Cyber Essentials Plus Certification: Self Certification

Cyber Essentials Plus certification with independent technical verification

Higher-Assurance Certification

Includes Cyber Essentials certification

External vulnerability scanning included

Independent technical assessment and device sampling

Retest included if required (scheme rules apply)

Certificate valid for 12 months

Important: Cyber Essentials Plus includes independent technical testing. If issues are identified, remediation will be required before certification can be issued.

Cyber Essentials Plus – higher assurance, real verification

Cyber Essentials Plus is the advanced version of Cyber Essentials.

Unlike standard certification, Plus includes independent technical testing to confirm your cybersecurity controls are properly implemented across your organisation.

Testing typically includes:

External vulnerability scanning

Device sampling and configuration checks

MFA validation

Patch management verification

Malware protection checks

User access and admin control review

This certification is ideal for organisations working in regulated sectors or supply chains where higher security assurance is expected.

What’s Included

Cyber Essentials certification support

Cyber Essentials Plus technical assessment

External vulnerability scan

Independent technical testing

Retest included if required

Certification issued on success

Certification valid for 12 months

Who This Is Best For

This service is ideal if:

Your customers require CE Plus

You work in regulated industries

You handle sensitive client data

You want independent verification for compliance

If you require hands-on support, we recommend our Assisted or Fully Managed packages.

Why Cyber Essentials Plus matters

Independent testing builds credibility

This is proof your security works, not just that it’s documented.

Required for certain contracts

Many high-security procurement frameworks require Plus.

Stronger competitive positioning

CE Plus gives customers confidence and reduces objections.

Improved cyber resilience

The testing process identifies real weaknesses before attackers do.

Important Information Before Purchase

Please review the following before purchase:

 • Cyber Essentials must be achieved before Plus certification is issued.
 • Independent testing includes device sampling based on scheme requirements.
 • If vulnerabilities are found, remediation must be completed before certification.
 • Retest is included where applicable under scheme rules.
 • Certification is valid for 12 months.
 • Assessment scheduling depends on availability.

Our security certifications

Cyber EssentialsCyber Essentials PlusPen Test accreditation logoVonahi Security logoISO Certification Image

Penetration testing services delivered in partnership with a CREST-accredited provider

Cyber Essentials Certification

Secure checkout

 UK-based support team

 Fast onboarding

Designed for SMEs

Transparent fixed pricing

Need certification for a tender deadline? Speak to us before purchasing to discuss fast-track options.

Additional add-ons you may be interested in

Cyber Essentials Plus – Get A Little Help

Extra preparation support to reduce retest risk.

Cyber Essentials Plus – Get Lots of Help

Best for complex environments and multi-site organisations.

Vulnerability Management

Policy templates and documentation to help speedOngoing scanning beyond certification. up compliance.

Managed Cyber Security

Stay protected long after certification

What is Cyber Essentials Plus?

Cyber Essentials Plus is the higher tier of the scheme. An independent assessor tests your security controls hands-on to confirm they actually work, rather than taking your word for it.

What does the assessment include?

Testing usually covers vulnerability scanning, a sample of your devices, MFA checks, patch verification and malware protection checks.

Do we need Cyber Essentials first?

Yes. You have to hold Cyber Essentials before CE Plus can be issued.

How long does Cyber Essentials Plus take?

Most organisations finish in 2 to 4 weeks, depending on readiness and scheduling.

What happens if vulnerabilities are found?

You get a window to fix them, and you may need a retest before the certificate is issued.

GET CERTIFIED

Get Cyber Essentials Plus Certified

The entry route to Cyber Essentials Plus. We prepare you for the technical audit, fix what's needed, and get you certified with support when you need it.

0333 370 7000

Mon-Fri 8am-5pm · 24/7 for managed clients

[email protected]

Response within 1 business day, guaranteed

United Kingdom

UK-based team, since 2012

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.