Cyber Essentials Plus is the higher-assurance level of the UK Government-backed Cyber Essentials certification scheme. It confirms that an organisation has implemented the same five technical controls required for Cyber Essentials, but adds independent technical testing by a qualified assessor.
While standard Cyber Essentials is based primarily on a verified self-assessment, Cyber Essentials Plus requires the organisation’s systems and security controls to be tested directly. This gives clients, insurers, regulators, and commercial partners greater confidence that the controls described in the assessment are operating in practice.
Cyber Essentials Plus focuses on protection against common internet-based cyber threats. It does not cover every aspect of cyber security, but it provides independently verified evidence that fundamental controls relating to firewalls, secure configuration, security updates, access control, and malware protection have been implemented.
Why Cyber Essentials Plus Is Important for Businesses
Cyber Essentials Plus is important because having security policies or software in place does not automatically prove that controls are configured correctly. Independent testing helps identify differences between what an organisation believes is protected and what is actually visible across its devices, networks, servers, and cloud services.
For businesses, particularly SMEs and regulated firms in London, Cyber Essentials Plus can provide valuable assurance during client due diligence, supplier onboarding, tender processes, cyber insurance reviews, and security questionnaires. A growing number of organisations also require suppliers to hold Cyber Essentials certification before they can bid for work.
Key benefits of Cyber Essentials Plus include:
- Independent verification of essential cyber security controls
- Stronger protection against common internet-based attacks
- Better visibility of unsupported software and missing security updates
- Improved control over user accounts and administrative privileges
- Greater confidence for clients, insurers, and business partners
- Better readiness for tenders and supplier security assessments
- Clear evidence that technical controls have been tested
- A practical foundation for wider cyber security improvement
These benefits help organisations move beyond self-declared security and towards a more independently assessed and defensible security position.
How Cyber Essentials Plus Works
Cyber Essentials Plus uses the same security requirements as Cyber Essentials. The main difference is the level of assurance: an authorised Certification Body performs a technical audit to check whether the controls are implemented effectively across the agreed certification scope.
The organisation normally completes the Cyber Essentials verified self-assessment before progressing to the Plus assessment. The scope of the Cyber Essentials Plus audit should match the scope covered by the associated Cyber Essentials certification.
A typical Cyber Essentials Plus process includes:
- Defining which systems, users, devices, networks, and cloud services are in scope
- Completing the Cyber Essentials verified self-assessment
- Correcting known control or configuration gaps
- Selecting an authorised Cyber Essentials Certification Body
- Agreeing how the technical audit will be delivered
- Providing access to the systems and devices selected for testing
- Completing internal and external vulnerability checks
- Testing security controls across a representative sample
- Remediating issues identified during the assessment
- Receiving certification after all required tests have been passed
The assessment includes a representative selection of user devices, internet gateways, and relevant internet-facing servers. Assessors typically test a random sample of in-scope systems and determine whether additional testing is needed based on the findings.
Cyber Essentials Plus certification is valid for 12 months. Organisations must renew annually to maintain an active certificate and demonstrate that controls continue to meet the current requirements.
The Five Cyber Essentials Plus Technical Controls
Cyber Essentials Plus assesses the same five technical controls used by the standard Cyber Essentials certification. These controls are designed to reduce exposure to the most common internet-based cyber attacks.
The five Cyber Essentials Plus controls are:
- Firewalls: Security boundaries must control connections between devices, networks, and the internet. Unnecessary services and publicly accessible interfaces should be restricted.
- Secure Configuration: Devices, operating systems, cloud services, and applications should be configured securely. Default accounts, unnecessary applications, and insecure settings should be removed or disabled.
- Security Update Management: Supported software must receive the security fixes required by the scheme. Updates should be applied consistently across the full certification scope rather than only to selected devices.
- User Access Control: Access should be limited according to business need. Administrative privileges must be controlled, and authentication requirements should protect accounts from unauthorised access.
- Malware Protection: Organisations must use appropriate controls to prevent malicious software from executing or causing damage. These may include anti-malware software, application allow-listing, and restrictions on untrusted applications.
Together, these controls provide a minimum technical security baseline. Cyber Essentials Plus independently tests whether that baseline is working across the assessed environment.
Common Cyber Essentials Plus Readiness Challenges
Cyber Essentials Plus can reveal control gaps that were not identified during the initial self-assessment. This often happens because the technical audit examines real devices, configurations, software versions, network exposure, and security behaviour.
Common Cyber Essentials Plus readiness challenges include:
- Unsupported operating systems or applications
- Missing security updates on in-scope devices
- Inconsistent patching across different device groups
- Unclear or inaccurate certification scope
- Devices that are missing from the asset inventory
- Users retaining unnecessary administrator privileges
- Weak authentication or incomplete Multi-Factor Authentication coverage
- Insecure firewall rules or exposed network services
- Default accounts or configurations remaining active
- Personal and remote-working devices being managed inconsistently
- Anti-malware controls not working across all supported devices
- Cloud platforms being configured differently from internal systems
- Limited evidence showing how controls are maintained
The current Cyber Essentials requirements are reviewed and updated regularly, so organisations should prepare against the latest applicable version rather than relying on answers or configurations used in a previous year.
Best Practices for Cyber Essentials Plus Certification
Preparing for Cyber Essentials Plus should begin before the technical audit is booked. Organisations should first confirm that the information submitted during the Cyber Essentials self-assessment accurately reflects the full in-scope environment.
Best practices for Cyber Essentials Plus certification include:
- Creating an accurate inventory of devices, software, and cloud services
- Defining and documenting the assessment scope clearly
- Reviewing the latest Cyber Essentials technical requirements
- Removing or replacing unsupported software
- Applying required security updates across all in-scope systems
- Checking patch compliance rather than relying on update policies alone
- Restricting local and cloud administrator privileges
- Enforcing strong authentication and Multi-Factor Authentication
- Reviewing firewall rules and internet-facing services
- Testing malware protection on different device types
- Checking remote-working and personally owned devices
- Reviewing mobile devices and cloud applications within scope
- Running readiness checks before the formal technical audit
- Keeping evidence of configurations and remediation work
- Assigning clear responsibility for maintaining the controls
The organisation should remediate issues across the entire certification scope, not only on the devices likely to be sampled. From April 2026, updated assessment procedures strengthened checks around consistent update management and introduced additional retesting where sampled devices fail.
Following these practices can reduce the risk of avoidable assessment failures and help ensure that Cyber Essentials Plus reflects the organisation’s genuine security position.
Conclusion: Why Cyber Essentials Plus Matters
Cyber Essentials Plus provides a higher level of assurance than standard Cyber Essentials because essential cyber security controls are tested independently. It helps confirm that controls are not only described in a questionnaire but are operating across real systems and devices.
For London SMEs and regulated firms, Cyber Essentials Plus can support stronger cyber resilience, client confidence, supplier assurance, tender requirements, and readiness for insurance or compliance reviews. When maintained as part of a broader security programme, it helps an organisation move from self-declared protection to a more independently verified and evidence-led cyber security position.