Skip to content

Home » Cyber Essentials Plus

Cyber Essentials Plus

Book a call

Cyber Essentials Plus, tested and certified directly by an IASME certification body

Cyber Essentials Plus is the independently tested level of the UK government’s Cyber Essentials scheme. Incursion Cyber Security is an IASME-licensed certification body for Cyber Essentials Plus, so we carry out the assessment and issue the certificate ourselves. Our assessors are penetration testers with UK Cyber Security Council professional titles, and we work with organisations across the UK.

What Cyber Essentials Plus is

Cyber Essentials has two levels. The basic level is a verified self-assessment: you answer a question set covering the five technical controls (firewalls, secure configuration, security update management, user access control and malware protection) and a certification body checks your answers. Cyber Essentials Plus covers the same five controls, but an assessor tests them on your systems instead of taking your word for it. That is the difference, and it is why larger clients, insurers and public sector buyers increasingly ask for Plus rather than the basic certificate.

The scheme is owned by the National Cyber Security Centre and delivered by IASME. Certificates are valid for 12 months.

What the assessor tests

A Cyber Essentials Plus assessment covers a representative sample of your user devices, every internet gateway, and every server with a service reachable from the internet. On those systems the assessor carries out:

An external vulnerability scan of each public-facing IP address, to check the perimeter for exposed services and known vulnerabilities.

An authenticated internal scan of the sampled devices and servers, run with credentials so it sees what a logged-in user would see, including missing security updates and unsupported software.

Malware protection tests: test files are sent by email and downloaded through the browser, and the assessor watches whether your controls stop them.

Configuration checks: that high and critical security updates are applied within 14 days of release, that administrator accounts are separate from day-to-day user accounts, and that multi-factor authentication is enforced on cloud services.

Assessments are normally carried out remotely using a screen-sharing session with a member of your team. On-site assessment is available where your environment needs it.

The timing rule

You must hold a current basic Cyber Essentials certificate before Plus, and the Plus assessment must be completed within 90 days of that certificate’s issue date. Miss the window and the basic assessment has to be repeated first. We plan both together so this does not happen: the basic assessment is submitted, the Plus assessment is booked into the window, and remediation time is built in between the two. If the first Plus assessment fails, the retest must be completed within 30 days and still inside the same 90-day window, so we leave room for it when we book.

How we run it

01

Scoping. We confirm your organisation size and send a short set of standard questions about your devices, users, cloud services and networks. An assessor reviews the answers before we issue a fixed proposal. A call with an assessor is available if you want one.

02

Basic Cyber Essentials. If you do not already hold it, we take you through the self-assessment question set and verify it. If you do, we check the date and plan the Plus assessment inside the 90-day window.

03

Assessment. Carried out by a named assessor. One day for micro and small organisations, one to two days for medium, three or more for large.

04

Result and certificate. A pass is certified by us as the certification body and recorded on the IASME and NCSC registers. A fail comes with a written list of exactly what failed and why. The scheme requires the retest to be completed within 30 days, and we do that retest free of charge as standard.

What most commonly fails

From our own assessments, the same five things account for most failures: high or critical security updates older than 14 days on a sampled device; multi-factor authentication not enforced on a cloud service; software that is out of support still installed; missing registry keys on Windows machines that leave a control configured but not enforced; and devices, cloud services or users that were left off the scope declaration. All five are fixable before the assessment if you know to look.

What it costs

Cyber Essentials Plus is priced by organisation size. The price is fixed once the scope is agreed and does not change unless the scope does.

Organisation sizeCyber Essentials (basic)Cyber Essentials Plus
Micro (0–9 employees)£320£1,000
Small (10–49 employees)£440£1,600
Medium (50–249 employees)£500£3,000
Large (250–10,000 employees)£600Price on scoping
Enterprise (10,000+ employees)£600Price on scoping

All prices are plus VAT. Basic Cyber Essentials prices are set nationally by IASME and are the same at every certification body. The Cyber Essentials Plus price is in addition to the basic certificate and covers the assessment, the certificate and, if you fail first time, the retest, which we include free as standard. Large and enterprise organisations are priced after a scoping call, because the number of sites, devices and servers in scope varies too much for a list price.

Who needs it

Cyber Essentials Plus is required or expected for most central government contracts involving personal or sensitive data, for many NHS, local authority and education suppliers, for a growing number of defence and aerospace supply chains, and increasingly by cyber insurers as a condition of cover. Outside those requirements, it is the fastest recognised way for a small or medium organisation to show a customer that its basic controls have been tested by someone independent.

Cyber Essentials Plus and penetration testing

They are different things and one does not replace the other. Cyber Essentials Plus checks that five baseline controls are in place and working. A penetration test looks for the ways an attacker would actually get in, including through things the five controls do not cover, such as application logic, misconfigured cloud services and people. Many organisations do Plus first because it is required, then a penetration test because it is useful. Because our assessors are also penetration testers, we can scope both in one conversation. See penetration testing alongside Cyber Essentials Plus.

Frequently asked questions

How long does a Cyber Essentials Plus assessment take?

One day for micro and small organisations (up to 49 employees), one to two days for medium (50 to 249), and three or more days for large and enterprise organisations. We confirm at scoping.

Do I need basic Cyber Essentials first?

Yes. Plus can only be assessed against a current basic certificate, and within 90 days of its issue date. We can do both.

What happens if we fail?

You get a written list of each failed item and why. The scheme requires the retest to be completed within 30 days of the failed assessment, and still inside the 90-day window from your basic certificate. We do that retest free of charge as standard; many certification bodies charge for it. Failing is not recorded publicly.

Can the assessment be done remotely?

Yes, and most are. The assessor works through a screen-sharing session with someone from your team who has administrative access. On-site is available where needed.

How much does Cyber Essentials Plus cost?

From £1,000 plus VAT for a micro organisation to £3,000 plus VAT for a medium one; large and enterprise organisations are priced on scoping. The full table is above. The price is fixed once your scoping answers have been reviewed, and includes the retest if you fail first time.

Are you the certification body, or do you prepare us for someone else?

We are the certification body. Incursion Cyber Security is licensed by IASME to assess and certify Cyber Essentials, Cyber Essentials Plus and IASME Cyber Assurance. You can check our listing in the IASME certification body directory, and see everything we hold on our accreditations page.

Ready to get certified?

Book a call. Our sales team will set it up and handle the proposal, and a qualified assessor will review everything before your booking is confirmed.