Enquiries: +44 (0) 20 8584 1400

CONTACT

Cyber Essentials Plus: What It Is and How to Get Certified

Cyber Essentials Plus

The contract is worth seven figures and the security schedule runs to one page. Halfway down sits a single line: the supplier shall hold and maintain Cyber Essentials Plus certification for the duration of the engagement. Bid submission closes in three weeks.

This is how most UK businesses meet the scheme for the first time. Not as a security initiative anyone chose, but as a procurement condition with a date attached to it and no obvious owner.

What Is Cyber Essentials Plus?

Cyber Essentials Plus is the audited tier of the UK Government’s Cyber Essentials scheme. It covers the same five technical controls as the self-assessed certification, but a qualified assessor tests your systems directly instead of taking your word for it. Certification lasts twelve months and is renewed annually.

The five controls are firewalls, secure configuration, security update management, user access control and malware protection. Nothing exotic. The difference at the audited tier is verification: somebody connects to a sample of your machines and checks.

The scheme is owned by the National Cyber Security Centre and delivered by IASME through a network of licensed Certification Bodies.

Why Buyers Keep Asking For It

Because it is the cheapest credible way to check that a supplier is not an obvious liability. A growing number of public and private sector contracts now name it as a condition of bidding, and it is a standing requirement across large parts of central government procurement.

Transputec holds the audited certification alongside ISO 27001, ISO 9001 and ISO 14001, and we are asked to evidence all four regularly. The pattern in supplier questionnaires is consistent: the audited certificate is what closes the question, because an assessor’s testing sits behind it rather than a signature.

The scheme also carries a side benefit that rarely gets mentioned in the sales conversation. Any UK organisation with turnover under £20m that certifies its whole organisation is automatically entitled to cyber liability insurance arranged by IASME, including incident response support.

Need Cyber Essentials Plus Before a Bid Deadline?

Tell us what your estate looks like and when the deadline falls. We will map the gap between where you are today and what the audit tests, so you know exactly what has to change and in what order.

Get a Strategic Consultation

What Is the Difference Between Cyber Essentials and Cyber Essentials Plus?

The requirements are identical. The evidence is not. The base certification is a verified self-assessment marked by an assessor, while the audited tier adds hands-on technical testing of your real systems.

AreaCyber EssentialsThe Audited Tier
How it is assessedSelf-assessment questionnaire, signed off by a board member and marked by an assessorEverything in the base tier, plus an assessor testing your systems directly
What gets testedYour written answersA sample of user devices, all internet gateways, all internet-facing servers
Cost basisFixed fee by headcount band, from £320 + VATQuoted by size and complexity of your network
Typical effortDays of preparation for a tidy estateWeeks, because gaps have to be closed before testing
What it proves to a buyerYou say the controls are in placeAn independent assessor confirmed they work

You cannot go straight to the audited tier. The self-assessed certificate is a prerequisite, and the audit must be completed within three months of achieving it. The scope of both must match, so an organisation that certified one department cannot present a whole-company certificate at the higher level.

How Much Does Cyber Essentials Plus Cost?

There is no fixed price at the audited level. IASME sets the self-assessment fee by organisation size and quotes the audit by the size and complexity of your network, so Certification Bodies price each engagement individually.

The self-assessment fees published by IASME are fixed and public:

  • 0 to 9 employees: £320 + VAT
  • 10 to 49 employees: £440 + VAT
  • 50 to 249 employees: £500 + VAT
  • 250 or more employees: £600 + VAT

The audit sits on top of that and is quoted separately. Most UK SMEs should plan for a four-figure sum, driven by device count, number of sites, and how many operating systems and cloud services fall inside scope.

The line that catches people out is remediation. If testing finds unsupported software, patch gaps or accounts without multi-factor authentication, fixing those is where the real budget goes. Costing the audit without costing the remediation is the most common planning error we see, and it is usually the difference between a comfortable project and an awkward conversation with finance.

What Does the Audit Actually Test?

An assessor tests a representative sample of your in-scope systems, typically around ten per cent of user devices, together with all internet gateways and every server running services reachable by unauthenticated internet users.

The testing covers:

  • Vulnerability scanning on sampled devices, looking for missing high and critical patches and any software past its supported life.
  • Malware delivery by email, sending harmless test files to see whether your filtering stops them.
  • Malware delivery by browser, doing the same through a web download.
  • Account and access checks, including multi-factor authentication on cloud services and separation of administrative accounts.
  • Configuration review on the sampled machines against each of the five controls.

The assessor decides after the initial sample whether wider testing is warranted. One problem device usually means more devices get examined rather than an immediate fail, which is why an accurate asset list matters more than a tidy sample.

How Do You Pass Cyber Essentials Plus First Time?

