The independently verified level of Cyber Essentials - a third-party technical audit confirming your security controls are correctly implemented. Preferred by government supply chains and enterprise clients.
Cyber Essentials Plus is the higher level of the Cyber Essentials scheme. While standard Cyber Essentials uses a self-assessment questionnaire, Plus requires an independent technical audit carried out by an approved assessor.
Our assessors remotely verify that your five security controls are correctly and effectively implemented - not just ticked on a form.
Who Requires CE Plus?
MOD and central government supply chain contracts
Organisations handling classified or sensitive data
Plus: higher assurance, preferred for enterprise and government
WHAT THE AUDIT COVERS
Our remote technical audit verifies all five Cyber Essentials controls are correctly implemented across your devices, systems and network.
Every CE Plus engagement includes a Pre-Assessment Check as standard - we review your controls against CE Plus requirements before the audit begins, so gaps are resolved before the assessment date, not during it. Most certification bodies skip this step.
DEVICE TESTING
We test a sample of in-scope devices - typically around 10% - including laptops, desktops and mobile, to verify configuration and patch status.
NETWORK SCANNING
External vulnerability scanning of your internet-facing systems and boundary controls.
MALWARE SIMULATION
Safe simulated malware testing to verify your protection is working correctly.
EVIDENCE REVIEW
Review of configuration evidence and security policies to support questionnaire responses.
// Step by Step
YOUR CE PLUS JOURNEY
Seven clear steps from booking to certification.
1
BOOKING YOUR AUDIT
Complete our online enquiry form and we will schedule your assessment at a time that suits you.
2
VULNERABILITY SCANNING & PREPARATION
We will provide access to our secure cloud scanning agent, or work with your existing PCI-DSS approved scanner if you have one.
3
DOCUMENTATION
You will need to submit an up-to-date asset list and return an Audit Authorisation Form before the assessment begins.
4
PRE-ASSESSMENT CHECK
Before the audit begins, we review your controls against CE Plus requirements in full. Any gaps are identified and resolved with you ahead of the assessment date - so you go in prepared, not surprised.
5
DEVICE SAMPLING
Up to three days before audit day, we confirm the device sample - typically around 10% of in-scope devices, selected by the auditor, not the client.
6
AUDIT DAY
Your auditor conducts internal and external vulnerability scans, email and download security tests, antivirus and mobile checks, and MFA verification - all via screen share. Use our readiness checklist to prepare.
7
AFTER YOUR AUDIT
It is normal to have a few outstanding actions after the live session. Your auditor will clearly outline what is needed, how to submit evidence, and the deadline for completion.
// Audit Readiness
CE PLUS READINESS CHECKLIST
The CE Plus audit is a hands-on technical test - not a questionnaire. Seven control areas are assessed live against your systems. Use our interactive checklist to confirm everything is in place before your assessment date.
Use our free interactive checklist - 25 items across all seven audit areas with a live progress score. Tick off each item as you confirm it is in place.
Important: If any of these areas are not in place before the audit, issues will be identified during the technical assessment. You have 30 days from the assessment start date to remediate - within the 90-day window from your CE basic certification date. Both windows run simultaneously, so there is very little margin for last-minute fixes.
// Transparent Pricing
HOW MUCH DOES CYBER ESSENTIALS PLUS COST?
All prices are fixed and include the IASME certification fee. No hidden charges.
Organisation Size
Employees
Price + VAT
Micro
1–9 employees
£1,295
Small
10–49 employees
£1,799
Medium
50–249 employees
£2,599
Large
250+ employees
£4,299
FREE CYBER LIABILITY INSURANCE - UP TO £25,000
UK organisations with annual turnover under £20m automatically receive free cyber liability insurance up to £25,000 with their Cyber Essentials certificate - which is included within your CE Plus engagement. No extra cost, no separate application.
// Bundle & Save
NEED CYBER ESSENTIALS FIRST? SAVE 5% ON THE BUNDLE
Cyber Essentials is a mandatory prerequisite for CE Plus. If you need both, buy them together and receive a 5% bundle discount off the combined price - the saving is applied automatically when you select both in the quote builder.
Before your formal CE Plus audit begins, we review your controls against CE Plus requirements, identify any gaps, and give you the opportunity to remediate - reducing the risk of a failed assessment. Included as standard with all CE Plus assessments at no additional charge.
// FAQ
COMMON QUESTIONS
// Getting Started
Yes - Cyber Essentials Plus builds on top of Cyber Essentials. You must hold a valid Cyber Essentials self-assessment before the Plus technical audit can take place. Once your CE basic certification is confirmed, you have 90 days (3 months) from that certification date to complete and pass CE Plus. If CE Plus is not passed within 90 days, the Plus application closes and you will need to re-certify at CE basic level before restarting - incurring an additional certification cost. In practice, both can be completed as part of the same engagement with us to keep the process as efficient as possible.
