What Cyber Essentials Plus adds
Cyber Essentials is a self-assessment that a certification body verifies. Cyber Essentials Plus adds a technical audit in which an assessor confirms the controls are actually working. Because it is evidence-based rather than declared, it carries more weight with buyers, insurers and regulators, and it is the level specified in higher-risk public sector and defence contracts.
What the audit tests
The audit follows the IASME Cyber Essentials Plus test specification. The assessor chooses a sample of devices covering every operating system and build in scope, plus any mobile devices, and runs the following tests.
External vulnerability scan
Every internet-facing IP address in scope is scanned for open services and known vulnerabilities. Anything rated critical or high must be fixed or shown to be mitigated.
Authenticated patch scan
A credentialed vulnerability scan on each sampled device checks that the operating system and installed software are supported and patched. A critical or high vulnerability with a fix available for more than 14 days is a fail.
Email malware test
Test files are emailed to a user on each sampled device. Your email filtering or endpoint protection must block or quarantine them, or at least prevent them from running.
Browser download test
The same test files are downloaded through the browser on each sampled device. They must be blocked, quarantined or prevented from executing.
Multi-factor authentication check
The assessor confirms that MFA is enforced on the cloud services in scope, including Microsoft 365 and Google Workspace, for both administrators and standard users.
Account separation check
The assessor confirms that day-to-day user accounts cannot perform administrative tasks, and that admin accounts are not used for email or web browsing.

Ready for the Plus audit?
Tell us where you are with Cyber Essentials and we will map out the fastest route to Plus, including a pre-audit check so there are no surprises.
Book a Plus auditOr call 01506 533100
Timing and logistics
Within three months of Cyber Essentials
The Plus audit must be completed within three months of your Cyber Essentials certificate date, on the same scope. If you are renewing, we book both together so the window is never a problem.
Half a day to a day
For a typical SME with one or two device builds, the tests take between half a day and a full day. Larger or more varied estates take longer because the device sample is bigger.
Fully remote
The audit is done over a screen-sharing session with a member of your team sitting at each sampled device. No site visit and no travel costs, and it works the same for a business in Livingston or in Cornwall.
If something fails
You get a clear list of what failed and why. Fix it, and we re-test the affected items inside the certification window. Nothing is issued until every test passes.
How to pass first time
Almost every failed Plus audit comes down to one of these. We check all of them in a pre-audit so you are not paying for a re-test.
- Every device in scope on a supported operating system, with all critical and high updates applied within the last 14 days, including browsers, Office and third-party apps such as Adobe and Java
- Anti-malware enabled and updated on every device, including Macs, with browser download protection switched on
- MFA enforced for every user on every cloud service, not just administrators
- No standard users with local administrator rights, and no admins using their admin account for email
- An accurate list of internet-facing IP addresses, including any home workers' routers that forward ports
- A named person available on each sampled device during the audit
Cyber Essentials Plus pricing
Priced by organisation size. The Cyber Essentials self-assessment, from £320, is charged separately.
Cyber Essentials Plus
Technical verification audit
| Size | Price |
|---|---|
| Micro (0–9) | from £1,050 |
| Small (10–49) | from £1,250 |
| Medium (50–249) | from £1,450 |
| Large (250+) | from £1,650 |
Best for Organisations whose contracts, insurers or customers specify Plus, and anyone who wants their controls proven rather than declared.
Book a Plus auditAll prices exclude VAT. Large (250+) priced per quote based on scope. See Cyber Essentials pricing for the self-assessment bands.
Frequently asked questions
What's the difference between Cyber Essentials and Cyber Essentials Plus?
Both certify the same five controls. Cyber Essentials is a self-assessment questionnaire that a certification body verifies. Cyber Essentials Plus adds a hands-on technical audit in which an assessor scans your internet-facing systems, runs authenticated vulnerability scans on a sample of devices, tests malware protection by email and browser download, and checks MFA and account separation.
Do we need Cyber Essentials before Cyber Essentials Plus?
Yes. The Plus audit is carried out against a current Cyber Essentials certificate and must be completed within three months of it, on the same scope. If you are starting from nothing we run both together, and if you are renewing we schedule them so the window is never an issue.
How much does Cyber Essentials Plus cost?
Our Cyber Essentials Plus audit starts from £1,050 for micro organisations (0 to 9 people), from £1,250 for small (10 to 49) and from £1,450 for medium (50 to 249), excluding VAT. Large organisations are quoted on scope. The Cyber Essentials self-assessment fee, from £320, is charged separately.
How long does the Cyber Essentials Plus audit take?
For a typical SME with one or two device builds, between half a day and a full day. The assessor tests a sample of devices covering every operating system and build in scope, so larger or more varied estates take longer. Certificates are usually issued within a few days of a clean audit.
Can the Cyber Essentials Plus audit be done remotely?
Yes, all of them are. The audit is carried out over a screen-sharing session with a member of your team sitting at each sampled device. There is no site visit, so it works the same and costs the same wherever you are in the UK.
Why do businesses fail Cyber Essentials Plus?
Usually patching. A critical or high-severity vulnerability with a fix available for more than 14 days fails the authenticated scan, and third-party apps such as browsers, Adobe and Java are the common culprits. The other regular failures are unsupported operating systems, malware protection that does not block the browser download test, and MFA that is enabled but not enforced for every user.
How long is Cyber Essentials Plus valid for?
Twelve months, the same as Cyber Essentials. Renewal means passing the self-assessment again and repeating the Plus audit against the current version of the requirements.
