Cyber Essentials Plus is the audited tier of the UK government-backed Cyber Essentials scheme: the same five technical controls, but verified by an independent assessor who tests your systems rather than taking your word for it. More customers, insurers, and procurement frameworks now ask for it by name, which is why the question we hear has shifted from “what is it?” to “how do we pass it, and how long will that take?”.
We hold the certification ourselves and we take clients through it as part of our cybersecurity services, so this explainer covers both sides: what the assessment involves, and what the preparation actually feels like.
Standard Cyber Essentials is a verified self-assessment. You answer a question set covering the five controls, firewalls, secure configuration, security update management, user access control, and malware protection, a board member signs it off, and an assessor reviews the answers. Certification starts at £320 plus VAT, banded by organisation size, and renews annually. The question set was tightened in April 2026, and the current version, called Danzell, turned two of the most common weak spots into automatic fails. We cover both below.
Plus adds an independent technical audit against the same controls, and it has to be completed within three months of your standard certification. Your self-assessment now needs to be clean before you can proceed to Plus; until this year, up to two major non-compliances were tolerated. The assessor does not ask whether you patch your machines. They scan a sample of them and find out.
That difference in method is the whole value. A self-assessment records what you believe about your environment. An audit records what is true of it, and in our experience those two pictures never quite match, even in well-run estates. The gap between them is exactly the space attackers work in.
Your internet-facing edge. An external vulnerability scan of the systems the outside world can reach, looking for exploitable weaknesses and misconfigurations. This is the same view an opportunistic attacker gets, which is rather the point.
A sample of your devices. Authenticated scans of representative workstations and servers, checking patch levels and configuration from the inside. Missing high-severity updates older than 14 days are the classic fail, and since April 2026 an automatic one. If the first scan finds a gap, the assessor retests a second random sample of devices, so patching only the machines you expect to be checked no longer works.
Malware defences, in anger. Test files delivered by email and browser download, to confirm your defences catch them in practice rather than in the datasheet. It is a simple test, and it fails more often than vendors would like you to expect.
Accounts and access. Multi-factor authentication on every cloud service that offers it, which now includes the company's social media accounts, and a missing one is an automatic fail rather than a mark against you. Then separation between everyday accounts and administrative ones, and evidence that standard users cannot simply install whatever they like.
For a business with a reasonably managed estate, six to eight weeks of steady work is a fair planning figure. The audit itself typically takes a day or two. The elapsed time is dominated by remediation: chasing down the unpatched machines, the shared admin logins, and the forgotten server that every environment turns out to contain.
Plan for people time as well as calendar time. Someone technical needs to own remediation, someone senior needs to own the scope decision, and end users need warning that admin rights they should never have had are about to disappear. That last conversation goes better in week two than on audit day.
Scope is the decision that shapes everything else. The certificate covers a defined boundary of your organisation, and everything inside that boundary is testable, including the laptop a director bought personally, the tablet in reception, and every cloud service you use, which can no longer be left out of scope. Declaring a sub-set honestly is allowed; discovering unmanaged devices during the audit is how certifications fail.
The same few things, in our experience. Out-of-support software nobody wanted to pay to replace, a legacy operating system on one production machine, bring-your-own devices that touch company data and therefore sit in scope, and MFA gaps on cloud services that were set up before it was the default, which is a straight fail rather than a note. None of these is hard to fix. All of them are hard to fix in the week before the audit.
Having been through the Plus audit ourselves, we would add one more: assume the assessor will find the thing you hoped they would not. Ours was a useful exercise precisely because it removed the gap between belief and reality, and the remediation list it produced was worth more to us than the certificate. Businesses that treat the audit as an inspection to survive get less from it than businesses that treat it as a free consultancy engagement with a pass mark attached.
If you sell to the public sector or through procurement frameworks, the question increasingly answers itself: Plus is becoming table stakes in supplier questionnaires, and its absence needs explaining in a way its presence never does. Certified UK organisations with turnover under £20 million also get cyber liability insurance included through the scheme. The same logic now runs down supply chains, with larger customers asking their suppliers for Plus because their own certifications and insurers ask about supplier assurance.
The quieter benefit is the one we tell clients about. The controls themselves stop the commodity attacks that make up most of what actually hits UK businesses, and the audit forces the estate hygiene that every other security investment depends on. If you are choosing an IT partner and want to know whether their own house is in order, our guide on how to vet an IT provider gives you the questions to ask
The businesses that pass first time are the ones that ran the tests on themselves beforehand. An internal readiness assessment against the five controls, using the same methods the assessor will use, turns the audit from an exam into a formality. It also gives you the remediation list months early, when there is still budget and calendar to work through it calmly.
That readiness work sits inside the wider Reduce risk picture: the certificate is evidence, and the controls are the actual protection. We deliver Cyber Essentials and Cyber Essentials Plus preparation as a standard engagement, from gap analysis through to standing beside you on audit day. Talk to us and we’ll set out how we’d approach yours.