
Pass the independent Cyber Essentials Plus audit first time.
Plus replaces self-declared answers with hands-on verification. We run the same checks the assessor will run — scanning, device sampling, MFA and patch validation — before the audit date is booked, not after it exposes a gap.
An assessor tests what's true, not what's declared.
Cyber Essentials Plus exists because self-assessment, however carefully completed, is still an honesty system. The Plus audit removes the ambiguity: an accredited assessor independently verifies the same five control areas — firewalls, secure configuration, access control, malware protection and patch management — using vulnerability scanning and direct inspection of a representative sample of your devices, rather than relying on a questionnaire answer.
This is where organisations that comfortably passed their base Cyber Essentials self-assessment sometimes stumble. A questionnaire answer of 'yes, patches are applied within fourteen days' is easy to write; demonstrating it across every sampled device, including the laptop that was on annual leave during the last deployment window, is a different exercise entirely. The gap between declared policy and actual configuration is exactly what the audit is designed to find.
Device sampling adds a further wrinkle. The assessor doesn't check everything — they check a representative sample, and if that sample turns up inconsistency, they're entitled to widen it. That means a single poorly configured laptop can turn into a much larger conversation if it suggests your patch management or MFA enforcement isn't applied consistently across the estate rather than to a curated few machines.
There's a scheduling pressure too. Once an audit date is booked, most organisations don't want to move it — assessors have limited availability and rebooking costs time and, often, money. That creates an incentive to book the date before verifying readiness, which is precisely how avoidable failures happen: a gap that would have taken two days to fix instead surfaces during the audit itself, in front of the assessor, with the date already committed.
- Self-declared answers that don't hold up under independent scanning
- Sampled devices exposing inconsistent patch or MFA enforcement
- Local admin rights reintroduced after rebuilds or new starters
- Audit dates booked before technical readiness is actually confirmed
We run the audit's checks before the assessor does.
Our starting point is to replicate, as closely as possible, what the certification body's assessor will actually do: external and internal vulnerability scans, a review of patch compliance against the fourteen-day critical and high-severity window, verification that MFA is enforced everywhere it's required, and a check of local administrator rights across a representative cross-section of your device estate.
Where the scanning or sampling turns up gaps, we prioritise fixes by what would fail the audit outright versus what's a minor inconsistency worth tidying up. Devices that are simply missing from automated patch management — often because they were offline, personally owned, or set up outside the standard build — get particular attention, since they're the most common cause of audit failure.
We then run a pre-audit sample review of our own, checking the same style of representative cross-section an assessor would pick, so you have direct evidence of consistency before the real audit rather than hoping the sample lands favourably. This is the step most self-managed preparations skip, and it's the one that catches problems while there's still time to fix them without moving the booked date.
Once we're confident the estate would pass, we help you book the audit with a certification body and brief whoever will be on hand during the assessment — usually IT or an operations lead — on what to expect and how to respond to assessor questions about specific devices or configurations.
- Full vulnerability scan mirroring the assessor's external and internal checks
- Patch compliance verification against the fourteen-day window
- MFA and local admin rights review across a representative device sample
- Dry-run sample review before the certification body's date is booked
Everything in the engagement, set out up front.
Technical verification and remediation support that mirrors the Cyber Essentials Plus audit itself.
Pre-audit vulnerability scan
External and internal scanning matched to the checks a Plus assessor will run against your network.
Patch compliance verification
Confirmation that critical and high-severity updates are applied across the estate within the required window.
MFA enforcement review
Checks across cloud services and remote access to confirm multi-factor authentication is genuinely enforced, not just enabled.
Device sampling exercise
A representative cross-section reviewed the way an assessor would sample it, surfacing inconsistency before the audit does.
Local admin rights audit
Identification of unnecessary administrative privileges left on user devices after rebuilds or role changes.
Audit-day briefing
Preparation for whoever will support the assessor, covering likely questions and how to evidence each control quickly.
What you receive.
- Vulnerability scan report with remediation priorities
- Patch compliance summary by device
- MFA enforcement status across all cloud services
- Device sample review findings
- Local admin rights remediation list
- Pre-audit readiness statement
- Audit-day briefing notes
- Recommended certification body and booking support
- Post-audit remediation plan if any non-conformities are raised
Built for organisations that need the work done properly.
Organisations already Cyber Essentials certified
Businesses with a current self-assessment certificate now required to move to independent verification.
Firms bidding for public sector or NHS contracts
Tenders that specifically require Cyber Essentials Plus rather than the base certificate.
Regulated organisations under client pressure
Legal, healthcare and financial services firms whose clients or insurers now expect independently verified controls.
Businesses that failed or deferred a previous audit
Organisations that had a difficult first attempt and want the gaps properly closed before rebooking.
What changes once the work is done.
What a properly prepared Plus audit delivers beyond the certificate itself.
Audit passed without last-minute surprises
Fixes identified and resolved before the assessor arrives, rather than discovered during the assessment.
