Cyber Essentials Plus

Government-Backed Cyber Security Certification – Self Assessment

Mitigate common attack risks and improve your company’s credentials with the correct security. Achieving Cyber Essentials Plus certification demonstrates that you are effectively managing cyber security and adhering to the standards established by the scheme.

amtivo feefo rating

Get Started Today

Enter your details below to get started on
your journey to certification.

What Is Cyber Essentials Plus Certification?

The Cyber Essentials Plus Standard, set by the UK Government, defines technical controls to help organisations improve the level of IT infrastructure security and guard their organisation against cyber attacks.

This scheme is designed to help organisations prevent highly common internet-based attacks and to implement the correct controls to protect the confidentiality, integrity, and availability of stored data on all internet-facing devices. Certification gives you peace of mind that your defences will protect against the vast majority of common cyber attacks.

The Cyber Essentials Plus certification process involves testing the five technical controls of your IT infrastructure. You are required to complete and submit a self-assessment questionnaire for evaluation.

Cyber Essentials Certification

What Are the Benefits of Cyber Essentials Plus?

  • Certification gives you peace of mind that your defences will protect against the vast majority of common cyber attacks
  • Stand out from competitors, retain and win more business
  • Increased credibility and reputation, customers feel more confident in sharing information with you
  • Raised awareness of threat with staff reduces risk levels
  • Improved business continuity management
  • Tender for contracts with the MOD, NHS, and central government work
  • Reduce your insurance premiums by reducing your resilience to cyber threats
  • Drive business efficiencies throughout your organisation which helps improve productivity

Why You Should Choose British Assessment Bureau

Our experts are with you at every step of your certification journey.
  • UKAS-accredited certification services – Your certification comes with the coveted Crown & Tick mark, which proves to your clients that it has the strength and security of government backing. Find out more about our UKAS accreditation

  • Expert support when you need it – Our auditors are with you every step of the way and our team is available online to offer support when you need it.

  • 5-star Feefo customer satisfaction – Our customers are so happy with our service that 97% have given us 4- or 5-star reviews. We are proud to hold an “Exceptional” Feefo rating – awarded to businesses achieving a rating of at least 4.5 for over ten years.

Why you should choose British Assessment Bureau

How to Become Cyber Essentials Plus Certified

STEP 1
STEP 2
STEP 3
STEP 4
STEP 5
Confirm your existing Cyber Essentials certification Start the process by completing providing your existing Cyber Essentials self-assessment certificate.
Complete and submit your online application for a technical audit Our online application form will provide our cyber security experts with the information they need to develop a plan for assessing your cyber security protections.
In-depth assessment takes place Our assessor will book in a time to access and assess your current security protections, based on the information supplied in your application form.
Certificate Awarded If your assessment is successful you will be notified and you will receive confirmation of your certification.
Annual renewal It is recommended that the Cyber Essentials Plus certification is reviewed and resubmitted annually to maintain certification.

How to Become Cyber Essentials Plus Certified

STEP 1
Confirm your existing Cyber Essentials certification Start the process by completing providing your existing Cyber Essentials self-assessment certificate.
STEP 2
Complete and submit your online application for a technical audit Our online application form will provide our cyber security experts with the information they need to develop a plan for assessing your cyber security protections.
STEP 3
In-depth assessment takes place Our assessor will book in a time to access and assess your current security protections, based on the information supplied in your application form.
STEP 4
Certificate Awarded If your assessment is successful you will be notified and you will receive confirmation of your certification.
STEP 5
Annual renewal It is recommended that the Cyber Essentials Plus certification is reviewed and resubmitted annually to maintain certification.

Implementing Cyber Essentials

Cyber Essentials and Cyber Essentials Plus certification is delivered by our sister company, Ascentor – an expert in cyber security and information risk management with over 20 years of experience. As one of the UK’s earliest providers of Cyber Essentials, Ascentor has issued more than 1,000 certificates, helping hundreds of organisations strengthen their cyber resilience and meet core security standards.

What sets Ascentor apart is a tailored, pragmatic approach built on deep expertise in technical assurance, governance, and risk management. You’ll gain structured guidance, practical insights, and the confidence that your organisation is taking measurable steps to improve its security posture.

