Pillar 02 · Accredit

Cyber Essentials Plus Certification

Cyber Essentials Plus is the government-backed certification that proves your organisation has the five basic technical controls in place. Unlike the entry-level scheme, it proves it by having someone check.

It has become the practical price of entry for a lot of work. Central government contracts, defence supply chains, NHS suppliers and an increasing number of large corporate procurement teams either require it or score you higher for having it.

We take clients through the whole Cyber Essentials certification process: gap analysis, remediation, the basic certification, then the Plus audit. Since Fourarmed came out of an insurance broker, we look at your controls the way an underwriter would as we go, rather than only the way the question set does.

Scheme
Run by IASME on behalf of the National Cyber Security Centre
Question set
Danzell, in force for assessments from 26 April 2026
Prerequisite
Basic Cyber Essentials, then Plus within three months
Scheme fee
£320 to £600 plus VAT, by organisation size
Renewal
Annual
Included cover
£25,000 cyber liability for eligible organisations

What Is Cyber Essentials Plus?

Five technical controls

Cyber Essentials is a UK government scheme, run by IASME on behalf of the National Cyber Security Centre. It covers five technical controls:

  • Firewalls, controlling what can reach your network from outside it
  • Secure configuration, removing default accounts, unnecessary software and open services
  • Security update management, installing critical and high-risk patches within 14 days
  • User access control, meaning least privilege, administrator separation, and multi-factor authentication on cloud services
  • Malware protection, in place and correctly configured

Get these five areas right and you prevent the large majority of untargeted attacks. This is the whole premise of the scheme, and it holds up.

Cyber Essentials Plus covers exactly the same five controls. What changes is the evidence. Basic Cyber Essentials is a verified self-assessment: you answer the question set and an assessor reviews your answers. Plus adds an independent technical audit, where a qualified assessor performs a hands-on evaluation of your actual systems and confirms the controls are working.

Cyber Essentials vs Cyber Essentials Plus

Scheme fees as at July 2026
Particular Cyber Essentials Cyber Essentials Plus
The five controls Same Same
How it is assessed Verified self-assessment questionnaire Hands-on technical audit by an assessor
What is tested Your written answers External vulnerability scan, sampled devices across each OS and device type, patch verification, malware protection config, account separation, MFA on cloud services
Prerequisite None You must already hold basic Cyber Essentials
Timing Not applicable The Plus audit must be completed within three months of your basic certification date
Certification fee £320 to £600 + VAT depending on organisation size Quoted individually, based on the size and complexity of your network
Renewal Annually Annually
Free £25,000 cyber liability cover Yes, if UK or Crown Dependencies domiciled, turnover under £20m, whole organisation in scope, and you opt in Included via your basic certification
What it signals You say the controls are in place Someone independent has verified the controls are in place

The certification fees above are IASME's published bands as at July 2026. Micro organisations of 0 to 9 employees pay £320, small organisations of 10 to 49 pay £440, medium organisations of 50 to 249 pay £500, and large organisations of 250 or more pay £600, all plus VAT. These are scheme fees only, separate from any support you buy in.

Why Your Business Needs Certification

Four reasons, in order of force

Contracts

This is the big one. Certification requirements have worked their way down supply chains, and if you sell to government, defence, healthcare or large corporations you will need to meet them. Being able to answer "yes, Plus, current" on a pre-qualification questionnaire is worth more than any amount of explaining your security posture in free text.

Defence is the sharpest example. The MOD and the primes above you, BAE, Leonardo, Rolls-Royce and the rest, pass cyber security requirements down to Tier 2 and Tier 3 suppliers, and Cyber Essentials Plus is increasingly the minimum accepted. Castlemead's membership of ADS Group is why we understand how those obligations cascade, and not simply what the certificate says.

Insurance

Certification alone will not get you cover, but it is a credible starting point and it gives an underwriter something concrete to work with. Basic certification also includes £25,000 of cyber liability cover for eligible organisations in the UK or Crown Dependencies turning over under £20m. It is no substitute for a real policy, though it is a reasonable floor. Our page on what cyber insurers require covers what underwriters look for beyond the certificate.

Actual security

The five controls are the five controls for a reason. Working through them properly closes real gaps, and the Plus audit finds the ones you would otherwise have missed, such as a device outside the patching schedule, a cloud service where MFA was enabled but not enforced, or an administrator account somebody set up as a convenience.

Board comfort

Under the current scheme, the compliance declaration is signed at board level and now explicitly acknowledges ongoing responsibility for maintaining the controls. This is a useful prompt for a conversation most boards should be having anyway.

Worth knowing: only 5% of UK businesses currently hold Cyber Essentials, though that is up from 3% the year before, and 12% of small businesses now have it. Certification still works as a differentiator, for now.

What Changed in April 2026

Four changes that catch people out

As of April 2026, the scheme has been updated, and if you certified prior to this then the goalposts have moved. The current question set is Danzell, published in February 2026 and in force for assessments from 26 April 2026.

  • If multi-factor authentication is missing on any cloud service, the assessment now fails outright. It is no longer something you can remediate afterwards.
  • Two new questions on security updates are also auto-fail criteria, including if high-risk or critical updates and vulnerability fixes are not installed within 14 days of release.
  • Scope descriptions have to be much fuller, with anything out of scope documented and in-scope legal entities identified.
  • For Plus specifically, update-management retesting now uses a fresh random sample of devices, and verified self-assessment answers cannot be adjusted after Plus testing has occurred.

In the past, it was possible to discover a problem during the Plus audit and quietly correct the self-assessment. This is no longer allowed, which makes doing the groundwork properly considerably more important than it previously was.

Our Certification Process

Six stages
  1. Gap analysis

    We assess you against the current question set and inform you exactly where you would fail today. You get a written gap report with a remediation list. Most organisations have several gaps, and at least one is usually a surprise.

  2. Remediation

    We work with you or your IT provider to close any gaps. This is the part that takes the time. How long depends on what we find, though device patching, MFA rollout and administrator separation are the usual culprits.

  3. Basic Cyber Essentials

    We take you through the verified self-assessment and submit it. This has to be in place before Plus, and it is where the £25,000 insurance opt-in becomes available.

  4. Readiness check

    Before the Plus audit, we sample your devices ourselves, in the same way an assessor will. It is much cheaper to find a problem here than during the audit.

  5. The Plus audit

    This independent technical audit must take place within three months of your basic certification. It includes an external vulnerability scan, device sampling across each operating system and device type in scope, patch verification, malware protection checks, and confirmation of account separation and MFA on cloud services.

  6. Certification and renewal

    After you get your certificate, you can start putting it on tenders. We will flag your renewal ahead of time, because letting it lapse mid-tender is an avoidable and annoying way to lose work.

Gap Analysis and Implementation Support

Where the value is

You can buy certification as a paperwork exercise from plenty of places. We would rather you did not.

The gap analysis is where the value is, because it is where you find out what is true about your estate. Clients regularly discover unsupported operating systems still in daily use, a cloud tenancy nobody was administering, or MFA that went live for the leadership team and was never rolled out to everyone else.

Fixing those things is worth doing whether or not you certify.

If the gap analysis turns up more than a certification exercise can sensibly address, we will say so and recommend a full cyber security audit first. It is a bigger piece of work and it is occasionally the right answer.

What Comes After Certification

Cyber Essentials Plus proves you have five technical controls working. ISO 27001 is a different kind of animal. It is an information security management system covering governance, risk assessment, policy, supplier management and continuous improvement. It is a management standard, not a technical baseline, and it is a bigger undertaking. It typically involves a year of work with ongoing audit cycles.

Most organisations should not jump straight into it. CE Plus first, then ISO 27001 when a client or a regulator makes it necessary, is the sensible order. The work you do for CE Plus is not wasted either. The technical controls and the evidence you build map onto several ISO 27001 requirements.

We help clients get ISO 27001-ready by mapping their current position against the standard and building the risk assessment foundations it requires. If you need certification itself, we will tell you honestly what is involved and who is best placed to do it.

Common questions

Five questions
Do we need basic Cyber Essentials before Plus?
Yes. Basic Cyber Essentials is a prerequisite, and the Plus audit must be completed within three months of your basic certification date.
How long does Cyber Essentials Plus take?
It depends almost entirely on what the gap analysis finds. Remediation is the part that takes the time, and device patching, MFA rollout and administrator separation are the usual culprits. It is rarely a two-week job, so the earlier you start the less it costs in stress.
How much does Cyber Essentials Plus cost?
The basic certification fee is published by IASME: £320 plus VAT for micro organisations of 0 to 9 employees, £440 for small organisations of 10 to 49, £500 for medium organisations of 50 to 249, and £600 for large organisations of 250 or more. The Plus audit is quoted individually based on the size and complexity of your network. Our support is quoted as a fixed price on top.
What happens if we fail?
Under the current scheme, a missing multi-factor authentication control on any cloud service fails the assessment outright, and it can no longer be remediated afterwards. This is why we run a readiness check first, sampling your devices ourselves in the same way an assessor will. It is much cheaper to find a problem there than during the audit.
How long is certification valid?
Annually, for both Cyber Essentials and Cyber Essentials Plus. We flag your renewal ahead of time, because letting it lapse mid-tender is an avoidable and annoying way to lose work.
Get started

Tell us your deadline

If you are facing a tender deadline, work backwards starting with gap analysis, remediation, basic certification, and finally the Plus audit. It is rarely a two-week job, so the earlier you start the less it costs in stress. Tell us your deadline and we will tell you if it is achievable.