Independently verified controls
A certificate backed by evidence, not just declaration, which carries more weight with clients and insurers.
Consistent estate, not a curated sample
Confidence that every device meets the standard, not just the ones checked on audit day.
Reduced re-audit risk
Lower chance of non-conformities that require a costly and time-consuming re-test.
Stronger tender and procurement position
Plus certification satisfies the higher bar increasingly set by public sector and NHS procurement.
A repeatable annual process
A documented pre-audit routine that makes next year's renewal considerably less demanding.
Why the independent audit is worth the extra rigour.
It's reasonable to ask whether Plus is worth the additional cost and disruption over the base certificate. In our experience, the answer depends on what you're using the certification for. If it's purely a supplier checklist item, the base certificate may be sufficient. If it's underpinning a client contract, a tender requirement, or an insurance renewal where the underwriter wants assurance the controls are real, the independent verification in Plus carries meaningfully more weight — and increasingly, procurement teams in the public sector and NHS specify it directly rather than accepting the self-assessed version.
The technical bar in Plus is not dramatically higher than the base certificate on paper — it's the same five control areas. What changes is that declared compliance has to survive scanning and sampling rather than a written answer. That distinction matters because it's exactly the gap that separates organisations with genuinely embedded security hygiene from those that completed a form accurately but haven't kept the underlying configuration consistent since.
We see this most often with patch management. Automated patch tools give a strong average compliance figure, but averages hide the handful of devices that fell outside the process — the laptop that was on leave, the meeting room PC nobody thinks about, the personally managed device used for email. A Plus assessor's sample has a reasonable chance of finding exactly that device, which is why our pre-audit sampling deliberately looks for the outliers rather than confirming the average.
We support clients through this process across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, working alongside existing IT providers rather than replacing them. Our role is to verify readiness honestly, tell you where the risk of failure actually sits, and make sure the audit date you book is one you're genuinely ready for.
Questions we are asked most often.
What's the difference between Cyber Essentials and Cyber Essentials Plus?
The base Cyber Essentials certificate relies on self-assessment: you answer the questionnaire and a certification body marks it. Cyber Essentials Plus adds an independent, hands-on technical audit — an assessor visits (or connects remotely) to verify the same five controls through vulnerability scanning, configuration checks and a sample of real devices, rather than taking the questionnaire's answers on trust.
How is the device sample chosen for the audit?
The assessor selects a representative sample across your device types, operating systems and locations, rather than testing every single machine. The sample size scales with the size of your organisation. If the sample reveals inconsistencies — one laptop patched differently to the rest, for instance — the assessor can widen the sample, which is why consistency across the whole estate matters more than any single device.
What does the technical audit actually test?
External and internal vulnerability scanning, verification of patch levels against the fourteen-day critical and high-severity window, checks that multi-factor authentication is enforced on cloud services, confirmation that malware protection is active and up to date, and a review of user account privileges to catch unnecessary local administrator rights.
Do we need Cyber Essentials before Plus?
Yes, a current Cyber Essentials self-assessment certificate is a prerequisite and must be in place before the Plus audit can be scheduled. Many organisations complete both close together, using the base certification process to fix the obvious gaps before the independent audit tests everything more rigorously.
What typically causes a Plus audit to fail?
Inconsistent patching is the most common cause — devices missed by automated patch management, particularly laptops that were offline during a deployment window. MFA gaps on secondary cloud accounts, local admin rights left on user devices after a rebuild, and out-of-date anti-malware definitions on a handful of machines account for most of the remainder.
How long does preparation take?
Where the base Cyber Essentials controls are already solid, we typically recommend two to three weeks of focused technical verification before booking the audit date. Where there are known gaps — inconsistent MFA enforcement or patching discipline, for example — four to six weeks gives enough time to fix and re-verify before the assessor arrives.
Is the audit disruptive to day-to-day operations?
The scanning and device checks are designed to be non-intrusive and are scheduled around your working hours. Most organisations experience no noticeable disruption. The larger time cost is internal — making sure the right people are available to grant access and answer questions about specific devices or configurations during the audit window.
How long is Cyber Essentials Plus valid for?
Twelve months, the same cycle as the base certificate. Because Plus verifies real configuration rather than declared answers, it tends to surface drift earlier — a laptop reissued without the standard build, or a new starter added to a system without MFA — which is why we recommend a lightweight interim check around the six-month mark.
Compliance support
Wider framework support spanning ISO 27001, NHS DSPT, PCI DSS and FCA-driven controls.
Penetration testing
Deeper technical testing beyond the Plus audit scope, for organisations with a higher-risk attack surface.
Vulnerability management as a service
Ongoing scanning and patch tracking that keeps you audit-ready between annual Plus assessments.
Considering Cyber Essentials Plus?
Request a free technical review and we'll show you, honestly, where your estate stands against the audit's actual checks before you book a date.
Request a free technical review