Cyber Essentials Plus Certification

Cyber Essentials Plus is the audited tier of the UK Government’s Cyber Essentials scheme. It covers the same five technical controls, but instead of taking your word for it, an assessor independently tests your systems to verify the controls actually work.

RedSecLabs is preparing to offer Cyber Essentials Plus assessments delivered by security professionals who test infrastructure for a living. Our CREST-accredited background means the technical audit, vulnerability scanning, device sampling, malware protection testing, holds no surprises for us or for you.

We get you audit-ready first, so assessment day is a formality rather than a gamble.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Register Your Interest

Tell us about your organisation and we’ll contact you the day our Cyber Essentials service goes live. No obligation.

You’ll get our Danzell readiness checklist by reply, and one email when we launch. No mailing lists, ever.

Launching Soon RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Register your interest for priority assessment slots at launch and our free Danzell readiness checklist now.
CREST-accredited testers · 2026 CE+ process ready · Pre-audit dry run included · Fixed-fee quotes · Remediation guidance
Who this is for

This page is for you if you’re..

1
Contract requirements
Suppliers whose contracts, MOD, NHS, enterprise procurement, specifically require Cyber Essentials Plus rather than the basic tier.
2
Higher assurance
Organisations that want independently verified evidence their controls work, not just a signed self-declaration.
3
Already CE certified
Businesses that passed basic Cyber Essentials within the last 3 months and need to complete the Plus audit window.

Cyber Essentials Plus, Quick Facts

Last reviewed: 2026-07-21
What it adds
Independent technical audit on top of the verified self-assessment: scans, device sampling and hands-on control testing
Prerequisite
A passed Cyber Essentials self-assessment; the Plus audit must be completed within 3 months of that pass
Audit activities
External vulnerability scan, authenticated scans of sampled devices, malware/email/browser download tests, MFA and account separation checks
2026 changes
Tightened CE+ methodology from April 2026, including measures against selective patching before assessment
Typical cost
Set by each Certification Body; commonly £1,400–£4,000+ VAT for SMEs depending on size and device sample
Validity
12 months, same as basic Cyber Essentials; annual reassessment required
3 months
Window after CE pass to complete Plus
1–2 days
Typical audit duration for an SME
100%
Of controls independently verified
12 months
Certificate validity

What does the Plus audit involve?

A Cyber Essentials Plus assessment is a structured technical audit carried out by a qualified assessor against a defined test specification. A representative sample of your devices, workstations, laptops and mobile devices across each build type, is selected, and the assessor verifies the five controls in practice.

Expect an external vulnerability scan of your internet-facing services, authenticated scans of the sampled devices to check patching and configuration, tests that malware protection blocks known-bad files and downloads, email and browser-based payload tests, and verification of MFA on cloud services and separation of admin accounts. The 2026 methodology update also introduced checks designed to catch organisations that patch selectively just before assessment day.

Why organisations choose Plus over basic Cyber Essentials:
Meets contracts that explicitly mandate Cyber Essentials Plus (common in MOD and NHS supply chains)
Independent verification carries far more weight in enterprise due diligence
Surfaces real misconfigurations a self-assessment can miss
Stronger position with cyber insurers and lower-friction renewals
Demonstrates security maturity beyond a signed declaration
A sensible first rung before ISO 27001 or SOC 2 programmes

If a contract simply says “Cyber Essentials”, check the wording carefully, an increasing share of buyers now specify Plus, and the two are not interchangeable.

Where Plus audits go wrong

Most Plus failures are not exotic. They come from the gap between what an organisation believes about its estate and what an authenticated scan actually finds. A device missing three months of patches, an unsupported browser plugin, or a shared local admin password will surface within minutes of the audit starting.

Our approach is to run the same tests before the real audit. A pre-audit dry run against the current CE+ test specification means every finding is fixed on our time, not discovered on assessment day.

The most common Plus failure points:
Sampled devices missing high/critical updates older than 14 days
Malware protection misconfigured or not blocking test payloads
Unsupported software discovered by authenticated scans
MFA gaps on cloud services found during verification
Locally installed apps nobody knew about (shadow IT)
Day-to-day use of administrator accounts on sampled machines

A failed Plus audit means paying for reassessment and, if your 3-month window from the basic pass expires, redoing the self-assessment too. A dry run is far cheaper than a second audit.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

The Cyber Essentials Plus audit process

What actually happens between booking a Plus assessment and receiving the certificate, based on the 2026 methodology.

1
Pass basic Cyber Essentials first
Plus builds on a current verified self-assessment; the technical audit must complete within 3 months of that pass. Book the Plus slot when you purchase the basic assessment so the window never becomes a deadline problem.
2
Scoping and device sampling
The assessor agrees the scope and selects a representative device sample across every operating system build and device type. The 2026 methodology revised sampling to counter selective, assessment-week-only patching, your whole estate needs to be genuinely current.
3
External vulnerability scan
Your internet-facing IP addresses and services are scanned for known vulnerabilities and exposed management interfaces. Anything high or critical must be resolved for a pass.
4
Authenticated device testing
Each sampled device gets an authenticated (credentialed) scan verifying patch status and supported software, plus hands-on checks: malware protection blocking test payloads, email and browser download tests, and screen-lock settings.
5
Account and MFA verification
The assessor verifies admin/standard account separation in practice and MFA enforcement on in-scope cloud services, the checks aligned to Danzell's automatic-failure conditions.
6
Findings, remediation window, certificate
Minor findings can typically be fixed and re-verified within the assessment terms; clean results mean certification, your listing on the NCSC register, and 12 months of validity.

Get Ready for Cyber Essentials Plus

Register your interest and we’ll assess your estate against the current CE+ test specification, so when we launch, you’re first in the audit calendar.

Frequently Asked Questions

Unlike the basic tier, Plus pricing is set by each Certification Body rather than IASME, because audit effort varies with your size and estate. For UK SMEs, expect roughly £1,400–£4,000 + VAT depending on employee count, device sample size, number of sites and build types, in addition to the basic Cyber Essentials fee.

Yes. Cyber Essentials Plus requires a passed verified self-assessment first, and the Plus audit must be completed within 3 months of that pass. If the window lapses, you must redo the self-assessment before attempting Plus.

For a typical SME, the technical audit itself takes one to two days, often deliverable remotely. End-to-end, allow 2–4 weeks from booking to certificate, longer if remediation is needed after a pre-audit review.

Largely yes. Most SME assessments are now conducted remotely using screen sharing and scanning tools, with the assessor verifying sampled devices live. Complex or multi-site environments may still warrant on-site elements.

The assessor samples devices according to the scheme's sampling rules, covering each operating system build and device type in scope. The more standardised your builds, the smaller the sample and the cheaper and faster the audit.

You'll receive the findings and typically a limited window to remediate and re-test, depending on the severity and the assessment terms. Failures outside that window mean a fresh assessment. This is exactly why we run a dry-run audit first, so nothing on assessment day is a surprise.
📞 Call us Book a call