AIS Technology Logo
Cybersecurity specialist reviewing network security

Cyber Essentials Plus

Somebody asked you for Plus.
Here is what actually happens.

Plus is the same five controls as basic Cyber Essentials, tested by an assessor instead of declared by you. Most of the anxiety is about the audit day. Most of the work is what you fix before it.

The audit, stage by stage

What the assessor actually does

Five stages, and what you need to have ready for each. Nothing here is a surprise on the day if you have read this first.

Stage 1 of 5

Agreeing what gets tested

Before anything is scanned, you and the assessor agree the scope: which offices, which cloud services, which devices, and whether home and personal devices are in. A sample of user devices is then selected to represent each different build you run, rather than every machine you own. The sample is set from IASME's test specification and agreed with your assessor before testing starts.

Have ready

  • A device list covering every operating system and build in use
  • A list of cloud services, including the ones a department bought without telling IT
  • Your external IP addresses

Which one do you need

Basic and Plus, side by side

If nobody has specifically asked you for Plus, basic certification is almost always the right place to start.

How it is verifiedBasicYou answer the question set and a certification body reviews itPlusAn assessor independently tests the controls on your actual systems
Technical testingBasicNonePlusExternal and authenticated vulnerability scans, malware tests, device checks
Typical costBasic£320 to £600 + VAT, set by IASME on headcountPlusFrom around £1,400 + VAT, priced on size and complexity
PrerequisiteBasicNonePlusA valid basic certificate, with 3 months to complete
Insurance includedBasic£25,000 for eligible organisationsPlus£25,000 for eligible organisations
Usually needed byBasicMost SMEs, first certification, general supplier assurancePlusGovernment contracts, financial services, enterprise supply chains

Work out your exact fee, including both levels, on the Cyber Essentials cost calculator.

Before you book

The three month clock is the real risk

You have three months from your basic certificate to complete Plus. Businesses rarely fail Plus outright. They run out of time fixing what the first scan found, and have to start again at basic.

  • Scan first, book second

    We run the same kind of authenticated scan the assessor will, before the clock starts. What it finds is your actual work list, and you find out in week one rather than week ten.

  • Fix the slow things early

    Replacing end of life kit and untangling shared admin accounts takes weeks and often needs budget. MFA and patching policy take hours. Start with the ones that need a purchase order.

  • Then certify both together

    With remediation done, basic and Plus can run back to back comfortably inside the window, and the audit day becomes a formality rather than an inspection.

We take businesses across London and Essex through Plus as a managed piece of work, and for managed IT clients most of the controls are already in place, because patching, MFA and device management are part of the service anyway.

Questions we get asked

Cyber Essentials Plus, answered

What is Cyber Essentials Plus?

Cyber Essentials Plus covers exactly the same five technical controls as basic Cyber Essentials, but instead of you declaring that the controls are in place, an IASME approved assessor tests them. That means an external vulnerability scan, an authenticated scan of a sample of your devices, live malware protection tests, and a hands on check of configuration and multi factor authentication.

Do I need basic Cyber Essentials before Plus?

Yes. You must hold a valid basic Cyber Essentials certificate before you can be assessed for Plus, and you have three months from receiving it to complete the Plus assessment. Miss that window and you have to recertify at basic level first.

How much does Cyber Essentials Plus cost?

Plus is priced on the size and complexity of your network rather than a fixed fee, typically from around £1,400 + VAT for a small business up to £3,000 or more for a larger or more complex estate. That sits on top of the basic certification fee, which is set by IASME and runs from £320 to £600 + VAT depending on how many people you employ.

Does the assessor test every device we own?

No. A sample of devices is tested, chosen to represent each different build you run rather than every machine. The sample size comes from IASME's test specification and is agreed with your assessor before testing begins. Servers and cloud services in scope are treated separately from the user device sample.

What happens if we fail part of the audit?

Failing a test is common and is not the end of the process. You are told what failed, you fix it, and the assessor retests. What matters is the three month window from your basic certificate, so the practical risk is running out of time rather than failing outright. That is why the remediation work is worth doing before the audit is booked.

How long does the Cyber Essentials Plus audit take?

The testing itself is usually a day or less for a small estate, sometimes split across a couple of sessions. The preparation is the part that takes real time. Where businesses lose weeks it is almost always fixing what the scan finds rather than the assessment day.

Is Cyber Essentials Plus the same as ISO 27001?

No, and they are not alternatives. Cyber Essentials Plus is a technical baseline verified by testing, achievable in weeks. ISO 27001 is an information security management system covering policy, risk assessment, governance and continual improvement, audited annually and typically taking months. Most UK SMEs treat Cyber Essentials as the starting point and ISO 27001 as the destination.

Who actually needs Plus rather than basic?

Usually someone has told you to get it. Government contracts handling sensitive or personal data commonly specify Plus, as do many large enterprise supplier frameworks, insurers, and clients in financial services and healthcare. If nobody is asking for Plus, basic certification plus the insurance that comes with it is normally the right place to start.

Get Scanned Before the Clock Starts

We will run the readiness scan first, tell you what would fail the audit today, and give you the work list. Free, no obligation, and you keep the findings whatever you decide to do next.

AIS Technology, Woodland Place, Hurricane Way, Wickford, SS11 8YB