Cyber Essentials is self-assessed - you complete a questionnaire that is reviewed by your Certification Body. Cyber Essentials Plus adds an independent technical audit where an approved assessor actively tests your systems to verify the controls are correctly implemented, not just documented. Plus provides a significantly higher level of assurance and is required for some government and enterprise contracts. Learn about standard CE →
CE Plus is typically required for MOD supply chain contracts involving sensitive or classified data, certain NHS and public sector frameworks, and enterprise clients requiring independent technical verification rather than self-assessment. If your contract tender specifies CE Plus or an independent technical audit, standard CE alone will not be sufficient. If you are unsure what your contract requires, our team can advise.
// The Audit
The scope is agreed upfront and typically aligns with IASME requirements - a representative sample of user devices, servers, and relevant systems, typically around 10% of in-scope devices with a minimum of one per operating system type in use. We will help define this clearly with you before the assessment begins.
Yes - remote and hybrid workers are included where they form part of your operational environment. Their devices are treated as in-scope and may be selected as part of the device sample.
Yes - we regularly assess Azure and Microsoft 365 environments as part of Cyber Essentials Plus. Cloud environments are assessed for configuration, access controls, and MFA enforcement across in-scope services. What falls in scope will depend on how your environment is structured, and we will confirm this with you before the audit.
Yes - both internal and external vulnerability scanning are included as part of the CE Plus assessment. Internal scanning covers a sample of in-scope devices; external scanning covers your internet-facing systems and services. Both are conducted remotely by our IASME-approved assessors.
The CE Plus audit is a hands-on technical assessment conducted remotely by our IASME-approved assessors. It includes: external vulnerability scanning of your internet-facing systems, internal vulnerability scanning of a sample of in-scope devices (typically around 10%), checks on email and web browser configuration, and active verification that controls such as patching, malware protection, and access control are correctly implemented - not just documented. The audit typically takes a few hours depending on the size and complexity of your environment.
The technical audit itself typically takes a few hours to a day depending on scope and environment size. Combined with the Cyber Essentials self-assessment that precedes it, the full CE Plus process usually takes one to three weeks. Bear in mind that once CE basic is certified, you have 90 days (3 months) to complete and pass CE Plus - so it is important not to let the process stall once you have started. If the 90-day window expires, you will need to re-certify at CE basic level before restarting. We work to your timeline and can accommodate urgent certification needs.
If the audit identifies controls that are not correctly implemented, you will receive specific, actionable feedback on what needs to change. You have 30 days from the date the CE Plus assessment started to remediate those issues and have the relevant checks revisited. This remediation window sits within the broader 90-day window from your CE basic certification date - so both constraints apply at the same time. If either window expires before you pass CE Plus, your Plus application closes and you will need to re-certify at CE basic level before restarting - which incurs an additional cost. Our team will support you through remediation as efficiently as possible to protect both windows.
Under the Danzell (v3.3) standard, if vulnerabilities are found in your initial device sample, you are given a remediation window to address them across your entire estate. The assessor will then retest the original sample and select a second, new random sample to verify that patches have been applied consistently. If unresolved vulnerabilities are present in the second sample, the CE Plus assessment fails automatically. Importantly, this also triggers revocation of your underlying Cyber Essentials basic certificate - meaning you would need to re-certify at CE basic level before restarting the CE Plus process, incurring additional cost and delay. This is why we work with you before the audit to ensure patching is consistent across your entire estate - not just the devices you expect to be sampled. Our preparation process is specifically designed to avoid this outcome.
A Pre-Assessment Check is included as standard with all CE Plus assessments - there is no additional charge. Before your formal audit begins, we review your controls against CE Plus requirements, identify any gaps, and give you the opportunity to remediate - reducing the risk of a failed assessment.
// Certification & Beyond
Cyber Essentials Plus certificates are valid for 12 months from the date of certification. Annual renewal is required to maintain certified status, which is important for ongoing government contracts and supply chain requirements. We can help manage your renewal cycle to avoid any gaps in certification.
Yes - CE Plus establishes well-documented, independently verified security controls, which provides a strong foundation for an ISO 27001 implementation. ISO 27001 is considerably broader in scope, covering governance, risk management, and organisational policies as well as technical controls - but CE Plus ensures your core technical controls are verified and working before you tackle the full management system requirements.
