Cyber Essentials Plus

Understand how this standard guards your organisation against the most common cyber threats and helps demonstrate your commitment to cyber security

The five technical controls

Cyber Essentials Plus tests against five categories of technical control. These are not aspirational best practices, they are specific, testable requirements.

Firewalls and internet gateways – Boundary firewalls and internet gateways must be configured to prevent unauthorised inbound access. Default admin passwords must be changed. Only necessary ports and services should be exposed. The assessor scans external-facing systems to confirm that the attack surface is minimised.

Secure configuration – Systems must be configured to reduce vulnerabilities. Default accounts must be removed or disabled. Unnecessary software must be uninstalled. Auto-run features must be disabled. The assessor checks that devices and software are hardened against known attack vectors.

User access control – User accounts must follow least-privilege principles. Admin accounts must only be used for administrative tasks. Each user must have a unique account. Multi-factor authentication is required for cloud services and remote access. The assessor verifies access policies and tests account configurations.

Malware protection – Anti-malware software must be installed and kept up to date on all in-scope devices. Alternatively, organisations can demonstrate equivalent protection through application whitelisting or sandboxing. The assessor confirms that malware defences are active and current.

Patch management – Operating systems and applications must be patched within 14 days of a critical or high-risk security update being released. Unsupported software must be removed from scope. The assessor checks patch levels across a sample of devices and verifies that the patching process is effective.

Cyber Essentials vs Cyber Essentials Plus

Cyber EssentialsCyber Essentials Plus
Assessment methodSelf-assessment questionnaireIndependent technical audit
VerificationResponses reviewed by a certification bodyHands-on testing by a qualified assessor
ScopeAll internet-connected devices and softwareSame scope, verified through scanning and testing
Validity12 months12 months
CostFrom £320 via IASME + VAT (self-assessment fee)From £1,900 + VAT (includes technical testing)
CredibilityDemonstrates intentDemonstrates verified capability
Government requirementAccepted for some contractsRequired for contracts involving personal data or sensitive information

The basic certificate is a useful starting point, but it is self-declared. The Plus certification carries more weight because an independent assessor has confirmed that the controls actually work. For organisations bidding on government contracts or working in supply chains where security assurance matters, Plus is the standard expected.

Who needs Cyber Essentials Plus

Cyber Essentials Plus is mandatory for UK government contracts that involve handling personal information, providing certain ICT products or services, or delivering to the Ministry of Defence. Beyond government procurement, it is increasingly expected by large enterprises conducting supply chain due diligence, insurers assessing cyber risk, and regulated sectors where demonstrable security hygiene is a condition of doing business.

The NCSC reports that Cyber Essentials controls, properly implemented, protect against approximately 80% of common cyber attacks. For organisations of any size, the certification process itself is valuable. It forces a structured review of basic security controls that many organisations assume are in place but have never verified.

Cyberfort and Cyber Essentials Plus

We deliver Cyber Essentials and Cyber Essentials Plus certification services. Our process includes a pre-assessment gap analysis to identify issues before the formal audit, the hands-on technical assessment itself, and remediation guidance for any failures. We also help organisations prepare for Cyber Essentials Plus as part of broader security improvement programmes, ensuring that the five controls are embedded in ongoing operations rather than treated as a one-off compliance exercise. For organisations building towards more comprehensive frameworks such as ISO 27001 or the NCSC CAF, Cyber Essentials Plus provides a solid baseline to build from.

Start your Cyber Essentials Plus certification →

Related glossary terms

  • NCSC CAF – the UK framework for assessing cyber resilience in critical national infrastructure, a step beyond Cyber Essentials
  • SOC 2 – US-originated assurance framework often required alongside Cyber Essentials for international contracts
  • Virtual CISO – fractional security leadership that can oversee Cyber Essentials implementation and ongoing compliance
  • G-Cloud – UK government procurement framework where Cyber Essentials certification is a supplier requirement
  • Secure by Design – the NCSC principle of building security into systems from the outset, complementing the Cyber Essentials control set

External references

Frequently asked questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment questionnaire where the organisation declares its compliance with five technical controls. Cyber Essentials Plus adds independent technical verification. A qualified assessor scans and tests the organisation’s systems to confirm that the controls are actually in place and working. Plus provides stronger assurance because the controls have been independently validated, not just self-reported.

Is Cyber Essentials Plus mandatory?

It is mandatory for certain UK government contracts, particularly those involving personal data, ICT services, or Ministry of Defence work. Outside government procurement, it is not legally required but is increasingly expected by enterprise customers, insurers, and regulated industries as evidence of baseline cyber hygiene. Many supply chain security assessments now treat it as a minimum requirement.

How long does Cyber Essentials Plus certification take?

The technical assessment itself typically takes one to three days depending on the size and complexity of the organisation’s IT estate. However, organisations should allow four to six weeks for preparation, including the gap analysis, remediation of any issues identified, and scheduling the assessment. The certificate is valid for 12 months and must be renewed annually.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.