Cyber Essentials Plus Certification With Confidence

Get Cyber Essentials Plus certified remotely with Cyphere, an IASME-licensed certification body based in Manchester, delivering across the UK. Complete certification starts from £1,299 + VAT, or £999 + VAT with an eligible security engagement.

Your self assessment, readiness check and technical audit are managed in one engagement, so you know exactly what to fix before the Cyber Essentials Plus assessment. Verify our certification body status on the IASME directory

No obligation quote. Remote assessments UK-wide.

Get in touch

No salesy newsletters. View our privacy policy.

When do you need Cyber Essentials Plus certification?

Cyber Essentials certification is a UK Government-backed standard. Cyber Essentials Plus is most consistently required across five buyer situations. Requirements vary by contract, and where CE+ is named in a tender it becomes a pass/fail procurement requirement.

Insurers are pricing premiums against demonstrable controls; Cyber Essentials Plus is increasingly a baseline expectation for renewal terms across private sector.

Any contract involving software development, IT infrastructure, managed services, or system integration for public sector buyers. If your organisation handles government data or connects to government networks, Cyber Essentials Plus is effectively mandatory.

Consultancy, research, financial services and legal services contracts where you will access personal data, commercially sensitive information, or government systems. Financial services buyers in particular are asking for CE+ evidence as part of due diligence.

Any supplier processing NHS patient data or connecting to NHS systems. The combination of DTAC, DSPT requirements and procurement specifications is making Cyber Essentials Plus standard rather than exceptional in health and care procurement. [Link “DSPT” to the NHS DSPT industries page.]

DE&S and the wider MOD supply chain have required Cyber Essentials Plus for years. The standard is now spreading into adjacent security and emergency services procurement.

What is covered in IASME Cyber Essentials Plus?

What is Cyber Essentials Plus certification?

It is the same five technical controls as Cyber Essentials, verified on your actual systems rather than by questionnaire alone. These are firewalls and routers, secure configuration, user access control, malware protection, and security update management. Our assessor tests a representative sample of your devices and internet-facing services: authenticated vulnerability scans to assess patch management, browser and email security checks as part of assessing the effectiveness of anti malware software, account separation, cloud services MFA configuration under the current IASME question set.

Are firewalls in place and configured to protect the organisation’s network from unauthorised access?

Are systems and devices configured securely to reduce the risk of exploitation?

Are security updates applied to systems and devices promptly?

Are user accounts and permissions managed effectively to prevent unauthorised access to systems and data?

Is malware protection configured effectively to protect the organisation’s network from malware infections?

cyber essentials certification

How does CE+ Certification helps your business?

By correctly applying the five essential security controls, the Cyber Essentials program significantly empowers you to reduce the cyber security risks posed by various common cyber threats.

Your company pays lower cyber insurance premiums by demonstrating high level security controls with cyber essentials plus certification

Being Cyber Essentials certified concretely demonstrates your dedication to protecting data and ensuring robust cybersecurity practices within your organisation.

The Cyber Essentials certificate opens the door to collaboration with the UK government and other public sector bodies where Cyber Essentials certification is a pre-requisite for government contracts.

  • Cyber Essentials certificates issued within the past year are featured on the IASME website, showcasing your unwavering commitment to safeguarding your and your customers’ data.
  • Impact on Cybersecurity Attitudes and Behaviors

The National Cyber Security Centre (NCSC) has assessed the influence of Cyber Essentials on organisational cybersecurity practices and found that organisations express confidence in their protection, increase supplier confidence, and exhibit heightened awareness of threats.

Benefits of cyber essentials for your business

Cyber Essentials Pricing

All prices are + VAT. Larger or more complex estates are quoted from the same rate card; what moves the price is device sample size, and operating systems variety. Your industry does not change the price. Pricing reflects the 2026 scheme under the Danzell question set.

