Cyber Essentials Plus

Enhanced Cyber Essentials Standard

Cyber Essentials Plus builds on the Cyber Essentials certification. It helps businesses implement effective, more complex cyber security measures to better safeguard sensitive data and improve customer trust and retention.

amtivo feefo rating

Get Started Today

Enter your details below to get started on
your journey to certification.

What Is Cyber Essentials Plus?

Cyber Essentials Plus is a UK certification that helps companies implement fundamental and effective cyber security measures. The next level up from Cyber Essentials, the certification helps organisations consistently meet security and regulatory requirements by focusing on essential protection against common cyber threats.

By following Cyber Essentials Plus, businesses can strengthen their security, reduce vulnerabilities, and enhance data protection. This certification is valuable for any organisation, large or small, in any industry or sector.

Achieving Cyber Essentials Plus certification demonstrates a commitment to cyber security and helps build trust with clients and partners by showing that the company prioritises and maintains robust cyber security practices.



What is Cyber Essentials Plus

Understanding Cyber Essentials Plus

Cyber Essentials Plus has grown from a simple cyber security framework into a respected certification that demonstrates strong cyber defences.
 
Since its launch in 2014, Cyber Essentials Plus has been regularly updated to address new and emerging threats and to keep pace with evolving security needs. The latest version places greater emphasis on technical testing and the integration of cyber security within wider business practices. It also highlights the important role of leadership in fostering a strong cyber security culture.
 
Unlike the Cyber Essentials certification, which is fully self-assessed, Cyber Essentials Plus builds on this self-assessment with a hands-on technical audit carried out by an independent assessor (such as Amtivo) to verify that security measures are in place and working effectively.
Understanding Cyber Essentials Plus

Who Needs Cyber Essentials Plus?

Cyber Essentials Plus is useful for any organisation that wants to improve its cyber security, no matter its size or industry. It helps businesses meet security regulations, build client trust, and strengthen data protection by identifying and reducing vulnerabilities.
 
Achieving Cyber Essentials Plus is especially valuable for businesses that want to enter new markets or show their commitment to cyber security. It applies to all types of organisations, including financial services, healthcare, education, and non-profits, as each faces different cyber risks.
 
This well-known certification helps improve security practices, boost stakeholder confidence, and support business growth and stability.
Who needs Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification can benefit an organisation in a number of ways.

  • Enhanced security – Strengthens defences against common cyber threats, reducing unnecessary risk.
  • Regulatory compliance – Helps meet legal and industry-specific cyber security requirements.
  • Customer trust – Builds confidence by demonstrating a commitment to protecting data.
  • Competitive advantage – Differentiates your organisation by showcasing robust security measures.
  • Risk management – Identifies and mitigates vulnerabilities, enhancing overall security measures.
  • Operational resilience – Supports continuous operation by preventing disruptions from cyber incidents.
  • Access to new markets – Facilitates entry into markets requiring verified cyber security credentials.
The benefits of Cyber Essentials Plus

Cyber Essentials Plus Explained

Cyber Essentials Plus Specification

Cyber Essentials Plus was launched in 2014 by the UK government, specifically through the National Cyber Security Centre (NCSC) and the Department for Digital, Culture, Media and Sport (DCMS).

Cyber Essentials Plus is a more in-depth certification than Cyber Essentials, involving a rigorous test of your organisation’s cyber security systems as well as hands-on technical verification. It provides a higher level of assurance.

Cyber Essentials Plus can apply to organisations across all sectors, helping organisations to establish robust cyber defences and promoting a culture of cyber security excellence.

Cyber Essentials Plus Requirements

Cyber Essentials Plus requirements guide you in establishing an effective cyber security framework for your organisation. There are five key technical controls across both Cyber Essentials and Cyber Essentials Plus:

  • Firewalls and internet gateways – Protects your network by controlling incoming and outgoing traffic, creating a barrier between your internal network and external threats.
  • Secure configuration – Checks that systems and devices are set up securely to minimise vulnerabilities and exposure to cyber threats.
  • User access control – Restricts access to data and systems to authorised users only, preventing unauthorised access and potential breaches.
  • Malware protection – Defends against malicious software through the use of antivirus programs and anti-malware tools, safeguarding systems from harmful attacks.
  • Patch management – Keeps software and devices up to date with the latest security patches, protecting against known vulnerabilities and exploits.

