Skip to main content

Requirements for Cyber Essentials Plus

Core Prerequisites

• Basic Certification: Must hold a valid basic Cyber Essentials certificate issued within the last 3 months.

• Zero Tolerance: Zero high or critical vulnerabilities or non-compliances are allowed during testing.

• Remediation Window: Any issues found during the audit must be fixed and re-tested within 30 days or before the 3 month deadline, which ever is sooner.

CEP Explained

Cyber Essentials Plus is the higher tier of the UK Government’s Cyber Essentials scheme. It covers the same five technical control areas as the basic certification, but with one critical difference: an independent assessor verifies that the controls are actually in place and working on your live systems, rather than relying on a self-assessment questionnaire.

Basic Cyber Essentials is a self-assessed certification. You answer roughly eighty questions about how your organisation handles firewalls, secure configuration, user access, malware protection and security update management, and a qualified assessor reviews your answers. It is fast, affordable and well suited to smaller organisations that want a recognised baseline.

Cyber Essentials Plus takes that same baseline and adds an independent technical audit. A trained assessor connects to a sample of your devices, runs vulnerability scans, attempts to deliver simulated malware to test endpoint defences, and inspects configuration evidence directly. It is the assurance level UK Government departments, the Ministry of Defence (MOD) and NHS suppliers increasingly require from their supply chain, and it is becoming a standard expectation in enterprise procurement processes for any supplier handling sensitive data.

If you are interested in Cyber Essentials Plus please reach out to our Support team and they can help you get started.

Did this answer your question?