply for Cyber Essentials Plus in isolation. IASME requires a valid, passed Cyber Essentials self-assessment first, which is usually completed within three months of the Plus audit, because the Plus audit verifies controls that Cyber Essentials assumes are already in place. |
A Cyber Essentials Plus audit is evidence-based, not paperwork-based. It’s normally carried out remotely by a qualified assessor from an IASME-accredited certification body, although larger or more complex environments sometimes involve an on-site visit.
The assessor runs authenticated and unauthenticated vulnerability scans against every internet-facing IP address within scope, checking for missing patches, insecure services, misconfigured boundary devices, and exposed administrative interfaces. Any vulnerability scoring 7.0 or above on the CVSS v3 scale is treated as a failure unless you can demonstrate it’s a false positive.
A representative sample of end-user devices like laptops, desktops, and increasingly mobile devices, is then tested with credentialed access, confirming that patching, malware protection, and secure configuration are genuinely applied at the device level, not just described in policy documents. The assessor also observes how real users interact with email and web browsing to confirm malware protection behaves as expected.
Organisations with firewalls, VPNs, or segmented networks in scope should expect close attention to configuration. Businesses relying on legacy or unmanaged network hardware often benefit from a review by a partner offering managed network security services before booking the audit, since boundary misconfiguration is one of the most common technical failure points.
Every device connecting to the internet must sit behind a correctly configured firewall or gateway, with default administrative passwords changed and unnecessary services closed off.
Devices and software must be configured to reduce vulnerabilities — removing unused accounts and software, disabling auto-run features, and applying authentication before access is granted.
Access to data and services should be limited to what each user needs. Administrative accounts must be tightly controlled, and multi-factor authentication is increasingly expected wherever a cloud service supports it.
Anti-malware software, application allow-listing, or sandboxing must be in place across all in-scope devices, actively protecting against malicious code.
All software, operating systems, and firmware must be kept up to date, with vendor-supplied patches applied promptly. Devices that can no longer receive security updates fall out of scope and typically need replacing or isolating.
Together, these five controls are designed to stop the vast majority of common, opportunistic internet-based attacks, not sophisticated, targeted intrusions, but the everyday phishing, malware, and exploitation attempts that account for most breaches affecting UK SMEs.
The audit itself is more structured than most business owners expect. Knowing the sequence in advance removes much of the anxiety around assessment day.
| Step | What Happens |
| 1. Scoping | You and the certification body agree exactly which devices, networks, and cloud services are within scope. |
| 2. Pre-audit self-assessment | A valid, passed Cyber Essentials certificate must already be in place. |
| 3. Vulnerability scanning | Authenticated and unauthenticated scans of internet-facing IP addresses in scope. |
| 4. Device sampling | A representative sample of laptops, desktops, and servers is tested with credentialed access. |
| 5. User behaviour checks | Assessor observes malware protection and browsing/email behaviour on sampled devices. |
| 6. Evidence review | Assessor reviews findings against the CE+ test specification and CVSS scoring thresholds. |
| 7. Result & certificate | Pass, or a defined remediation window to fix and retest specific failures. |
| ✅ Best Practice
Run your own internal vulnerability scan roughly two weeks before the official audit. It surfaces exactly the same categories of issue the assessor will find, giving you time to patch before assessment day rather than during it. |
Most first-time failures aren’t caused by weak security strategy, they’re caused by small,overlooked gaps that scanning tools catch immediately. Organisations preparing for certification often begin with professional audit and compliance services to identify these gaps through a structured readiness assessment before the formal audit, rather than discovering them on the day.