In order to become Cyber Essentials Plus-certified, an organisation must have an existing Cyber Essentials certification that is less than two months old.

Read Cyber Essentials Plus Checklist

Cyber Essentials Plus Certification

Cyber Essentials Plus certification demonstrates that your organisation’s cyber security measures meet the respected Cyber Essentials Plus standard. It assures customers, partners and regulators that you consistently maintain strong security practices to protect against cyber threats.

Certification focuses on your cyber security measures, rather than the entire organisation.

Certification builds trust with clients and stakeholders, fulfils contract requirements and provides a competitive edge by showcasing your commitment to cyber security.

To achieve certification, follow these steps:

  • Confirm Cyber Essentials certification – Provide your existing Cyber Essentials self-assessment certificate.
  • Technical audit application – Complete the online application for the technical audit. Our auditors use this information to develop an assessment plan.
  • Pass the certification audit – One of our expert assessors will review your current security protections.
  • Maintain certification – We recommend you resubmit and recertify annually to keep your Cyber Essentials Plus certification.

Learn More About Cyber Essential Plus Certification

Cyber Essentials Plus FAQs

What is the difference between ISO 27001 and Cyber Essentials Plus?

ISO 27001 is a comprehensive international standard for information security management systems, focusing on a wide range of security controls and risk management.

Cyber Essentials Plus is a UK certification that targets basic cyber security measures, with an emphasis on protecting against common cyber threats.

While ISO 27001 involves a detailed risk assessment and management process, Cyber Essentials Plus includes a hands-on technical verification to check that essential security controls are in place.

Is Cyber Essentials Plus a legal requirement?

No, Cyber Essentials Plus is not a legal requirement.

However, some government contracts mandate it for suppliers and it helps organisations demonstrate their commitment to cyber security best practices.

Who needs Cyber Essentials Plus?

Everyone can benefit from Cyber Essentials Plus! Organisations that handle sensitive data or wish to demonstrate a higher level of cyber security assurance can pursue Cyber Essentials Plus certification.

It is particularly beneficial for businesses looking to enhance their security posture and build trust with clients and partners who require verified cyber security measures.

Is Cyber Essentials Plus Globally recognised?

Cyber Essentials Plus is primarily recognised in the UK, as it is a government-backed scheme.

However, its principles of basic cyber security measures are universally applicable, and it can be respected by international clients and partners who value verified cyber security practices, especially for businesses operating within or with the UK.

How long is Cyber Essentials Plus valid for?

Cyber Essentials Plus certification is valid for one year. Organisations must undergo an annual assessment to maintain their certification, so that their cyber security measures continue to meet the required standards and adapt to evolving threats.

Is Cyber Essentials Plus worth it?

Yes, Cyber Essentials Plus is a worthwhile investment for many organisations in different sectors.

It provides a cost-effective way to enhance cyber security measures, improve data protection and demonstrate commitment to cyber security to clients and stakeholders. The certification can also open doors to new business opportunities, as some contracts and clients require it.

How much does Cyber Essentials Plus cost?

The cost of Cyber Essentials Plus varies depending on the size and complexity of the organisation and the chosen certification body. Typically, it ranges from a few hundred to a few thousand pounds. Organisations should contact accredited certification bodies to get specific quotes tailored to their needs and circumstances.

Sign Up to Our Newsletter

Enter your details below to stay up to date with all the latest certification news and expert insights.

Related ISO Standards

Cyber Essentials

Cyber Essentials is a UK scheme for cyber security, helping organisations improve their cyber security framework.

ISO 14001

ISO 14001 is a globally recognised standard for Environmental Management Systems, helping organisations improve sustainability & reduce environmental impact.

ISO 27001

Discover ISO 27001, the global standard for information security management, safeguarding data integrity, confidentiality, and availability.

ISO 27701

Discover ISO 22301, the standard for Business Continuity Management, helping businesses effectively manage disruptions & maintain operations.

ISO 42001

Learn about ISO 42001, the first international standard outlining the requirements for Artificial Intelligence Management Systems (AIMS).