Cyber Essentials Plus: what it tests, and what actually fails.
Cyber Essentials Plus is the audited tier of the UK government’s Cyber Essentials scheme. The five controls are identical to the self-assessed certificate — what changes is that a qualified assessor tests them on your actual machines rather than reading your answers. Most organisations that fail do so for one of a small number of predictable reasons, and one of them fails you outright. This page covers the requirements, the cost, what the assessor does on the day, and what a certificate is worth when a supplier sends you one.
Last reviewed
What is Cyber Essentials Plus?
Cyber Essentials is the UK government’s baseline security certification, owned by the NCSC and delivered by IASME as its official delivery partner. It comes in two tiers, and the difference between them is evidence, not scope.
The base certificate is a verified self-assessment: you answer a question set about how your organisation is configured, and an assessor marks your answers. Nobody looks at your estate. Cyber Essentials Plus starts from that same questionnaire and adds a technical audit — an assessor runs internal and external vulnerability scans and hands-on tests against a sample of your real devices to confirm the controls you claimed are genuinely in place.
IASME states the position plainly: “The controls for Cyber Essentials and Cyber Essentials Plus are exactly the same but the level of assurance is different.” That distinction is the whole point. A self-assessment tells you what an organisation believes about itself. Plus tells you what an assessor found.
Both certificates expire after 12 months and are annually renewable. IASME removes organisations from its certified list if they have not certified in the past year — which is worth knowing if you are relying on a supplier’s certificate rather than checking its date.
Cyber Essentials Plus requirements the five controls
The requirements are the five technical controls, unchanged between the two tiers. For Plus, each one has to survive contact with an assessor.
- FirewallsEvery device is protected by a correctly configured firewall — a boundary firewall at the network edge, or a host-based one on devices used on untrusted networks. Default administrative passwords changed, and no unauthenticated inbound services exposed without a documented business case.
- Secure configurationDevices and software are set up to reduce inherent vulnerability: unnecessary accounts and software removed, default passwords changed, auto-run disabled, and no unnecessary services reachable from the internet.
- Security update managementEverything in scope is supported by its vendor and patched. High-risk and critical updates must be applied within 14 days of release. This is the control that catches most organisations out, because it applies to every operating system, browser, browser plugin and application in scope — not just the servers.
- User access controlAccounts are individual, granted through an approval process, and removed when people leave. Administrative privilege is separated from day-to-day accounts, and multi-factor authentication is applied to cloud services.
- Malware protectionAnti-malware is active and up to date on in-scope devices, or the equivalent is achieved through application allow-listing. The assessor will test this rather than take your word for it.
What the assessor actually does
The audit is narrower than most people expect, and it is a sample rather than a census.
IASME defines the in-scope estate for the Plus audit as three things:
- a representative set of user devices
- all internet gateways
- all servers with services accessible to unauthenticated internet users
Against that estate the assessor runs an internal and external vulnerability scan, then tests a random sample of systems — IASME puts this at typically around 10 per cent — before deciding whether further testing is needed. That last clause matters: a sample that comes back messy expands the audit rather than ending it.
The audit can be run remotely or in person, at the certification body’s discretion.
One piece of sequencing is worth planning around. The Cyber Essentials question set forms part of the Plus process, but if you achieved the verified self-assessment less than three months before certifying to Plus, you do not repeat the questionnaire stage. Leave it longer and you do it twice. Most organisations should treat the two as a single project rather than two separate events.
Why assessments fail and how to not be one
The failure modes are consistent, and mostly they are not sophisticated. These are the ones worth checking before you book.
- Unsupported software anywhere in scope — an automatic failIASME is unambiguous: “Any company using unsupported software in the scope of the assessment will fail to achieve Cyber Essentials certification.” Not a finding, not a discussion — a fail. An end-of-life operating system on one forgotten machine, an unsupported database version, an old PHP runtime on a web server. Inventory first, book second.
