Cyber Essentials Plus, sorted before the assessor arrives
Plus is the same five controls as Cyber Essentials – checked by an independent assessor who tests your actual machines instead of taking your word for it. It is the level defence, NHS and larger private contracts increasingly ask for.
We find the gaps, fix them, and handle the preparation and the paperwork. Which means audit day is a formality rather than a gamble.
The same five controls. Someone else checks them.
Cyber Essentials is self-assessed. You answer the question set, an assessor reviews your answers, and you are certified. Cyber Essentials Plus takes those same five controls – firewalls, secure configuration, security update management, user access control and malware protection – and tests them on your devices.
That is why it carries more weight in a tender. Nobody is relying on what you said about your patching; an assessor has looked. The NCSC reports that organisations following the Cyber Essentials controls are 92% less likely to make a claim on their cyber insurance.
The order matters. You need to hold Cyber Essentials first, and the Plus audit has to happen within three months of that certificate. Leave it longer and you start the assessment again, so it is worth booking the two together.
What Plus gives you that self-assessment does not
Verified, not declared.
An assessor tests your devices and scans your public IP addresses. The certificate says someone independent checked, which is exactly what a procurement team is looking for.
The level bigger clients ask for.
Defence supply chains, NHS suppliers and enterprise procurement increasingly specify Plus rather than the self-assessed certificate. If a tender says Plus, only Plus will do.
Answers for bid packs and insurers.
A tested certificate settles a whole page of supplier security questions, and insurers take it seriously when they price your cover.
Gaps found before an attacker finds them.
The external scan and device testing surface unsupported software, missed patches and admin rights nobody meant to hand out. Fixing those is the real security win.
Cyber insurance included.
UK organisations turning over under £20 million that certify the whole organisation can opt in to £25,000 of cyber liability cover through the scheme, at no extra cost.
A yearly reason to stay tidy.
Certification is renewed each year, so patching, leavers and admin accounts get checked properly rather than drifting quietly out of shape.
What actually happens on audit day
The assessment can be done remotely or on site, and it is more practical than people expect. The assessor works through:
- An external scan of every public IP address, looking for open services and vulnerabilities anyone on the internet could find
- A sample of devices covering each operating system you run – servers, laptops, desktops, tablets and phones – checked for unsupported software and for high and critical patches applied within 14 days
- Malware protection tested on each sampled device
- Everyday tasks watched in real time, such as opening email attachments and downloading files, to see the protection do its job
- A check that standard user accounts cannot carry out administrator functions
Almost all of the work sits in the weeks before, which is the part we take off you.
Cyber Essentials Plus, answered
Do we need Cyber Essentials before we can do Plus?
Yes. Plus verifies the controls you certified against, so you need the self-assessed certificate first and the Plus audit has to follow within three months of it. Most businesses run the two together as one piece of work.
How long does it take?
The audit itself is short. Getting ready is the longer part, and how long depends on what we find – unsupported software, machines behind on updates or shared administrator accounts all take time to put right. We tell you what needs doing before you commit to a date.
What happens if a device fails a test?
From April 2026, if the sampled devices fail the security update test, you fix the problem and the assessor retests rather than the whole assessment failing. It is still far cheaper to find those machines beforehand, which is what the preparation work is for.
What is changing in 2026?
A new question set, Danzell, applies to assessments bought from 27 April 2026, alongside version 3.3 of the technical requirements. The marking is stricter on multi-factor authentication and on applying security updates, and the scoping wording has been simplified so any device connected to the internet is in scope.
Are home working and personal phones included?
If a device is used to access your organisation’s data or services, it is in scope – home computers, laptops that leave the office and personal phones used for work all count. Getting the scope right early is one of the things that stops an assessment going sideways.
What does it cost?
Cyber Essentials starts at £320 plus VAT and is priced in bands by organisation size. Plus is quoted separately on the size and complexity of your network, because an assessor is doing real testing. The honest bit: remediation is often the bigger number, and it is the part that actually improves your security. Ask us and we will price the whole thing up front.
“Rejuvenate IT have recently set us up for Cyber Essentials. Excellent and very friendly company offering a wide range of IT solutions.”
Find out what your Plus audit would involve
Tell us roughly how many machines you run and what the contract is asking for. We will come back with what needs fixing, what it costs and how long it takes – from our team in Bournemouth, not a call centre.
"*" indicates required fields