Fix the five controls across the whole estate before booking the audit, not only on the machines you expect to be sampled. Sampling is the assessor’s choice, and preparing selectively is the fastest route to a failure.

A sequence that works:

  1. Define scope precisely. Decide whether you are certifying the whole organisation or a defined subset, and be able to defend where the boundary sits.
  2. Build an accurate asset list. Every laptop, desktop, mobile, server and cloud service. Devices nobody remembered are a frequent cause of failure.
  3. Remove unsupported software. Anything past its vendor support date fails automatically, including old operating systems on machines that fell out of the refresh cycle.
  4. Get patching inside fourteen days. High and critical severity updates must be applied within fourteen days of release.
  5. Enable multi-factor authentication across cloud services, and separate administrative accounts from day-to-day ones.
  6. Verify malware protection is active and updating on every device, not most of them.
  7. Run a dry run using the free IASME readiness tool before the assessor arrives.

Transputec prepares client estates for this through our cyber security services and managed IT services. The pattern is consistent: organisations with centrally managed devices and automated patching pass comfortably, while those relying on users to update their own machines rarely do.

Why Do Organisations Fail the Audit?

Almost always because of something that was already true long before the assessor arrived. The audit does not create problems, it finds them.

The recurring causes:

  • Unsupported software still running, usually on a machine that dropped out of the refresh cycle years ago.
  • Patch gaps beyond fourteen days, most often on devices belonging to people who rarely restart them.
  • Missing multi-factor authentication on a cloud service nobody classed as in scope.
  • Shared or generic accounts holding administrative rights.
  • Scope drawn too loosely, pulling in systems the organisation never intended to certify.
  • Unmanaged personal devices reaching organisational data without controls in place.

Every one of these is fixable, and every one is considerably cheaper to fix before the audit than after a failed attempt. A failure also costs you time against the three-month window, which is where a bid deadline starts to look uncomfortable.

How Long Does Certification Take?

Allow six to twelve weeks end to end for a first certification, though a well-managed estate can move faster. The assessment itself is quick. The preparation is not.

A realistic timeline:

  • Weeks one to six: scoping, asset discovery and remediation. This is where the time actually goes.
  • Week six or seven: complete the self-assessment. Assessors review submissions within three working days, and you can update and resubmit if they need clarification.
  • Weeks seven to nine: the technical audit, which must fall within three months of the self-assessment.
  • On success: certificate issued, valid for twelve months.

If a contract deadline is driving this, work backwards from it and start scoping now. The three-month window between the two stages is the constraint most organisations discover far too late, and it cannot be extended.

Conclusion

The certificate is not really the point. What the audit checks is whether the basics are working on real machines rather than described accurately in a policy document, and most organisations that fail already knew about the gap that caught them.

Treated as a one-off compliance exercise, this becomes an annual scramble against a renewal date. Treated as a yearly check on controls you maintain anyway, it becomes routine, and the certificate stops being the thing that blocks a bid.

Transputec holds Cyber Essentials Plus, ISO 27001, ISO 9001 and ISO 14001, and we prepare client estates for the audit as part of our managed IT and security work. If a contract deadline is driving your timeline, or a previous attempt did not go to plan, talk to our UK team about what your estate would need. Our current accreditations are listed on the certifications page.

FAQs

The audit is quoted individually by a Certification Body, based on the size and complexity of your network, so there is no published price. The self-assessment underneath it is fixed by IASME at £320 to £600 + VAT depending on headcount. Budget for remediation as well, because closing gaps found during preparation usually costs more than the certification fees themselves.

The technical requirements do not change at all. What changes is how they are verified. The base level is a self-assessment questionnaire marked by an assessor, while the higher level adds independent testing of a sample of your devices, your internet gateways and your internet-facing servers. Buyers ask for the audited version when a signature alone is not enough assurance.

Twelve months, then it needs renewing. Start preparation for the renewal roughly two months before expiry rather than treating it as a fresh project each year. Organisations that keep patching, asset records and access controls current throughout the year find renewal straightforward, which is the practical argument for folding it into managed IT services rather than running it as a standalone exercise.

Yes. The verified self-assessment is a prerequisite, and the audit must take place within three months of achieving it. The scope of both has to match. If you certify at the base level and then let more than three months pass, you will need to repeat the self-assessment before the audit can proceed, so sequence the two deliberately rather than treating them as separate purchases.

You fix what the assessor found and get retested, though the terms and any additional fee depend on your Certification Body, so check that before you engage one. The larger cost is time, because the three-month window from your self-assessment keeps running. Where a bid deadline is involved, a gap analysis before the formal audit is a sensible investment. Transputec’s cyber security team can run that assessment first.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Share Blog »

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his “straight-talking” approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.
← Blogs

Contact

Get in Touch