Cyber Essentials Plus
Understand how this standard guards your organisation against the most common cyber threats and helps demonstrate your commitment to cyber security
The five technical controls
Cyber Essentials Plus tests against five categories of technical control. These are not aspirational best practices, they are specific, testable requirements.
Firewalls and internet gateways – Boundary firewalls and internet gateways must be configured to prevent unauthorised inbound access. Default admin passwords must be changed. Only necessary ports and services should be exposed. The assessor scans external-facing systems to confirm that the attack surface is minimised.
Secure configuration – Systems must be configured to reduce vulnerabilities. Default accounts must be removed or disabled. Unnecessary software must be uninstalled. Auto-run features must be disabled. The assessor checks that devices and software are hardened against known attack vectors.
User access control – User accounts must follow least-privilege principles. Admin accounts must only be used for administrative tasks. Each user must have a unique account. Multi-factor authentication is required for cloud services and remote access. The assessor verifies access policies and tests account configurations.
Malware protection – Anti-malware software must be installed and kept up to date on all in-scope devices. Alternatively, organisations can demonstrate equivalent protection through application whitelisting or sandboxing. The assessor confirms that malware defences are active and current.
Patch management – Operating systems and applications must be patched within 14 days of a critical or high-risk security update being released. Unsupported software must be removed from scope. The assessor checks patch levels across a sample of devices and verifies that the patching process is effective.
Cyber Essentials vs Cyber Essentials Plus
| Cyber Essentials | Cyber Essentials Plus | |
| Assessment method | Self-assessment questionnaire | Independent technical audit |
| Verification | Responses reviewed by a certification body | Hands-on testing by a qualified assessor |
| Scope | All internet-connected devices and software | Same scope, verified through scanning and testing |
| Validity | 12 months | 12 months |
| Cost | From £320 via IASME + VAT (self-assessment fee) | From £1,900 + VAT (includes technical testing) |
| Credibility | Demonstrates intent | Demonstrates verified capability |
| Government requirement | Accepted for some contracts | Required for contracts involving personal data or sensitive information |
The basic certificate is a useful starting point, but it is self-declared. The Plus certification carries more weight because an independent assessor has confirmed that the controls actually work. For organisations bidding on government contracts or working in supply chains where security assurance matters, Plus is the standard expected.
Who needs Cyber Essentials Plus
Cyber Essentials Plus is mandatory for UK government contracts that involve handling personal information, providing certain ICT products or services, or delivering to the Ministry of Defence. Beyond government procurement, it is increasingly expected by large enterprises conducting supply chain due diligence, insurers assessing cyber risk, and regulated sectors where demonstrable security hygiene is a condition of doing business.
The NCSC reports that Cyber Essentials controls, properly implemented, protect against approximately 80% of common cyber attacks. For organisations of any size, the certification process itself is valuable. It forces a structured review of basic security controls that many organisations assume are in place but have never verified.
Cyberfort and Cyber Essentials Plus
We deliver Cyber Essentials and Cyber Essentials Plus certification services. Our process includes a pre-assessment gap analysis to identify issues before the formal audit, the hands-on technical assessment itself, and remediation guidance for any failures. We also help organisations prepare for Cyber Essentials Plus as part of broader security improvement programmes, ensuring that the five controls are embedded in ongoing operations rather than treated as a one-off compliance exercise. For organisations building towards more comprehensive frameworks such as ISO 27001 or the NCSC CAF, Cyber Essentials Plus provides a solid baseline to build from.
Start your Cyber Essentials Plus certification →
Related glossary terms
- NCSC CAF – the UK framework for assessing cyber resilience in critical national infrastructure, a step beyond Cyber Essentials
- SOC 2 – US-originated assurance framework often required alongside Cyber Essentials for international contracts
- Virtual CISO – fractional security leadership that can oversee Cyber Essentials implementation and ongoing compliance
- G-Cloud – UK government procurement framework where Cyber Essentials certification is a supplier requirement
- Secure by Design – the NCSC principle of building security into systems from the outset, complementing the Cyber Essentials control set
External references
- Wikipedia: Cyber Essentials — overview and history of the scheme
- Wikidata: Q18202498 — canonical entity identifier
- NCSC: Cyber Essentials — official scheme guidance from the National Cyber Security Centre
- IASME Consortium — the scheme operator responsible for certification body accreditation
Frequently asked questions
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a self-assessment questionnaire where the organisation declares its compliance with five technical controls. Cyber Essentials Plus adds independent technical verification. A qualified assessor scans and tests the organisation’s systems to confirm that the controls are actually in place and working. Plus provides stronger assurance because the controls have been independently validated, not just self-reported.
Is Cyber Essentials Plus mandatory?
It is mandatory for certain UK government contracts, particularly those involving personal data, ICT services, or Ministry of Defence work. Outside government procurement, it is not legally required but is increasingly expected by enterprise customers, insurers, and regulated industries as evidence of baseline cyber hygiene. Many supply chain security assessments now treat it as a minimum requirement.
How long does Cyber Essentials Plus certification take?
The technical assessment itself typically takes one to three days depending on the size and complexity of the organisation’s IT estate. However, organisations should allow four to six weeks for preparation, including the gap analysis, remediation of any issues identified, and scheduling the assessment. The certificate is valid for 12 months and must be renewed annually.
Awards and Accreditations




















Contact Us
Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX
