
Cyber Essentials Plus
Somebody asked you for Plus.
Here is what actually happens.
Plus is the same five controls as basic Cyber Essentials, tested by an assessor instead of declared by you. Most of the anxiety is about the audit day. Most of the work is what you fix before it.
The audit, stage by stage
What the assessor actually does
Five stages, and what you need to have ready for each. Nothing here is a surprise on the day if you have read this first.
Stage 1 of 5
Agreeing what gets tested
Before anything is scanned, you and the assessor agree the scope: which offices, which cloud services, which devices, and whether home and personal devices are in. A sample of user devices is then selected to represent each different build you run, rather than every machine you own. The sample is set from IASME's test specification and agreed with your assessor before testing starts.
Have ready
- A device list covering every operating system and build in use
- A list of cloud services, including the ones a department bought without telling IT
- Your external IP addresses
Which one do you need
Basic and Plus, side by side
If nobody has specifically asked you for Plus, basic certification is almost always the right place to start.
Work out your exact fee, including both levels, on the Cyber Essentials cost calculator.
Before you book
The three month clock is the real risk
You have three months from your basic certificate to complete Plus. Businesses rarely fail Plus outright. They run out of time fixing what the first scan found, and have to start again at basic.
Scan first, book second
For clients we run the same kind of authenticated scan the assessor will, before the clock starts. What it finds is the actual work list, and it turns up in week one rather than week ten.
Fix the slow things early
Replacing end of life kit and untangling shared admin accounts takes weeks and often needs budget. MFA and patching policy take hours. Start with the ones that need a purchase order.
Then certify both together
With remediation done, basic and Plus can run back to back comfortably inside the window, and the audit day becomes a formality rather than an inspection.
This is work we do for managed service clients, not something we sell on its own. By the time Plus comes up, most of the controls are already in place, because patching, MFA and device management are what the service does anyway. That is the whole reason a client passes an audit that catches other people out.
Questions we get asked
Cyber Essentials Plus, answered
What is Cyber Essentials Plus?
Cyber Essentials Plus covers exactly the same five technical controls as basic Cyber Essentials, but instead of you declaring that the controls are in place, an IASME approved assessor tests them. That means an external vulnerability scan, an authenticated scan of a sample of your devices, live malware protection tests, and a hands on check of configuration and multi factor authentication.
Do I need basic Cyber Essentials before Plus?
Yes. You must hold a valid basic Cyber Essentials certificate before you can be assessed for Plus, and you have three months from receiving it to complete the Plus assessment. Miss that window and you have to recertify at basic level first.
How much does Cyber Essentials Plus cost?
Plus is priced on the size and complexity of your network rather than a fixed fee, typically from around £1,400 + VAT for a small business up to £3,000 or more for a larger or more complex estate. That sits on top of the basic certification fee, which is set by IASME and runs from £320 to £600 + VAT depending on how many people you employ.
Does the assessor test every device we own?
No. A sample of devices is tested, chosen to represent each different build you run rather than every machine. The sample size comes from IASME's test specification and is agreed with your assessor before testing begins. Servers and cloud services in scope are treated separately from the user device sample.
What happens if we fail part of the audit?
Failing a test is common and is not the end of the process. You are told what failed, you fix it, and the assessor retests. What matters is the three month window from your basic certificate, so the practical risk is running out of time rather than failing outright. That is why the remediation work is worth doing before the audit is booked.
How long does the Cyber Essentials Plus audit take?
The testing itself is usually a day or less for a small estate, sometimes split across a couple of sessions. The preparation is the part that takes real time. Where businesses lose weeks it is almost always fixing what the scan finds rather than the assessment day.
Is Cyber Essentials Plus the same as ISO 27001?
No, and they are not alternatives. Cyber Essentials Plus is a technical baseline verified by testing, achievable in weeks. ISO 27001 is an information security management system covering policy, risk assessment, governance and continual improvement, audited annually and typically taking months. Most UK SMEs treat Cyber Essentials as the starting point and ISO 27001 as the destination.
Will AIS take us through Plus if you do not manage our IT?
No. Plus is an audit of your live systems, and preparing an estate we do not run would mean guessing at answers an assessor is about to verify with a scan. That helps nobody. We take managed service clients through Plus because we already know what is on the network and can fix what the pre audit scan finds. If Plus is a contract requirement for you, the conversation to have is about your IT, not about the certificate.
Who actually needs Plus rather than basic?
Usually someone has told you to get it. Government contracts handling sensitive or personal data commonly specify Plus, as do many large enterprise supplier frameworks, insurers, and clients in financial services and healthcare. If nobody is asking for Plus, basic certification plus the insurance that comes with it is normally the right place to start.
Plus, Without the Scramble
We take managed service clients through Cyber Essentials Plus as part of looking after their IT. If you want that, the conversation starts with your IT rather than with the certificate.
AIS Technology, Woodland Place, Hurricane Way, Wickford, SS11 8YB
