Certification
What is Cyber Essentials Plus?
Cyber Essentials Plus is the audited tier of the UK Cyber Essentials scheme. It covers the same five technical controls as the self-assessed certification, but a licensed assessor independently verifies them through hands-on technical testing of a representative sample of devices and user accounts, rather than relying on the organisation's own declaration.
At a glance
- Prerequisite
- Cyber Essentials passed within the previous 3 months
- Assessment type
- Independent technical audit
- Testing method
- Device sampling, vulnerability scan, malware and email tests
- Validity
- 12 months
- Typical audit duration
- 1–2 days
What the assessor actually tests
The audit is practical rather than documentary. An assessor examines a sample of end-user devices and servers drawn from the declared scope, sized according to the number and variety of devices in use.
- Patch verification — an authenticated vulnerability scan confirming that high and critical updates are applied within 14 days, across operating systems and third-party software.
- Malware protection testing — attempts to download or execute benign test files to confirm protection is active and effective.
- Email and web testing — test files delivered by email and via browser download to confirm filtering and endpoint controls behave as declared.
- Account separation — verification that administrative accounts are separate from day-to-day user accounts.
- Multi-factor authentication — confirmation that MFA is enforced on cloud services and administrative access.
- External vulnerability scan — a scan of internet-facing IP addresses in scope.
Sequence and timing
Cyber Essentials Plus cannot be taken in isolation. The base Cyber Essentials certification must be achieved first, and the Plus audit must be completed within three months of that pass date. If the window is missed, the self-assessment must be retaken.
Most organisations plan for a gap of two to eight weeks between the two, which allows time to correct anything the self-assessment surfaced before an assessor tests it directly.
Why the higher tier is requested
Buyers who require independent assurance — larger enterprises, some public sector bodies, and clients handling regulated or sensitive data — increasingly specify Cyber Essentials Plus rather than the base certificate, because it evidences that controls are working in practice, not merely declared.
It is also a practical internal check. The audit routinely surfaces discrepancies between what an organisation believes is deployed and what is actually running on its devices.
Sources
The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.
- Cyber Essentials: overview — National Cyber Security Centre
- Cyber Essentials certification scheme — IASME Consortium
- Cyber Essentials Plus: the audited assessment — IASME Consortium
FAQ
What is Cyber Essentials Plus — common questions
Direct answers to the questions asked most often about this topic.
How much more does Cyber Essentials Plus cost than Cyber Essentials?
+
Cyber Essentials Plus costs significantly more than the base certification because it involves assessor time on site or remotely, technical testing and reporting. Where the self-assessment fee typically sits in the hundreds of pounds, Plus commonly runs into low four figures for a small organisation, and scales with the number and diversity of devices in scope, the number of sites and whether remote workers must be tested. The base certification fee is also payable, since Plus can only be taken after passing it. Remediation work identified during preparation is a separate cost.
What happens if a device fails during the audit?
+
A failure does not automatically end the process. Assessors typically report the issue and allow a remediation period — commonly up to 30 days — for the organisation to correct it and provide evidence or allow retesting. The most frequent failures are missing patches on third-party software such as browsers, PDF readers and conferencing clients; unsupported operating system versions; and administrative accounts used for everyday work. If problems are extensive, the assessment may need to be restarted, which is why a pre-audit readiness check is worthwhile before booking the formal audit.
How many devices will be tested?
+
Assessors test a representative sample rather than every device. The sample size is determined by IASME's sampling rules and reflects the total number of devices and the number of distinct build types — for example, Windows laptops, macOS laptops, Android phones and iPhones each count as a separate group. A small organisation with a uniform Windows estate may see only a handful of devices tested. A mixed estate with several operating systems and multiple sites will see more, because the assessor must cover each group. Remote workers' devices are included where they hold organisational data.
Can Cyber Essentials Plus be completed remotely?
+
Yes, in most cases. Remote auditing has become standard practice: the assessor connects to sampled devices via screen sharing or a remote access session, runs the vulnerability scan against them, and observes the malware and email tests being carried out. This suits organisations with distributed or home-based staff. Some assessors still offer on-site audits, and certain environments — isolated networks, or estates where remote access is restricted by policy — are easier to test in person. The testing requirements and the resulting certificate are identical either way.
Do mobile phones need to be included?
+
Mobile devices that access organisational data — company email, files or business applications — are in scope, including staff-owned phones used for work. In practice this means they must be running a supported operating system version, receive security updates, have a passcode or biometric lock, and be covered by the organisation's access controls. Devices used only for voice calls and text messages, with no access to business data, fall outside scope. Because personal phones are common in SMEs, clarifying which devices touch business data is one of the first steps in defining scope.
Is Cyber Essentials Plus worth it if clients only ask for Cyber Essentials?
+
If no contract or insurer requires it, the base certification satisfies the immediate need at a much lower cost. The argument for Plus is assurance rather than compliance: the audit independently verifies that patching, malware protection and account controls genuinely work across real devices, and it routinely finds gaps that a self-assessment does not. Organisations bidding for larger contracts often certify to Plus pre-emptively, because buyers increasingly specify it and the lead time to achieve it can exceed a tender deadline.