| Failure Area | Typical Cause |
| Missing patches | Devices or software not updated within the expected timeframe before assessment |
| Unsupported software | Operating systems or applications that no longer receive vendor security updates |
| Weak or missing MFA | Multi-factor authentication not enabled on cloud services that support it |
| Excessive admin rights | Standard users retaining local administrator privileges unnecessarily |
| Unscoped devices | Personal or BYOD devices accessing company data without being included in scope |
| Firewall misconfiguration | Default credentials left unchanged, or unnecessary ports left open |
| ⚠ Common Mistake
IASME’s 2026 scheme update specifically flags organisations ‘applying selective updates’ immediately before assessment, patching only the sampled devices rather than the whole estate. Assessors are now scoping and evidencing this more closely, so partial preparation is increasingly easy to spot. |
| Organisation Size | Typical Cyber Essentials Plus Cost (ex. VAT) |
| Micro (0–9 employees) | From roughly £1,300–£1,500 |
| Small (10–49 employees) | From roughly £1,500–£2,000 |
| Medium (50–249 employees) | From roughly £2,000–£3,500 |
| Large (250+ employees) | Custom quote based on scope and device count; often £3,500–£8,000+ |
Unlike standard Cyber Essentials, where IASME sets a fixed, published assessment fee, Cyber Essentials Plus pricing is set individually by each accredited certification body, based on the size and complexity of your environment. Costs typically scale with organisation size, device count, and network complexity. This figure sits on top of the standard Cyber Essentials self-assessment fee, which remains a prerequisite. Beyond the certification fee itself, many organisations underestimate remediation costs like patching legacy systems, replacing unsupported devices, or enabling MFA across cloud services, which can meaningfully exceed the audit fee if security hygiene has been neglected.
Timelines depend far more on your starting point than on the audit itself. A well-prepared organisation with modern, well-patched infrastructure can move through the entire process in a matter of weeks. An organisation with legacy systems or inconsistent patching may need several months of remediation first.
| Stage | Typical Duration |
| Scoping and preparation | 1–3 weeks |
| Cyber Essentials self-assessment | 1–3 days once submitted |
| Remediation of known gaps | 1–8 weeks, depending on legacy systems |
| Cyber Essentials Plus audit booking | 1–2 weeks lead time with most certification bodies |
| Audit and scanning | 1–3 days |
| Retest window (if needed) | Typically within 30 days of initial findings |
Organisations with distributed or remote workforces, or infrastructure hosted across Microsoft 365, Azure, or AWS, sometimes need additional time to confirm cloud-based controls are configured correctly under the shared responsibility model before booking their audit date. A review from a partner delivering cloud security services can shorten this stage considerably by confirming MFA, conditional access, and configuration baselines are already aligned with CE+ expectations.
Preparation is where certification is genuinely won or lost. The checklist below reflects the areas assessors consistently test.
| Area | Checklist Item |
| Devices | Confirm every in-scope device is patched, supported, and correctly configured |
| Access | Remove unused accounts; enforce MFA on all supporting cloud services |
| Firewalls | Change default credentials; close unnecessary ports and services |
| Malware protection | Confirm anti-malware or allow-listing is active on all endpoints |
| Scope | Document exactly which devices, networks, and cloud services are in scope |
| Evidence | Prepare configuration screenshots and policy evidence for the assessor |
| 🔒 Security Tip
Don’t wait for audit week to check MFA coverage. Run a coverage report across Microsoft 365 or Google Workspace admin consoles now, it’s the single fastest way to spot accounts that will fail assessment. |
Cyber Essentials Plus is valid for 12 months, and re-certification requires the full process again, there’s no discounted renewal fee, and controls must be demonstrably maintained throughout the certification period, not just on assessment day.
Recent scheme updates have reinforced this expectation directly: the declaration signed by a board member or director now explicitly acknowledges ongoing responsibility for maintaining every control throughout the year, not simply at the point of assessment.
For organisations bidding on government contracts, working with regulated industries, or simply wanting independently verified proof of their security posture, the answer is almost always yes. Beyond opening procurement doors, the preparation process itself typically closes real security gaps — inconsistent patching, excessive admin rights, missing MFA — that would otherwise sit unnoticed until exploited.
Certification isn’t a substitute for a full security strategy, but it’s a strong, independently verified foundation. Organisations exploring what comes next often look at Website Security to build on the momentum certification creates.
Cyber Essentials Plus is more than a certification, it’s independent proof that your organization takes cybersecurity seriously. By strengthening security controls before the audit, businesses not only improve their chances of passing certification but also reduce cyber risk, build customer trust, and create a stronger foundation for long-term growth.
Elite IT Team helps organizations prepare secure, compliant IT environments that support both certification success and ongoing resilience.
Get a response tomorrow if you submit by 9pm today. If we received
after 9pm will get a reponse the following day.