Cyber Essentials Plus

Cyber Essentials Plus: what it tests, and what actually fails.

Cyber Essentials Plus is the audited tier of the UK government’s Cyber Essentials scheme. The five controls are identical to the self-assessed certificate — what changes is that a qualified assessor tests them on your actual machines rather than reading your answers. Most organisations that fail do so for one of a small number of predictable reasons, and one of them fails you outright. This page covers the requirements, the cost, what the assessor does on the day, and what a certificate is worth when a supplier sends you one.

Last reviewed

What is Cyber Essentials Plus?

Cyber Essentials is the UK government’s baseline security certification, owned by the NCSC and delivered by IASME as its official delivery partner. It comes in two tiers, and the difference between them is evidence, not scope.

The base certificate is a verified self-assessment: you answer a question set about how your organisation is configured, and an assessor marks your answers. Nobody looks at your estate. Cyber Essentials Plus starts from that same questionnaire and adds a technical audit — an assessor runs internal and external vulnerability scans and hands-on tests against a sample of your real devices to confirm the controls you claimed are genuinely in place.

IASME states the position plainly: “The controls for Cyber Essentials and Cyber Essentials Plus are exactly the same but the level of assurance is different.” That distinction is the whole point. A self-assessment tells you what an organisation believes about itself. Plus tells you what an assessor found.

Both certificates expire after 12 months and are annually renewable. IASME removes organisations from its certified list if they have not certified in the past year — which is worth knowing if you are relying on a supplier’s certificate rather than checking its date.

Cyber Essentials Plus requirements the five controls

The requirements are the five technical controls, unchanged between the two tiers. For Plus, each one has to survive contact with an assessor.

  • Firewalls
    Every device is protected by a correctly configured firewall — a boundary firewall at the network edge, or a host-based one on devices used on untrusted networks. Default administrative passwords changed, and no unauthenticated inbound services exposed without a documented business case.
  • Secure configuration
    Devices and software are set up to reduce inherent vulnerability: unnecessary accounts and software removed, default passwords changed, auto-run disabled, and no unnecessary services reachable from the internet.
  • Security update management
    Everything in scope is supported by its vendor and patched. High-risk and critical updates must be applied within 14 days of release. This is the control that catches most organisations out, because it applies to every operating system, browser, browser plugin and application in scope — not just the servers.
  • User access control
    Accounts are individual, granted through an approval process, and removed when people leave. Administrative privilege is separated from day-to-day accounts, and multi-factor authentication is applied to cloud services.
  • Malware protection
    Anti-malware is active and up to date on in-scope devices, or the equivalent is achieved through application allow-listing. The assessor will test this rather than take your word for it.

What the assessor actually does

The audit is narrower than most people expect, and it is a sample rather than a census.

IASME defines the in-scope estate for the Plus audit as three things:

  • a representative set of user devices
  • all internet gateways
  • all servers with services accessible to unauthenticated internet users

Against that estate the assessor runs an internal and external vulnerability scan, then tests a random sample of systems — IASME puts this at typically around 10 per cent — before deciding whether further testing is needed. That last clause matters: a sample that comes back messy expands the audit rather than ending it.

The audit can be run remotely or in person, at the certification body’s discretion.

One piece of sequencing is worth planning around. The Cyber Essentials question set forms part of the Plus process, but if you achieved the verified self-assessment less than three months before certifying to Plus, you do not repeat the questionnaire stage. Leave it longer and you do it twice. Most organisations should treat the two as a single project rather than two separate events.

Why assessments fail and how to not be one

The failure modes are consistent, and mostly they are not sophisticated. These are the ones worth checking before you book.

  • Unsupported software anywhere in scope — an automatic fail
    IASME is unambiguous: “Any company using unsupported software in the scope of the assessment will fail to achieve Cyber Essentials certification.” Not a finding, not a discussion — a fail. An end-of-life operating system on one forgotten machine, an unsupported database version, an old PHP runtime on a web server. Inventory first, book second.
  • The 14-day patch window missed on something nobody was watching
    Servers are usually patched. Browser plugins, PDF readers, developer tooling and the laptop of someone on long-term leave usually are not. The control applies to all of it, and a vulnerability scan finds it immediately.
  • MFA missing on a cloud service somebody forgot was in scope
    Cloud services are in scope, and multi-factor authentication is required on them. The gap is rarely the main identity provider — it is the standalone SaaS tool a team bought on a card, which nobody mapped.
  • Administrative accounts used for everyday work
    Separation of administrative privilege is explicit. An admin account used to read email and browse the web fails the control however strong its password is.
  • Scope drawn to flatter, then contradicted by the scan
    Scope can legitimately be a defined sub-network, but it has to be honest and coherent. A scope that excludes the awkward estate tends to be undone by an external scan that finds the excluded assets on the same perimeter.