CE+ Gap Analysis

From

£499

  • Full gap analysis against the current CE+ pass criteria

  • Compliance status and remediation requirements report from our assessors

  • Fully credited against your certification if you proceed within 90 days

  • Ideal if you are not sure you would pass today

  • Direct access to CE+ assessors 

Cyber Essentials Plus Certification

From

£1299

  • Cyber Essentials self assessment (VSA) included

  • CE+ Readiness check included (£499 value, credited)

  • CE+ technical controls audit

  • 30-day remediation window on any findings

  • Certificate valid 12 months and listed on the IASME register

  • £25,000 cyber liability insurance included*

*Free cyber insurance is available for a UK-domiciled organisation with a turnover under £20m passing Cyber Essentials (whole-organisation self-assessed scope). Up to £25,000 of cover underwritten by AIG; cyber fraud losses are excluded. Full details on IASME website.

If you have already passed Cyber Essentials assessment from another certification body, dated within the last three months, ask us to quote the Plus audit alone.

Cyber Essentials for NHS Suppliers and HealthTech – Selling into the NHS usually means DTAC or DSPT, and both lean on the same building blocks. For DTAC compliance we offer a combined package of CREST-accredited OWASP Top 10 penetration testing and Cyber Essentials certification in one engagement, saving you time and money. We certify several health tech companies today, including AI application vendors holding Cyber Essentials certificates.

OUR BUNDLE OFFER

CE+ and annual pentest, one engagement

When Cyber Essentials Plus is delivered alongside an eligible CREST penetration test, security audit, configuration review or compliance engagement, the CE+ element is discounted to £999 + VAT, fixed price. We confirm eligibility before quoting, and these can be schedule separately or together with individual deliverables.

How to get cyber essentials certified?

Cyber Essentials Plus certification follows the four steps below, all handled inside one engagement. Our accredited IASME Cyber Essentials assessors carry out the technical controls assessment, and most organisations complete it remotely.

  1. Set the scope – Before you begin the certification process, clarifying the certification’s range is essential. All certifications will now go through Danzell’s question set (the latest Cyber Essentials scheme, as of April 2026). This could encompass an organisation’s entire enterprise IT infrastructure or a specific subset. Clearly defining the scope is a crucial preliminary step.
  2. Cyber Essentials self assessment (SAQ), referred to as the Verified Self Assessment (VSA) by IASME – This is part of your CE+ engagement, and we sequence it so the scheme’s timing rules are never your problem. The SAQ is carefully reviewed to ensure it complies with the scheme’s requirements before submission to the assessor, and a successful submission following a declaration by a board member clears the path to your CE Plus audit.
  3. Technical Assessment (Vulnerability Scan, Device and endpoint checks) – This step is part of the Cyber Essentials Plus certification process. Organisations aiming for Cyber Essentials Plus certification must undergo a comprehensive technical evaluation. This includes a series of internal vulnerability scans and assessments of the in-scope system(s) along with the SAQ (considered as the scope). An external vulnerability scan is conducted on your internet-facing networks and applications to confirm the absence of obvious vulnerabilities. These tests are mostly carried out from a remote location.
  4. Certification Awarded – Certification is awarded on passing the technical controls assessment. If weaknesses are found, you have 30 days to apply fixes and reschedule the affected checks. Once the assessment, internal scans and external scans pass, Cyphere, as an IASME certification body, issues your Cyber Essentials Plus certificate. On passing, you receive the Cyber Essentials Plus badge and logo pack for your website and bids, and your certificate is listed on the IASME register for 12 months.
  • Access to the Cyber Essentials portal, or your existing self assessment if you have one
  • Your device and user scope, external IPs and internet-facing services
  • A technical contact (yours or your MSP’s) and remote access arrangements for sampled devices
  • Time to remediate anything the readiness check finds

That is the whole ask; we handle the sequencing, submissions and scheme timing rules.

BENEFITS

Cyber Essentials was launched in 2014 by the UK Government. NCSC (National Cyber Security Centre) owns the Cyber Essentials scheme, managed by IASME, is designed to protect organisations against the most common online threats, and Cyber Essentials Plus, sometimes called CE+ accreditation, proves your controls work in practice rather than on paper.

