Cyber Essentials Plus Certification

Cyber Essentials Plus is the audited tier of the UK Government’s Cyber Essentials scheme. It covers the same five technical controls, but instead of taking your word for it, an assessor independently tests your systems to verify the controls actually work.

RedSecLabs is an IASME-licensed Certification Body for Cyber Essentials, with Cyber Essentials Plus assessments launching soon. Until then, our security professionals deliver Plus readiness consultancy: we prepare your estate so the audit is a formality, whoever performs it. Our CREST-accredited background means the technical audit, vulnerability scanning, device sampling, malware protection testing, holds no surprises for us or for you.

We get you audit-ready first, so assessment day is a formality rather than a gamble.

CREST Member Company Cyber Essentials Certification Body PCI SSC Qualified Security Assessor (QSA) Company ISO 27001 Certified UKAS Accredited Certification

Get a Fixed-Fee Quote

Tell us about your organisation and we’ll come back with a fixed-fee quote and readiness view the same business day. No obligation.

We reply within one business day with next steps. Your details are used only to scope your enquiry, never shared or sold.

You’ll get our Danzell readiness checklist by reply. No mailing lists, ever.

Certification Body RedSecLabs is an IASME-licensed Certification Body for Cyber Essentials. Cyber Essentials Plus assessments launching soon; Plus readiness consultancy available now. Start your assessment or request our free Danzell readiness checklist.
CREST-accredited testers · 2026 CE+ process ready · Pre-audit dry run included · Fixed-fee quotes · Remediation guidance
Who this is for

This page is for you if you’re..

1
Contract requirements
Suppliers whose contracts, MOD, NHS, enterprise procurement, specifically require Cyber Essentials Plus rather than the basic tier.
2
Higher assurance
Organisations that want independently verified evidence their controls work, not just a signed self-declaration.
3
Already CE certified
Businesses that passed basic Cyber Essentials within the last 3 months and need to complete the Plus audit window.

Cyber Essentials Plus, Quick Facts

Last reviewed: 2026-07-21
What it adds
Independent technical audit on top of the verified self-assessment: scans, device sampling and hands-on control testing
Prerequisite
A passed Cyber Essentials self-assessment; the Plus audit must be completed within 3 months of that pass
Audit activities
External vulnerability scan, authenticated scans of sampled devices, malware/email/browser download tests, MFA and account separation checks
2026 changes
Tightened CE+ methodology from April 2026, including measures against selective patching before assessment
Typical cost
Set by each Certification Body; commonly £1,400–£4,000+ VAT for SMEs depending on size and device sample
Validity
12 months, same as basic Cyber Essentials; annual reassessment required
3 months
Window after CE pass to complete Plus
1–2 days
Typical audit duration for an SME
100%
Of controls independently verified
12 months
Certificate validity

What does the Plus audit involve?

A Cyber Essentials Plus assessment is a structured technical audit carried out by a qualified assessor against a defined test specification. A representative sample of your devices, workstations, laptops and mobile devices across each build type, is selected, and the assessor verifies the five controls in practice.

Expect an external vulnerability scan of your internet-facing services, authenticated scans of the sampled devices to check patching and configuration, tests that malware protection blocks known-bad files and downloads, email and browser-based payload tests, and verification of MFA on cloud services and separation of admin accounts. The 2026 methodology update also introduced checks designed to catch organisations that patch selectively just before assessment day.

Why organisations choose Plus over basic Cyber Essentials:
Meets contracts that explicitly mandate Cyber Essentials Plus (common in MOD and NHS supply chains)
Independent verification carries far more weight in enterprise due diligence
Surfaces real misconfigurations a self-assessment can miss
Stronger position with cyber insurers and lower-friction renewals
Demonstrates security maturity beyond a signed declaration
A sensible first rung before ISO 27001 or SOC 2 programmes

If a contract simply says “Cyber Essentials”, check the wording carefully, an increasing share of buyers now specify Plus, and the two are not interchangeable.

Where Plus audits go wrong

Most Plus failures are not exotic. They come from the gap between what an organisation believes about its estate and what an authenticated scan actually finds. A device missing three months of patches, an unsupported browser plugin, or a shared local admin password will surface within minutes of the audit starting.

Our approach is to run the same tests before the real audit. A pre-audit dry run against the current CE+ test specification means every finding is fixed on our time, not discovered on assessment day.