The two-day rule

If you fail, you get two working days. IASME allows two working days to review the assessor’s feedback, fix simple issues and update your answers, after which the assessor takes another look at no extra charge. Miss that window and you reapply and pay the assessment fee again. Two days is enough for a configuration change and nowhere near enough for a migration off unsupported software — which is why the inventory happens first.

Cyber Essentials Plus cost

The base Cyber Essentials fee is set by IASME and banded by organisation size, using the UK government’s employee-count definitions. Cyber Essentials Plus is not on a published price list.

Organisation sizeEmployeesCyber Essentials fee
Micro0–9£320 + VAT
Small10–49£440 + VAT
Medium50–249£500 + VAT
Large250+£600 + VAT
Cyber Essentials PlusAnyQuoted individually

Fees as published by IASME and verified on 23 August 2026; check iasme.co.uk before relying on them. Plus is quoted per organisation because it consumes assessor time that scales with the size and complexity of the network — IASME will send you quotes from three certification bodies. Budget for the base fee and the Plus quote as separate line items, plus the two costs that are easy to forget: remediation work before the audit, and a fresh assessment fee if you fail and cannot fix it inside the two-day window.

Cyber Essentials vs Cyber Essentials Plus

Same controls, same question set, same 12-month validity. The difference is who checked.

Self-assessed
Cyber Essentials
  • You answer the question set; an assessor marks the answers
  • No vulnerability scan required at this level
  • Published fee, £320–£600 + VAT by organisation size
  • Evidence is your own attestation
  • Enough for many public-sector procurement thresholds
Independently audited
Cyber Essentials Plus
  • Everything above, plus a hands-on technical audit
  • Internal and external vulnerability scans
  • Roughly 10% of in-scope systems sampled and tested
  • Evidence is an assessor’s findings on your real estate
  • Required where a contract specifies audited assurance

What to demand when a supplier holds one the part buyers get wrong

A Cyber Essentials Plus certificate is genuinely meaningful evidence. It is also routinely over-read.

If you are assessing a supplier who has sent you a certificate, four questions separate real assurance from a PDF:

  • What was in scope? The certificate does not state it. A company can certify a defined sub-network, and the system you are buying may sit outside it. Ask for the scope statement, not the certificate.
  • When was it issued? Certification lasts 12 months, and IASME delists organisations that have not certified within the year. A certificate dated 14 months ago is evidence of a state that has since expired.
  • Plus or self-assessed? The two are visually similar and frequently conflated in supplier questionnaires. Only one of them involved anyone testing anything.
  • What has changed since? This is the real limitation. The certificate describes one day. Nothing in the scheme monitors the supplier for the following 364 — a new internet-facing service, a lapsed patch cycle or an acquisition can undo it the week after the audit.

That last point is not a criticism of the scheme; it is a description of what annual point-in-time certification is for. It sets a floor. It is not a monitoring control, and treating it as one is how organisations end up surprised by suppliers who were, on paper, certified.

Cyber Essentials Plus, answered.

How long does Cyber Essentials Plus last?
Twelve months. Both Cyber Essentials and Cyber Essentials Plus certificates expire after a year and are annually renewable, and IASME removes organisations from its certified list if they have not certified within the past year.
Do I need Cyber Essentials before Cyber Essentials Plus?
The Cyber Essentials question set is part of the Plus process, so in effect yes. If you achieved the verified self-assessment less than three months before certifying to Plus, you do not have to repeat the questionnaire stage. Beyond three months you do it again.
How much does Cyber Essentials Plus cost?
It is quoted individually rather than published, because the audit consumes assessor time that scales with the size and complexity of your network. IASME will return quotes from three certification bodies. The base Cyber Essentials fee is published and banded: £320 + VAT for micro organisations up to £600 + VAT for those with 250 or more employees.
What is tested in a Cyber Essentials Plus audit?
An internal and external vulnerability scan, then hands-on testing of a random sample — typically around 10 per cent — of in-scope systems: a representative set of user devices, all internet gateways, and all servers with services reachable by unauthenticated internet users. If the sample raises concerns the assessor can extend the testing.
What fails a Cyber Essentials Plus assessment automatically?
Unsupported software anywhere in the scope of the assessment. IASME treats it as an outright fail rather than a finding, so an end-of-life operating system on a single in-scope machine is enough.
What happens if we fail?
You get two working days to review the assessor’s feedback, correct simple issues and resubmit, and the assessor re-checks at no extra charge. If you still fail after that, you reapply and pay the assessment fee again.
Does Cyber Essentials Plus cover our suppliers?
No. It certifies your own in-scope estate. Your suppliers’ security is assessed separately, and a supplier’s own certificate covers only whatever scope they defined, on the day they were audited.

Certificates describe one day. See the rest.

Book a 30-minute call and we will produce a complete external posture report on one of your certified suppliers — scored, evidenced and dated today.