Find Out More

 

Cyber Essentials

Cyber Essentials is a self-assessment certification which gives you peace of mind that your defences will protect against the majority of common cyber attacks. Obtaining Cyber Essentials is simple, through completion of a self-assessment questionnaire we assess you against the FIVE basic security controls. A qualified assessor verifies the information provided and if you satisfy the requirements, our Certification Body, Ascentor, will award you with Cyber Essentials certification.

Cyber Essentials Plus

Cyber Essentials Plus Certification FAQs

What is the purpose of Cyber Essential Plus certification?

Cyber Essentials Plus is a UK Government standard for technical controls to help organisations improve the level of IT infrastructure security and guard your organisation against cyber attack. This certification requires you to have an independent audit of your systems.

This scheme is designed to help organisations prevent highly common internet-based attacks and to implement the right controls to protect the confidentiality, integrity, and availability of stored data on devices on all internet-facing devices.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials certification is a simple process to protect your business guard against common cyber threats. You will need to complete a self-assessment questionnaire which is assessed by a British Assessment Bureau assessor.  They will independently check your completed questionnaire to ensure that you have in place the recommended FIVE cyber key controls necessary to protect your organisation from the most common cyber attacks

Cyber Essentials Plus certification still has the same basic principles as Cyber Essentials but will have a more rigorous test of your organisation’s cyber security systems. It will require a hands-on technical verification with a qualified assessor to check your eligibility for Cyber Essentials Plus certification.

Why should I get Cyber Essentials Plus certified?

Becoming Cyber Essentials Plus certified confirms you have been independently audited and have addressed your cyber security effectively and reduced the risk from internet-based threats and have met the standards set by Cyber Essentials scheme.

Certification gives assurance to stakeholders that you demonstrate compliance to the FIVE key controls, protecting your organisation against cyber threats and this reassurance may help with winning new business. Depending on the industry sectors you work within, central government contracts require Cyber Essentials certification as a minimum.

Key benefits of Cyber Essentials Plus certification?

Protecting your organisation against the majority of common cyber attacks demonstrates to stakeholders your commitment to keeping their data secure which can lead to business retention and potentially new business.

By having a higher level of security of your systems it will help drive business efficiencies throughout your organisation which helps improve productivity through streamlined processes and reducing operational costs.

Bid for UK central government contracts that involve the handling of personal and sensitive information.

Reduce your insurance premiums by reducing your resilience to cyber threats.

Should I get Cyber Essentials or Cyber Essentials Plus?

This all depends on your organisational needs. If you are looking to work within the public sector and bid for central government contracts than they will ask for Cyber Essentials as a minimum. If you want to demonstrate that your organisation is compliant with cyber security and takes data protection seriously and you hold sensitive data, then you may want to also achieve Cyber Essentials Plus certification.

How do I get Cyber Essentials Plus certified?

Become Cyber Essential Plus certified through these simple steps

  1. Purchase Cyber Essential Plus certification through one of our sales advisors
  2. Complete self-assessment question (SAQ) for Cyber Essentials and upload for the British Assessment Bureau for assessment review
  3. Once the submission is approved, you will be notified of your systems audit date
  4. Your systems will be rigorously tested during this audit to ensure you have put in place all the steps to meet the required standard
  5. If you have you all the steps in place, we will issue your Cyber Essentials Plus certification.
Where can I find details of full requirements for the Cyber Essentials Plus scheme?

More details on cyber security and the Cyber Essentials and Cyber Essentials Plus scheme can be found at the National Cyber Security Centre website.

Can I see the self-assessment questions before I pay for an assessment?

You can download a copy of the self-assessment questionnaire here and you can find further guidance on the National Cyber Security Centre website.

How are the Cyber Essentials Plus assessments verified?

The Cyber Essentials question set is part of the Cyber Essentials Plus certification process. It is the same checks as Cyber Essentials scope but involves a technical audit of the systems. This includes a representative set of user devices, all internet gateways, and all servers with services accessible to unauthenticated internet users. If you have achieved the basic level Cyber Essentials certification less than 3 months before certifying to Cyber Essentials Plus and nothing has changed you will not need to repeat the self-assessment questions stage. The assessor will check that you still meet the FIVE security requirements of Cyber Essentials before proceeding with Cyber Essentials Plus certification.

