A customer asks for proof of cyber security. A public-sector tender makes certification a condition of entry. Your insurer wants evidence that basic controls are in place. These are the moments when business leaders ask: what is Cyber Essentials Plus, and is it worth the time and cost?
Cyber Essentials Plus is the independently assessed level of the UK Government-backed Cyber Essentials scheme. It confirms that an organisation has put core cyber security controls in place and, crucially, that those controls work in practice. While the standard Cyber Essentials certification is based on a self-assessment questionnaire verified by an assessor, Cyber Essentials Plus adds hands-on technical testing by an independent certification body.
For businesses managing customer data, operating critical systems or competing for regulated contracts, that distinction matters. It provides external evidence that your security baseline is more than a policy document or a tick-box exercise.
Cyber Essentials Plus explained
Cyber Essentials Plus builds on Cyber Essentials. Before an organisation can achieve Plus, it must first meet the Cyber Essentials requirements. The scheme focuses on five technical control areas that address many of the most common routes into a business network:
- boundary firewalls and internet gateways
- secure configuration of devices and software
- access control and user permissions
- malware protection
- security update management
These are foundational controls, not a complete cyber security strategy. They will not, by themselves, eliminate phishing, insider risk, complex cloud misconfiguration or targeted attacks. But they substantially reduce exposure to common, preventable incidents such as unpatched vulnerabilities, weak administrator access and poorly configured devices.
The Plus assessment independently tests a representative sample of the systems within scope. The assessor checks that the declarations made during Cyber Essentials are accurate, carrying out technical checks such as vulnerability scanning and device configuration testing. The exact assessment activity depends on your environment and the scheme requirements in force, but the central principle remains the same: an independent party verifies the controls rather than relying only on your answers.
Cyber Essentials vs Cyber Essentials Plus
The practical difference is assurance.
Cyber Essentials demonstrates that your organisation has reviewed its systems against the scheme requirements and made a declaration that the required controls are in place. It is a useful first step for businesses establishing a consistent security baseline, particularly where internal IT teams need a clear framework for prioritising improvements.
Cyber Essentials Plus goes further by testing that baseline. This gives customers, procurement teams, insurers and senior management greater confidence that security controls are functioning across real devices and user accounts.
That additional assurance usually makes Cyber Essentials Plus the stronger choice where you handle sensitive information, support larger clients, operate in supply chains with security requirements, or need to differentiate your business during a tender process. Some government contracts require Cyber Essentials certification as a minimum, while specific opportunities may request Plus. Requirements should always be checked early, before a bid is underway.
There is a trade-off. Plus requires more preparation, more active involvement from your IT team or managed service provider, and a higher certification cost. It can also expose gaps that must be remediated before certification is achieved. That is not a reason to avoid it. Finding an unsupported operating system, an overdue patch or an over-privileged user account before an attacker does is a valuable outcome.
What does the assessment look for?
Cyber Essentials Plus is designed to test whether day-to-day IT management matches the security position claimed by the business. It is not a penetration test and it does not attempt to simulate every possible attack. Instead, it validates the core controls that should be operating consistently across laptops, desktops, servers, mobile devices, cloud services and network equipment within the agreed scope.
Assessors may examine whether devices are receiving security updates within the required timeframes, whether malware protection is active, whether users have appropriate privileges and whether insecure or unsupported software is present. They can also check internet-facing systems for known vulnerabilities and test a sample of devices to confirm that basic protections are not simply documented but missing in reality.
This is where organisations often encounter practical issues. A policy may state that only authorised staff hold administrator rights, for example, but a legacy account may still have elevated permissions. Central patching may be working for newer laptops while a small group of remote devices has fallen outside the management platform. A cloud application may be secure in principle but lack multi-factor authentication for a particular administrator account.
These are operational problems, not theoretical ones. They require ownership, accurate asset records and a team that can make changes promptly without interrupting the business.
Who should consider Cyber Essentials Plus?
Cyber Essentials Plus is relevant to far more than large enterprises. Small and mid-sized businesses are frequently targeted because attackers expect weaker controls, limited monitoring and a slower response to incidents. If a successful attack would interrupt trading, expose client information or damage a key commercial relationship, independently tested certification deserves consideration.
It is particularly useful for organisations that work with government bodies, education providers, financial services firms, healthcare organisations, legal practices and larger corporate supply chains. It can also support businesses preparing for cyber insurance discussions, although certification does not guarantee cover or replace the need to meet an insurer’s specific conditions.
For a growing business, Plus can create discipline at the right time. It encourages a clear view of devices, software, user access and security responsibilities before IT becomes difficult to manage. For an established organisation with multiple sites, hybrid workers or several technology suppliers, it can reveal where accountability has become fragmented.
Certification may be less urgent where there is no contractual requirement, the business has a very small and simple IT estate, and the immediate priority is resolving fundamental operational issues. Even then, the Cyber Essentials controls remain a sensible benchmark. The decision should be based on business risk and customer expectations, not on certification for its own sake.
Preparing without disrupting operations
The smoothest Cyber Essentials Plus assessments begin well before the assessor starts testing. Preparation is not about hiding weaknesses. It is about understanding the environment, addressing obvious gaps and ensuring the assessment scope reflects how the business actually operates.
Start by creating an accurate inventory of devices, operating systems, software, cloud services and user accounts. Include remote workers, shared devices, mobile phones and equipment at satellite sites. If it connects to business data or services, it may affect your security position.
Next, confirm who owns patching, endpoint protection, firewall management, user access and incident response. In many businesses, responsibility is split between an internal employee, a software supplier, a telecoms provider and an outsourced IT company. That arrangement can work, but only if responsibilities are explicit and there is someone accountable for the overall result.
Access control deserves close attention. Remove unused accounts, review administrator privileges and apply multi-factor authentication wherever it is available and appropriate. Keep standard users separate from privileged accounts. This reduces the impact of stolen credentials and makes it harder for malware to spread.
Finally, allow time for remediation. An assessment may identify items that need to be corrected, and some changes require testing to avoid disruption to applications or users. Leaving certification until days before a tender deadline creates unnecessary pressure and can turn a manageable technical task into a commercial risk.
Certification is a baseline, not the finish line
Cyber Essentials Plus is valid for a defined period and should be treated as part of an ongoing security programme, not a one-off project. New devices arrive, staff change roles, software reaches end of life and threats evolve. A control that passed in one month can fail later if routine management slips.
The strongest approach is to build the scheme’s requirements into normal IT operations: managed patching, regular access reviews, monitored endpoint protection, documented asset management and clear escalation when a risk is found. This reduces the scramble before renewal and gives leadership better visibility of the systems the business depends on.
For organisations without the internal capacity to manage this alone, a managed IT and cyber security partner can coordinate the preparation, remediation and ongoing control management. The value is not just passing an assessment. It is having one accountable team that understands the environment and acts before routine weaknesses become downtime, data loss or a difficult customer conversation.
Cyber Essentials Plus will not make a business immune to cyber attack. What it can do is prove that the basic defences attackers routinely exploit are actively managed, independently checked and taken seriously. That is a practical signal of reliability to customers and a stronger operational footing for the business behind the certificate.