By correctly applying the five essential security controls, the Cyber Essentials program significantly empowers you to reduce the cyber security risks posed by various common cyber threats. Cyber Essentials is proven to be effective in protecting up to 80% of the common cyber attacks.

Your company pays lower cyber insurance premiums by demonstrating high level security controls with cyber essentials plus certification

Being Cyber Essentials certified concretely demonstrates your dedication to protecting data and ensuring robust cybersecurity practices within your organisation.

The Cyber Essentials certificate opens the door to collaboration with the UK government and other public sector bodies where Cyber Essentials certification is a pre-requisite for government contracts.

  • Cyber Essentials certificates issued within the past year are featured on the IASME website, showcasing your unwavering commitment to safeguarding your and your customers’ data.
  • Impact on Cybersecurity Attitudes and Behaviors

The National Cyber Security Centre (NCSC) has assessed the influence of Cyber Essentials on organisational cybersecurity practices and found that organisations express confidence in their protection, increase supplier confidence, and exhibit heightened awareness of threats.

Benefits of cyber essentials for your business

Businesses across the UK rely on our IASME Cyber Essentials Assessors

Why get Cyber Essentials Plus certified with Cyphere?

100% of the clients who complete our readiness check pass first time. We hold Cyber Essentials Plus ourselves and go through the same assessment we run for clients.

We understand that every organisation is unique. Cyphere doesn’t believe in a one-size-fits-all approach. We ensure that a readiness audit is covered in our quote, providing you peace of mind to aim for first time certification audit pass after any fixes needed from the audit.

Our certification process is designed to be straightforward and efficient without putting customer into application, audit, fail and retest cycles. We help you navigate the complexities of cybersecurity, making achieving and maintaining your certification easy. 

Our pricing section above shows exactly where the cost comes from (£1299), and if you engage us for penetration testing or wider security work, certification drops to £999 + VAT fixed inside an eligible engagement. We believe cyber security should be accessible to all businesses, regardless of size.

Our commitment doesn’t end with certification. We offer ongoing support, helping you maintain your cybersecurity posture. Our experts are here to answer your questions and assist you in addressing any concerns.

Trust is at the core of what we do. Cyphere has earned a reputation for integrity and professionalism. Service quality underpins everything we do.

Cyphere doesn’t just stop at Cyber Essentials. We offer various cybersecurity services to help you strengthen your defences and stay ahead of threats. From penetration testing to security audits, we’ve got you covered.

Cyber Essentials Plus for MSPs and IT providers

We partner with MSPs and IT providers today and welcome more. There are two ways it works. You can refer your clients to us and keep the relationship while an IASME-licensed body handles their certification, or you can use us as your CE+ reporting partner, where you manage certification on behalf of clients and we provide the assessment and reporting layer. Either way, your clients are certified by assessors in-house at a certification body rather than through a reseller.

Prices shown are our direct client rates. As a partner, you have higher flexibility on client pricing and margin, and we agree volume terms as your certification volume grows. 

Cyber Essentials Plus FAQs

What is the Cyber Essentials Plus certification process?

Once you engage us for Cyber Essentials Plus, you are given access to the portal, where you will find the electronic self-assessment questionnaire, or you can submit the one you have. You can start the application, save your progress, and return to it later. Every CE+ engagement includes a readiness check to help you pass on the first attempt, and you will have practical support from Cyphere’s comply team throughout. – Harman Singh, Founder, Cyphere

What is the difference between Cyber Essentials and Cyber Essentials Plus, and is basic enough?

Cyber Essentials is your answers, verified; Plus is your IT systems, tested. If a contract, framework or insurer names a level, it is increasingly Cyber Essentials Plus. A questionnaire alone cannot find gaps you do not know about that sets the main difference between two certification levels. You cannot achieve Cyber Essentials Plus without first certifying Cyber Essentials. Your self assessment is included inside the Plus engagement either way. – Harman Singh, Founder, Cyphere

How long does Cyber Essentials Plus take?