The most common Plus failure points:
Sampled devices missing high/critical updates older than 14 days
Malware protection misconfigured or not blocking test payloads
Unsupported software discovered by authenticated scans
MFA gaps on cloud services found during verification
Locally installed apps nobody knew about (shadow IT)
Day-to-day use of administrator accounts on sampled machines

A failed Plus audit means paying for reassessment and, if your 3-month window from the basic pass expires, redoing the self-assessment too. A dry run is far cheaper than a second audit.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

The Cyber Essentials Plus audit process

What actually happens between booking a Plus assessment and receiving the certificate, based on the 2026 methodology.

1
Pass basic Cyber Essentials first
Plus builds on a current verified self-assessment; the technical audit must complete within 3 months of that pass. Start Plus readiness alongside the basic assessment so the 3-month window never becomes a deadline problem.
2
Scoping and device sampling
The assessor agrees the scope and selects a representative device sample across every operating system build and device type. The 2026 methodology revised sampling to counter selective, assessment-week-only patching, your whole estate needs to be genuinely current.
3
External vulnerability scan
Your internet-facing IP addresses and services are scanned for known vulnerabilities and exposed management interfaces. Anything high or critical must be resolved for a pass.
4
Authenticated device testing
Each sampled device gets an authenticated (credentialed) scan verifying patch status and supported software, plus hands-on checks: malware protection blocking test payloads, email and browser download tests, and screen-lock settings.
5
Account and MFA verification
The assessor verifies admin/standard account separation in practice and MFA enforcement on in-scope cloud services, the checks aligned to Danzell's automatic-failure conditions.
6
Findings, remediation window, certificate
Minor findings can typically be fixed and re-verified within the assessment terms; clean results mean certification, your listing on the NCSC register, and 12 months of validity.

Get Ready for Cyber Essentials Plus

Request a CE+ scope and fixed-fee quote and we’ll assess your estate against the current test specification, then book your audit slot.

Three ways to get Plus-ready

Plus assessments are launching soon. The organisations that pass Plus comfortably are the ones that prepared before booking, and the 3-month window after basic certification punishes anyone who didn’t.

Readiness review
We assess your estate against the current Plus test specification: patching windows, malware defences, browser and email protections, account separation.
  • Device-sample review matching audit methodology
  • Prioritised fix list, plain-English
  • Fixed fee, quoted same business day
Book a readiness review
RECOMMENDED
Readiness + dry-run audit
Everything in the review, then we run the audit for real before the real audit: same tests, same sampling, zero consequences for a fail.
  • Full dry-run against the Plus test spec
  • Re-check of fixed items included
  • Nothing on assessment day is a surprise
  • First in the queue when our Plus slots open
Get audit-ready
Basic + Plus-ready bundle
No basic certificate yet? One project: we certify Cyber Essentials, run Plus readiness inside the 3-month window, and schedule the audit before the window closes.
  • Basic certification (official IASME fee)
  • Plus readiness sequenced inside the window
  • £25,000 insurance benefit for eligible UK organisations
  • One fixed quote for the whole path
Plan the full path
How the window works
1
Pass basic Cyber Essentials
The Plus clock starts here: the audit must complete within 3 months of your basic certificate.
2
Get Plus-ready inside the window
Readiness and dry-run in weeks one to six. Fail items get fixed while fixing is cheap.
3
Audit inside the window
Book the slot with headroom to spare. Miss the window and the whole path restarts, including fees.

Frequently Asked Questions

Unlike the basic tier, Plus pricing is set by each Certification Body rather than IASME, because audit effort varies with your size and estate. For UK SMEs, expect roughly £1,400 to £4,000 + VAT depending on employee count, device sample size, number of sites and build types, in addition to the basic Cyber Essentials fee.

Yes. Cyber Essentials Plus requires a passed verified self-assessment first, and the Plus audit must be completed within 3 months of that pass. If the window lapses, you must redo the self-assessment before attempting Plus.

For a typical SME, the technical audit itself takes one to two days, often deliverable remotely. End-to-end, allow 2 to 4 weeks from booking to certificate, longer if remediation is needed after a pre-audit review.

Largely yes. Most SME assessments are now conducted remotely using screen sharing and scanning tools, with the assessor verifying sampled devices live. Complex or multi-site environments may still warrant on-site elements.

The assessor samples devices according to the scheme's sampling rules, covering each operating system build and device type in scope. The more standardised your builds, the smaller the sample and the cheaper and faster the audit.

You'll receive the findings and typically a limited window to remediate and re-test, depending on the severity and the assessment terms. Failures outside that window mean a fresh assessment. This is exactly why we run a dry-run audit first, so nothing on assessment day is a surprise.
📞 Call us Book a call