Cyber Essentials Plus (CE+, also called CE Plus) covers the same five controls as Cyber Essentials (CE), verified by a hands-on technical audit of your systems. It is the level most larger customers, public sector bodies and insurers look for.

Every client we have taken through an accreditation has achieved it - and kept it at every renewal.
We submit ourselves to independent third-party testing. Certification is always issued by an independent body, never by us.
We prove each control works on your real devices and services. Questionnaire answers can be inaccurate or optimistic; tests cannot.
We will look at your current position for free and tell you exactly which controls you need - with no obligation.
Cyber Essentials Plus - usually shortened to CE+ or CE Plus - builds on Cyber Essentials (CE). Where the basic CE certificate relies on your answers, CE+ adds an independent technical audit that proves the controls work in practice.
An assessor tests a representative sample of your user devices, all internet gateways and any servers reachable from the internet. The audit must be completed within three months of achieving Cyber Essentials.
Because it is tested rather than self-declared, CE Plus carries far more weight with customers, procurement teams and insurers than CE alone.
Your internet-facing IP addresses and services are scanned for known vulnerabilities and misconfigurations.
A sample of laptops, desktops, servers and mobiles is checked for missing security updates and unsupported software.
Test files are sent by email and downloaded in the browser to prove your malware protection blocks them.
Assessors confirm day-to-day users do not have admin rights and that admin accounts are used only for admin tasks.
Cloud services are checked to confirm MFA is enforced for all users.
We review your devices, cloud services and processes against Cyber Essentials Plus and show you where you stand.
We fix or guide you through every control that would fail, in priority order.
We prove each control works - scans, patch checks, malware tests, restores and MFA checks - before anyone else looks.
An independent assessor, auditor or certification body confirms it. We never certify our own work.
We monitor your controls in real time and fix drift as it happens, so renewal is a normal day, not a cliff edge.
Our own intellectual property is how we run compliance: we monitor the major Cyber Essentials Plus controls in real time using the leading enterprise SaaS tools. That lets us map gaps and bridge controls quickly and accurately while you work towards accreditation - and then keep standards up, and risk down, every day after it.
We watch the major controls continuously using leading enterprise SaaS security and compliance tools - not once a year with a questionnaire.
Live data shows exactly which controls are missing or drifting, so we can map the gaps and bridge them quickly and accurately.
Every change to your systems follows a compliant change process, so an upgrade or a new starter never quietly breaks a control.
Issues are picked up and fixed as they happen. Your risk goes down over the year instead of creeping up until the next audit.
Annual review is not viable in the current threat landscape. Attackers do not wait twelve months - so neither do we.
Prices exclude VAT. Payment is taken securely by instant bank payment through GoCardless and we contact you within one working day to start.
You facilitate access to your digital systems for testing
Certification is a snapshot. Our compliance plans keep the controls tested, the evidence current and renewals handled - Level 1 demonstrates, Level 2 practises and Level 3 proves compliance continuously.
CE and Digital GDPR Controls - Our consultants will complete the CE submission with input from your staff.
CE, CE+ and Digital GDPR Controls -Monitoring & Submission as a Service (Submission following Quarter)
CE, CE+, GDPR Governance, Supply Chain Audits, Pen Testing, Vulnerability Scanning, (Real-time Maintained) Compliance As A Service
Yes. CE+, CE Plus and Cyber Essentials Plus are all names for the same IASME certification: the technically audited level of the UK Cyber Essentials scheme. CE on its own refers to the basic, self-assessed Cyber Essentials certificate.
Yes. Cyber Essentials Plus is always preceded by the Cyber Essentials (CE) self-assessment, and the CE+ audit must be completed within three months of it.
Before the assessor arrives we run the same style of tests ourselves - vulnerability scans, patch checks, malware tests and MFA checks - and fix what fails. We then book the independent audit. That is how our clients achieve and keep Plus.
Typically one to two days of testing depending on the size of your estate, followed by the assessor's report.
You give the assessor access to your systems and devices for testing. If you would rather we prepare everything and remediate the gaps first, choose one of our Level plans or ask us for a supported quote.
The online price covers a typical single-site organisation. If your estate is larger or more complex we will confirm any difference before testing starts.
We monitor the major controls in real time using leading enterprise SaaS tools, with compliant change management behind every change. Gaps are found and bridged quickly, standards are maintained every day, and accreditation stops being a fraught cliff edge - you can say you were compliant yesterday, not a year ago.
Controls drift: devices miss patches, accounts change, new services appear. With an annual review that drift goes unnoticed for months while risk rises. Real-time monitoring catches it as it happens, so issues are fixed quickly and your compliance improves rather than decays.
Book a free, no-obligation Cyber Essentials Plus assessment. We will show you which controls you already meet, which you need, and the quickest route to getting certified.