There is one honest answer to this: it depends on your readiness. Organisations with high security maturity get there within one or two weeks. Medium sized organisations that need technical baselines implemented first should treat it as a couple of months project to achieve cyber essentials regardless of your chosen certification body. Small businesses may find it faster due to less complex IT systems, networks and services in use. The questionnaire itself takes a few hours; what takes time is fixing what the readiness check finds. – Harman Singh, Founder, Cyphere

How much does Cyber Essentials Plus cost?

£1,299 + VAT for the complete engagement, including your self assessment, the readiness check and the technical audit. If you buy penetration testing or wider security work from us, CE+ is £999 fixed inside that engagement. The only extra to budget for is remediation work if the readiness check finds gaps or any contractors on your side. – Harman Singh, Founder, Cyphere

Do we need Cyber Essentials before Cyber Essentials Plus?

The scheme requires a passed self assessment dated within three months of your CE+ assessment completing, otherwise you reapply and pay another application fee. In practice this is our problem rather than yours: we wrap the self assessment (VSA) inside your CE+ engagement and sequence both so the window is always met. – Harman Singh, Founder, Cyphere

What happens if we fail the CE+ assessment?

You get 30 days to apply fixes and re-schedule the affected checks, without restarting the whole certification. CE sand CE+ applications must be submitted within 90 days. As an assessor, the most common failure I’ve observed is organisations submitting CE application quickly without planning for CE+ readiness. If you start preparing with CE+ in mind, then start CE application helps with proactive approach. If you miss the 90 days window between CE and CE+ submissions, you will retake CE.

Our readiness check exists precisely so that first-time passes are the norm rather than making CE+ a painful process. – Harman Singh, Founder, Cyphere

What are the Cyber Essentials Plus requirements?

The same five cyber essentials controls are part of CE+ criteria, evidenced on your systems assessed by third party under Cyber Essentials Plus Assessment. Most often, people misjudge that the sampling approach is minimum number of assets per operating system category (for desktops, servers, laptops, mobile phones, tablets etc), not for the entire number of systems in an organisation. For instance, sampled set will be taken from Windows 2022 servers, and then another separate sample set from Windows 11 builds. Another popular example from our experience is similar to real world security audits results such as lack of supported version for third party software or use of default passwords as these are the open invitation for the most common cyber attacks. In case of cyber essentials security update requirement, all critical and high risk vulnerabilities patches must be implemented within 14 days. The cost and effort required are higher than for the Cyber Essentials self-assessment. – Harman Singh, Founder, Cyphere

Can you work with our MSP, or act as a certification partner for IT providers?

Yes, both. We work with MSP partners on referral and reporting-partner models, and we welcome new partnerships; the section above explains how it works. – Harman Singh, Founder, Cyphere

How do I check whether a company holds Cyber Essentials certification?

Search the IASME certificate register, where every valid certificate is listed for 12 months from issue. If a supplier claims certification and does not appear on the register, ask them for the certificate number. – Harman Singh, Founder, Cyphere

Do you provide Cyber Essentials Plus certification in Manchester?

We are based in Manchester and provide Cyber Essentials Plus certification and IASME Governance certification Level1, Level2 for organisations across the UK. This is a remote audit, so your location does not affect delivery or pricing; you get the same in-house IASME assessors whether you are in Altrincham (you’re most welcome for a coffee!), London, Edinburgh or anywhere else in the UK. – Harman Singh, Founder, Cyphere

How long is Cyber Essentials Plus valid for?

Twelve months from the date of issue, and your certificate is listed on the IASME register for that period. Renewal is annual, and we contact you ahead of expiry so certification never lapses mid-contract. – Harman Singh, Founder, Cyphere

Is the CE+ assessment done remotely or on-site?

Remotely for the vast majority of organisations, including the device sampling and technical checks. If your environment genuinely needs on-site testing, tell us at scoping and we will plan for it. – Harman Singh, Founder, Cyphere

Ready for Cyber Essentials Plus certification? Complete certification from £1,299 + VAT, or £999 + VAT with an eligible security engagement.

Dark Shadow

How "Defensible" is your firm compared to UK peers?

Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.