Do I have to complete Cyber Essentials to apply for Cyber Essential Plus?

Cyber Essentials self-assessment forms part of the application for Cyber Essentials Plus and is processed at the same time. You must meet the minimum requirements of Cyber Essentials before we process the Cyber Essentials Plus and complete the Cyber Essentials questionnaire which will verify your compliance as part of achieving Cyber Essentials Plus.

To apply for Cyber Essentials Plus you must possess a Cyber Essentials certificate, supply a copy of the Cyber Essentials questionnaire submitted, and confirm that no changes have been made to your controls since that submission.

How much does it cost for Cyber Essentials Plus certification?

Cyber Essentials Plus assessments involve a technical audit of the system and must be quoted individually. You can request a quotation here.

How quickly can I get certified to Cyber Essentials Plus certified?

You will need to complete and pass the Cyber Essentials requirements and once we have carried out the technical audit, we aim to return a report as quickly as possible. I may take up to five working days from the time you submit your assessment.

How long will I have to complete and submit my assessment?

You can take as long as you want to start your assessment. Once you have started it, you need to complete it including any corrective actions identified by your assessor within one month.

If I fail will I get feedback about why I failed?

If you fail the assessment, we will supply a report back with the answers you gave along with the assessor feedback. This should help you improve your security so you can pass again in the future. You will have 30 days for the remediation of any components of the assessment which received fail status.

My organisation is not based in the UK can still obtain Cyber Essentials Plus certification?

Yes, organisations overseas can get certified, contact us now.

Do certifications have an expiry date?

Certificates expire after 12 months, therefore, we recommend you seek to renew your certification before expiry.

Will I receive a reminder to recertify?

We will email you with a reminder before your expiry date to check your situation and if you want to proceed with another year’s certification.

When I recertify will I have to re-enter all the information again?

If you have made no significant changes to your security setup, you may wish to copy and paste the details from the previous year’s submission into the self-assessment questionnaire. You will still need to book your technical audit and wait for the report which may take up to five days.

If I have ISO 27001 certification, do I still need to Cyber Essentials Plus certification.

This will depend on your motivations for being certified, if you are asked to be Cyber Essentials Plus certified, an ISO 27001 certification although more comprehensive will not show that your security levels are up to the National Cyber Security Centre (NCSC) standards.

ISO 27001 is an international standard that provides specifications for an ISMS (Information Security Management System)–a systematic approach to managing information security risk. It goes considerably further than Cyber Essentials, but they are complementary to one another.

Do I need Cyber Essentials Plus to bid for Government contract?

Some government contracts may require you to be as a minimum Cyber Essentials certified, it is important that you seek clarification for each contract.

Who is IASME?

Cyber security firm IASME was chosen by the National Cyber Security Centre (NCSC) to take over full responsibility for Cyber Essentials delivery and become the Cyber Essentials Partner with the NCSC. The IASME Governance standard allows small companies in a supply chain to demonstrate their level of cyber security cost-effectively to show that they are taking the steps to properly protect their customers’ information.

What support will I get during certification?

We understand that certification can appear daunting. Our experts are here to make sure that the process is as smooth as possible and that you gain maximum benefits.

Sign Up to Our Newsletter

Enter your details below to stay up to date with all the latest certification news and expert insights.

Related Standards

Cyber Essentials

Cyber Essentials is a UK scheme for cyber security, helping organisations improve their cyber security framework.

ISO 27001

Discover ISO 27001, the global standard for information security management, safeguarding data integrity, confidentiality, and availability.

ISO 42001

Learn about ISO 42001, the first international standard outlining the requirements for Artificial Intelligence Management Systems (AIMS).

ISO 14001

ISO 14001 is a globally recognised standard for Environmental Management Systems, helping organisations improve sustainability & reduce environmental impact.

ISO 22301

Get in touch with Amtivo now to find out how we can help your business to become ISO 22301 certified.

ISO 9001

ISO 9001 is an internationally recognised standard for quality management, helping businesses across industries improve the quality of their products and services.