When your CE Plus assessment passes you receive your official IASME-issued Cyber Essentials Plus certificate, a digital CE Plus badge you can display on your website, email signature, and tender submissions, and a public listing on the IASME register of certified organisations. Your underlying Cyber Essentials basic certificate is also confirmed as part of the engagement. UK-registered organisations with annual turnover under £20 million automatically receive free cyber liability insurance up to £25,000 - included at no additional cost for whole-organisation scope. Both certificates are valid for 12 months from the date of certification.
Yes. Cyber Essentials Plus is built on top of Cyber Essentials basic - you cannot achieve CE Plus without first holding a valid CE basic certificate. If you hold a current CE Plus certificate, the CE basic prerequisite for DCC Level 0 is already satisfied. You do not need a separate CE basic certificate. However, your CE Plus certificate must be current and cover the same scope as your intended DCC assessment - a scope misalignment between the two is an automatic DCC assessment failure.
Yes - renewal follows the same process as your initial CE Plus engagement: a fresh Cyber Essentials self-assessment followed by a technical audit. Renewal pricing is the same as the initial certification fee for your organisation size. One key difference: your current CE Plus certificate remains valid while the renewal is in progress, so there is no gap in certified status provided you start before your certificate expires. We recommend beginning the renewal process at least four to six weeks before your expiry date to allow time for the Pre-Assessment Check and any remediation. We can help manage your renewal cycle to avoid any disruption to ongoing contracts.
// Microsoft 365 & Intune
Yes - Microsoft 365 and Intune-managed environments are among the most common we assess, including within larger and multi-site organisations. We are familiar with how these platforms map to Cyber Essentials Plus requirements.
Yes - we are happy to clarify requirements and explain what Cyber Essentials expects from your Microsoft 365 environment as part of the assessment process. Where additional advisory support is needed - for example, reviewing your existing Intune configuration against CE requirements - this can be discussed. We do not implement controls on your behalf, as this would conflict with our independence as your Certification Body.
// Remediation & Reassessment
One free rescan is included in your CE Plus fee. If issues are identified during the technical audit, we include a single rescan to verify remediation at no additional charge. IASME timelines take precedence: the 30-day remediation window (from the date the assessment started) and the 90-day window (from your CE basic certification date) both apply simultaneously - whichever expires first is the binding deadline. We work proactively on preparation beforehand to minimise the need for a rescan in the first place.
If issues cannot be remediated within the 30-day window, or if the 90-day window from your CE basic certification date expires, a full reassessment would be required at an additional certification charge. We work with you in advance to minimise this risk, but it is important to be aware of both windows from the outset.
Yes. Cyber Essentials Plus is open to any organisation regardless of where it is registered or based. We have certified organisations based in the United States, Germany, the Netherlands, Ireland, Spain, and Italy who needed CE Plus to supply to UK government, NHS, or enterprise clients. Because the entire CE Plus audit is conducted remotely - external vulnerability scanning, internal device scanning, and email and browser configuration checks - your physical location is not a factor. Note that the free IASME cyber liability insurance applies to UK-registered organisations only; overseas companies receive the full CE Plus certificate and IASME public register listing.
Yes. If you purchase Cyber Essentials and Cyber Essentials Plus together as a bundle, a 5% discount is applied automatically to the combined price. The saving is shown in the quote builder and on your PDF quote. It is the most cost-effective way to get fully certified if you need both certifications.
GOVERNMENT CYBER RESILIENCE PLEDGE SIGNATORY
Vincent Cyber Defence has signed the Government Cyber Resilience Pledge - including the commitment to require Cyber Essentials across our supply chain. View our signed declaration →
DIRECT LEAD ASSESSOR ACCESS
Every client works directly with a qualified lead assessor from first contact through to certification. No helpdesk, no handoffs, no rotating contacts - consistent, senior-level support throughout. This is a deliberate part of how VCD operates, not an afterthought.
// Client Reviews
WHAT OUR CLIENTS SAY
★★★★★
"The CE Plus audit was thorough, professional and well-coordinated. Our assessor explained every step and we passed first time - great experience."
- IT DIRECTOR / Financial Services, London
★★★★★
"We needed CE Plus for a government contract. VCD managed both the basic and Plus assessments together - efficient, clear and no surprises on the day."
- OPERATIONS DIRECTOR / MOD Supply Chain
★★★★★
"Having the gap review before the technical audit gave us real confidence going in. We knew exactly what to expect and everything went smoothly."
- HEAD OF IT / Professional Services
Client names are withheld in line with confidentiality requirements; character references are available upon request.
READY FOR CYBER ESSENTIALS PLUS?
Get independently verified. Talk to our UK-based team today - no jargon, no add-ons, no hard sell.