Cyber Essentials Plus

Cyber Essentials Plus certification for Belfast & Northern Ireland

Cyber Essentials Plus is the audited level of the scheme, where an independent assessor tests your systems hands-on. We get NI businesses audit-ready and guide you through the whole process, as hands-on as you need, working alongside an accredited certification body.

The audited level

What is Cyber Essentials Plus?

Cyber Essentials Plus covers exactly the same five controls as Cyber Essentials. The difference is how they are checked. Instead of a self-assessment questionnaire, an independent, accredited assessor tests a sample of your systems directly to confirm the controls are genuinely working. It is the stronger, audited level of assurance, and you need Cyber Essentials in place first.

The audited levelAn independent assessor verifies your controls hands-on, not just on paper.
Cyber Essentials firstYou must hold current Cyber Essentials before you can take Plus, usually within three months.
Sampled on your devicesThe assessor tests a representative sample of your laptops, desktops and servers.
Valid for 12 monthsRenewed each year, so your certification and register listing stay current.

What happens

What the Cyber Essentials Plus audit involves

The assessor works through a set audit on a representative sample of your devices, testing your systems against the Cyber Essentials Plus requirements. Here is what they check.

01

External vulnerability scan

A scan of your internet-facing systems to confirm nothing is exposed that a common attacker could exploit.

02

On-device testing

An authenticated check on a sample of your devices, confirming patching, configuration and account controls are actually in place.

03

Malware & email defences

Tests that malicious files and links are blocked in email and the browser, the routes most attacks actually take.

04

Multi-factor authentication

Verification that MFA is enforced on cloud services and administrative accounts across the sample.

05

Certification decision

The accredited certification body reviews the results and issues your Cyber Essentials Plus certificate.

How we get you through it

Audit-ready, then certified

We do as much of the work as you want us to. The audit itself is carried out by an independent, accredited certification body; we get you ready for it and stand with you through it.

01

Gap analysis

We test your systems the way the assessor will, and show you exactly where you would fail today.

02

Remediation

We close the gaps: patching, configuration, MFA, malware and email controls across your estate.

03

Readiness review

We walk through your controls against the Plus requirements first, so nothing on audit day is a surprise.

04

Audit & certify

We coordinate the certification body, support you through the audit, and keep you compliant to renewal.

Why it matters

Why Northern Ireland businesses choose Plus

Contracts that demand it

A growing number of public-sector and larger private contracts, and parts of the MOD supply chain, require the audited Plus level, not the self-assessment. Plus keeps you eligible to bid.

Proof, not just a claim

Plus is independently tested, so it is the strongest signal you can give clients and partners that your security genuinely works.

Stronger insurance footing

Many cyber insurers view the audited level favourably when they underwrite or price a policy.

Cost

How much does Cyber Essentials Plus cost?

There are two separate costs. The certification body charges a fee for the audit itself, which depends mainly on the size of your device sample. Separately, we help you get audit-ready on a time basis, charging only for the hours we put in, so the more of the preparation and remediation your own team takes on, the less you pay us. We scope the likely hours with you before we start. Talk to us about the likely cost for your setup.
Your device sample sizeThe certification body’s audit fee scales mainly with how many laptops, desktops and servers fall in scope.
How much needs fixingIf your controls are already close, remediation is light; more gaps mean more of our time to close them.
How much you take onThe more of the preparation and remediation your own team handles, the fewer hours you pay us for.

Cyber Essentials Plus questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?

They cover the same five security controls; the difference is how they are checked. Cyber Essentials is a self-assessment questionnaire, verified by an accredited body. Cyber Essentials Plus adds an independent, hands-on audit, where an assessor tests a sample of your devices directly to confirm the controls are genuinely working. Plus is the stronger, audited level, and you need current Cyber Essentials in place first.

Do we need Cyber Essentials before Cyber Essentials Plus?

Yes. You must hold a current Cyber Essentials certification first, and Plus is normally taken within three months of it. We can take you through both.

Who actually carries out the audit?

The audit is performed by an independent, accredited certification body. We get you audit-ready, review your controls against the requirements beforehand, and manage the process with the body on your behalf.

What does the assessor test?

An external vulnerability scan plus hands-on checks on a sample of your devices: patching, secure configuration, account and admin controls, multi-factor authentication, and malware and email defences.

How long does Cyber Essentials Plus take?

For most SMEs, a few weeks. The main variable is remediation. If your controls are already close, we can move quickly to the audit; if there are gaps, we close them first.

How long is it valid for?

Twelve months. You renew each year to keep your certification and register listing current, and we handle the renewal with you.

Get Cyber Essentials Plus certified

Book a no-obligation discovery session and we will map your route to the audited level.

Book a discovery session