- The 14-day patch window missed on something nobody was watchingServers are usually patched. Browser plugins, PDF readers, developer tooling and the laptop of someone on long-term leave usually are not. The control applies to all of it, and a vulnerability scan finds it immediately.
- MFA missing on a cloud service somebody forgot was in scopeCloud services are in scope, and multi-factor authentication is required on them. The gap is rarely the main identity provider — it is the standalone SaaS tool a team bought on a card, which nobody mapped.
- Administrative accounts used for everyday workSeparation of administrative privilege is explicit. An admin account used to read email and browse the web fails the control however strong its password is.
- Scope drawn to flatter, then contradicted by the scanScope can legitimately be a defined sub-network, but it has to be honest and coherent. A scope that excludes the awkward estate tends to be undone by an external scan that finds the excluded assets on the same perimeter.
The two-day rule
Cyber Essentials Plus cost
The base Cyber Essentials fee is set by IASME and banded by organisation size, using the UK government’s employee-count definitions. Cyber Essentials Plus is not on a published price list.
| Organisation size | Employees | Cyber Essentials fee |
|---|---|---|
| Micro | 0–9 | £320 + VAT |
| Small | 10–49 | £440 + VAT |
| Medium | 50–249 | £500 + VAT |
| Large | 250+ | £600 + VAT |
| Cyber Essentials Plus | Any | Quoted individually |
Fees as published by IASME and verified on 23 August 2026; check iasme.co.uk before relying on them. Plus is quoted per organisation because it consumes assessor time that scales with the size and complexity of the network — IASME will send you quotes from three certification bodies. Budget for the base fee and the Plus quote as separate line items, plus the two costs that are easy to forget: remediation work before the audit, and a fresh assessment fee if you fail and cannot fix it inside the two-day window.
Cyber Essentials vs Cyber Essentials Plus
Same controls, same question set, same 12-month validity. The difference is who checked.
- You answer the question set; an assessor marks the answers
- No vulnerability scan required at this level
- Published fee, £320–£600 + VAT by organisation size
- Evidence is your own attestation
- Enough for many public-sector procurement thresholds
- Everything above, plus a hands-on technical audit
- Internal and external vulnerability scans
- Roughly 10% of in-scope systems sampled and tested
- Evidence is an assessor’s findings on your real estate
- Required where a contract specifies audited assurance
What to demand when a supplier holds one the part buyers get wrong
A Cyber Essentials Plus certificate is genuinely meaningful evidence. It is also routinely over-read.
If you are assessing a supplier who has sent you a certificate, four questions separate real assurance from a PDF:
- What was in scope? The certificate does not state it. A company can certify a defined sub-network, and the system you are buying may sit outside it. Ask for the scope statement, not the certificate.
- When was it issued? Certification lasts 12 months, and IASME delists organisations that have not certified within the year. A certificate dated 14 months ago is evidence of a state that has since expired.
- Plus or self-assessed? The two are visually similar and frequently conflated in supplier questionnaires. Only one of them involved anyone testing anything.
- What has changed since? This is the real limitation. The certificate describes one day. Nothing in the scheme monitors the supplier for the following 364 — a new internet-facing service, a lapsed patch cycle or an acquisition can undo it the week after the audit.
That last point is not a criticism of the scheme; it is a description of what annual point-in-time certification is for. It sets a floor. It is not a monitoring control, and treating it as one is how organisations end up surprised by suppliers who were, on paper, certified.
Cyber Essentials Plus, answered.
How long does Cyber Essentials Plus last?
Do I need Cyber Essentials before Cyber Essentials Plus?
How much does Cyber Essentials Plus cost?
What is tested in a Cyber Essentials Plus audit?
What fails a Cyber Essentials Plus assessment automatically?
What happens if we fail?
Does Cyber Essentials Plus cover our suppliers?
Related reading.
Certificates describe one day. See the rest.
Book a 30-minute call and we will produce a complete external posture report on one of your certified suppliers — scored, evidenced and dated today.