A supplier questionnaire, tender requirement or board-level risk review can turn Cyber Essentials from a technical acronym into an urgent business decision. If you are asking what is Cyber Essentials Plus, the short answer is that it is an independently tested UK cyber security certification. It gives customers, partners and procurement teams evidence that your organisation has key security controls in place and that they work in practice.
For many small and mid-sized organisations, that evidence matters as much as the controls themselves. A well-written policy is useful, but it will not stop an unpatched laptop, a weak administrator account or an exposed remote access service from creating disruption. Cyber Essentials Plus is designed to check the practical basics that reduce those risks.
What Cyber Essentials Plus means
Cyber Essentials Plus is the higher level of the UK Government-backed Cyber Essentials scheme. It starts with the standard Cyber Essentials certification, which is based on a verified self-assessment questionnaire. Cyber Essentials Plus then adds an independent technical assessment by a certification body.
The scheme focuses on five core technical control areas: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. These are not obscure enterprise-only measures. They are the day-to-day disciplines that help prevent common attacks from becoming business interruptions.
The word “Plus” is significant. Rather than relying solely on your answers about how systems are configured, an assessor tests a sample of your organisation’s devices, users and internet-facing services. They look for evidence that the stated controls are operating as intended.
A successful assessment results in a Cyber Essentials Plus certificate, normally valid for 12 months. It can help demonstrate a measured approach to cyber risk when bidding for work, responding to supplier due diligence or reassuring customers who need confidence in how their information is handled.
How a Cyber Essentials Plus assessment works
The process begins with defining the scope. This means identifying the people, devices, applications, cloud services and locations covered by the certification. Scope is one of the most important decisions in the process. If a system is used to process business data or access the wider organisation’s network, it cannot simply be left out because it is inconvenient to assess.
Organisations usually complete Cyber Essentials first, then prepare for the additional tests required for Plus. An assessor will agree a sample from the agreed scope and carry out checks that may be performed remotely, on site, or through a combination of both. The exact approach depends on your environment, including whether staff work remotely, use personal devices, or rely heavily on cloud platforms.
The tests are practical, not theoretical
Cyber Essentials Plus assessments typically include checks such as external vulnerability scanning, testing of a sample of internal devices, reviews of user access, and checks that malware defences and security updates are working properly. The assessor may also test how devices respond to a controlled security scenario.
This is not intended to catch organisations out. It is intended to establish whether the fundamentals work under scrutiny. An organisation may have a patching policy, for example, but the assessment can reveal that several machines have not installed important updates. Equally, multi-factor authentication may be available in a cloud service but not enforced for all relevant accounts.
If an issue is found, there is normally an opportunity to remediate it and arrange retesting within the scheme’s permitted timescales. That makes preparation worthwhile. It is generally quicker and less disruptive to identify gaps before the formal assessment than to respond to findings during it.
The controls Cyber Essentials Plus examines
The scheme is deliberately focused. It does not attempt to assess every aspect of cyber security, but it does require consistent management of the controls most commonly linked to avoidable compromise.
- Boundary firewalls and internet gateways help control traffic entering and leaving your network. This includes internet-facing services, routers, firewalls and remote access arrangements.
- Secure configuration means devices and services are set up to reduce unnecessary exposure. Default passwords, unused accounts and unneeded software are common examples of avoidable risk.
- User access control ensures people have the access they need, but not more than they need. Administrative access should be tightly controlled, and accounts should be removed or changed when staff leave or change roles.
- Malware protection covers the measures used to prevent and detect malicious software. Depending on the environment, this may include endpoint protection, safe browsing controls and restrictions on how software can run.
- Security update management requires supported software and timely application of critical updates. Unsupported operating systems and applications are a frequent obstacle because they cannot be patched to the required standard.
These controls often expose operational weaknesses rather than a lack of effort. A school may have older specialist software tied to a legacy device. A manufacturer may rely on equipment that cannot tolerate unscheduled updates. A charity may have accumulated unmanaged laptops through years of flexible working. The answer is rarely to ignore the problem. It is to identify the risk, isolate or replace what is necessary, and make a workable plan.
Is Cyber Essentials Plus right for your organisation?
Cyber Essentials Plus is particularly valuable where assurance is being requested by someone outside the organisation. This may be a public sector contract, a larger customer, a framework supplier requirement or a partner handling sensitive information. Some contracts specify a particular level of Cyber Essentials as a condition of doing business, so checking the requirement early can prevent a last-minute bid issue.
It can also be useful when a leadership team wants independent confirmation that security basics are being managed properly. For an organisation without a large internal IT function, the assessment provides an objective checkpoint. It turns broad assurances into a clear outcome, with practical findings where improvement is needed.
That said, Plus is not automatically the right first step for every business. If your systems are poorly documented, devices are unmanaged, or staff access is inconsistent, completing standard Cyber Essentials and resolving its underlying issues may be the sensible starting point. Moving too quickly towards Plus can create avoidable retesting costs and place unnecessary pressure on internal teams.
The decision should be based on contractual needs, the sensitivity of the data you handle, your operational risk, and the current state of your technology estate. Certification is valuable when it supports a real business objective, rather than becoming a badge that is renewed without improving security.
What Cyber Essentials Plus does not cover
Cyber Essentials Plus is a strong baseline, not a complete cyber security programme. It does not replace regular backups, disaster recovery planning, security awareness training, incident response arrangements, monitoring, or a risk assessment tailored to your organisation.
It is also not the same as a full penetration test. The assessment checks defined controls and known technical conditions within the scheme. A penetration test is a broader, goal-led exercise designed to identify exploitable weaknesses in a specific environment. Many organisations need both at different points, particularly where they operate public-facing applications, hold sensitive data or support critical services.
The certificate also cannot guarantee that an organisation will never suffer a cyber incident. Phishing, fraud, supplier compromise and newly discovered vulnerabilities remain real risks. What it can do is show that common attack routes are being addressed with recognised, independently checked controls.
Preparing without disrupting the business
The most efficient route to Cyber Essentials Plus is to treat it as an operational improvement project, not a form-filling exercise. Start with a clear device and software inventory. Know who administers each service, where business data is stored, how remote access works, and which systems are no longer supported.
Next, review how updates are applied and evidenced. A patching process that depends on individual staff remembering to act is unlikely to be dependable at scale. Central management, defined ownership and regular reporting make it easier to maintain standards between certifications as well as during the assessment.
Access control deserves similar attention. Remove dormant accounts, separate everyday and administrative access where appropriate, and make sure multi-factor authentication is properly enforced. These changes can reduce risk quickly, but they must be planned around staff workflows so security does not create unnecessary friction.
For organisations with mixed office, home and site-based working, the practical challenge is often visibility. Devices cannot be secured consistently if nobody knows they exist or whether they are receiving updates. Managed monitoring, endpoint management and clear support processes help bring that visibility under control.
Cyber Essentials Plus is most useful when it becomes part of how technology is run: systems are maintained, access is reviewed and risks are dealt with before they affect productivity. CETSAT can help organisations prepare for that standard in a way that supports day-to-day operations, rather than adding another disconnected compliance task.

