
Cyber Essentials Plus
Somebody asked you for Plus.
Here is what actually happens.
Plus is the same five controls as basic Cyber Essentials, tested by an assessor instead of declared by you. Most of the anxiety is about the audit day. Most of the work is what you fix before it.
The audit, stage by stage
What the assessor actually does
Five stages, and what you need to have ready for each. Nothing here is a surprise on the day if you have read this first.
Stage 1 of 5
Agreeing what gets tested
Before anything is scanned, you and the assessor agree the scope: which offices, which cloud services, which devices, and whether home and personal devices are in. A sample of user devices is then selected to represent each different build you run, rather than every machine you own. The sample is set from IASME's test specification and agreed with your assessor before testing starts.
Have ready
- A device list covering every operating system and build in use
- A list of cloud services, including the ones a department bought without telling IT
- Your external IP addresses
Which one do you need
Basic and Plus, side by side
If nobody has specifically asked you for Plus, basic certification is almost always the right place to start.
Work out your exact fee, including both levels, on the Cyber Essentials cost calculator.
Before you book
The three month clock is the real risk
You have three months from your basic certificate to complete Plus. Businesses rarely fail Plus outright. They run out of time fixing what the first scan found, and have to start again at basic.
Scan first, book second
We run the same kind of authenticated scan the assessor will, before the clock starts. What it finds is your actual work list, and you find out in week one rather than week ten.
Fix the slow things early
Replacing end of life kit and untangling shared admin accounts takes weeks and often needs budget. MFA and patching policy take hours. Start with the ones that need a purchase order.
Then certify both together
With remediation done, basic and Plus can run back to back comfortably inside the window, and the audit day becomes a formality rather than an inspection.
We take businesses across London and Essex through Plus as a managed piece of work, and for managed IT clients most of the controls are already in place, because patching, MFA and device management are part of the service anyway.
Questions we get asked
Cyber Essentials Plus, answered
What is Cyber Essentials Plus?
Cyber Essentials Plus covers exactly the same five technical controls as basic Cyber Essentials, but instead of you declaring that the controls are in place, an IASME approved assessor tests them. That means an external vulnerability scan, an authenticated scan of a sample of your devices, live malware protection tests, and a hands on check of configuration and multi factor authentication.
Do I need basic Cyber Essentials before Plus?
Yes. You must hold a valid basic Cyber Essentials certificate before you can be assessed for Plus, and you have three months from receiving it to complete the Plus assessment. Miss that window and you have to recertify at basic level first.
How much does Cyber Essentials Plus cost?
Plus is priced on the size and complexity of your network rather than a fixed fee, typically from around £1,400 + VAT for a small business up to £3,000 or more for a larger or more complex estate. That sits on top of the basic certification fee, which is set by IASME and runs from £320 to £600 + VAT depending on how many people you employ.
Does the assessor test every device we own?
No. A sample of devices is tested, chosen to represent each different build you run rather than every machine. The sample size comes from IASME's test specification and is agreed with your assessor before testing begins. Servers and cloud services in scope are treated separately from the user device sample.
What happens if we fail part of the audit?
Failing a test is common and is not the end of the process. You are told what failed, you fix it, and the assessor retests. What matters is the three month window from your basic certificate, so the practical risk is running out of time rather than failing outright. That is why the remediation work is worth doing before the audit is booked.
How long does the Cyber Essentials Plus audit take?
The testing itself is usually a day or less for a small estate, sometimes split across a couple of sessions. The preparation is the part that takes real time. Where businesses lose weeks it is almost always fixing what the scan finds rather than the assessment day.
Is Cyber Essentials Plus the same as ISO 27001?
No, and they are not alternatives. Cyber Essentials Plus is a technical baseline verified by testing, achievable in weeks. ISO 27001 is an information security management system covering policy, risk assessment, governance and continual improvement, audited annually and typically taking months. Most UK SMEs treat Cyber Essentials as the starting point and ISO 27001 as the destination.
Who actually needs Plus rather than basic?
Usually someone has told you to get it. Government contracts handling sensitive or personal data commonly specify Plus, as do many large enterprise supplier frameworks, insurers, and clients in financial services and healthcare. If nobody is asking for Plus, basic certification plus the insurance that comes with it is normally the right place to start.
Get Scanned Before the Clock Starts
We will run the readiness scan first, tell you what would fail the audit today, and give you the work list. Free, no obligation, and you keep the findings whatever you decide to do next.
AIS Technology, Woodland Place, Hurricane Way, Wickford, SS11 8YB
