CYBER ESSENTIALS PLUS CERTIFICATION

Cyber Essentials Plus Certification UK

Cyber Essentials Plus is the independently audited tier: an IASME-accredited assessor tests the same five controls hands-on, with boundary and internal vulnerability scans and device-sample testing. Cyber Essentials Plus requires a valid Cyber Essentials certificate first. We are an active IASME-accredited certification body, issue your certificate directly, and run a pre-audit gap analysis so you pass first time.

  • IASME-accredited assessors
  • Pre-audit gap analysis
  • No hidden fees
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
5–15
Working days, audit
IASME
Accredited body
>95%
First-time pass
5
Controls independently tested
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori
WHY IT MATTERS
24h

from scope to active testing. Pre-audit gap analysis, IASME-accredited assessor delivery and direct certificate issuance, end to end in 5 to 15 working days.

Self-certified Cyber Essentials questionnaires won’t satisfy enterprise procurement. CE+ testing will.

Cyber Essentials, the self-assessment tier, is a starting point, fine for smaller suppliers and lower-risk procurement. Cyber Essentials Plus adds independent technical testing by an IASME-accredited assessor: confirmed boundary firewall, confirmed device patching, confirmed secure configuration, validated user access controls, and validated malware protection.

UK government and enterprise procurement increasingly require CE+ rather than CE. We are an active IASME Cyber Essentials Certification Body, verifiable on the IASME registry. Our assessors deliver the full CE+ technical test, issue certificates directly, and provide pre-audit gap analysis to ensure first-time pass.

Reports satisfy UK government supplier requirements (CCS, G-Cloud), align with NHS DSPT, and provide evidence accepted by cyber-insurance underwriters as a baseline maturity signal.

CE+ TECHNICAL TEST · 5 CONTROLS

What We Test in Cyber Essentials Plus

IASME-accredited assessor-led testing across the five Cyber Essentials Plus technical controls, with pre-audit gap analysis included.

CE-1

Boundary Firewalls & Internet Gateways

External vulnerability scanning of every internet-facing device. Default credential testing. Configuration review against IASME standard.

CE-2

Secure Configuration

Sample device build review. Default password audit. Unnecessary service identification. Account and role configuration validation.

CE-3

User Access Control

MFA enforcement validation, least-privilege role review, joiners, movers and leavers process audit, admin account separation.

CE-4

Malware Protection

Anti-malware product validation, signature update verification, real-time protection enforcement, sample malicious-file detection test.

CE-5

Security Update Management

Patch level assessment across all in-scope devices. Operating system, browser and application updates verified. Critical patch lag analysis.

CE-6

Cloud Service Scoping

Cloud-services-in-scope determination (Microsoft 365, Google Workspace, AWS, Azure, GCP). 2022 update: cloud is now in CE+ scope by default.

CE-7

Boundary Vulnerability Scan

External authenticated and unauthenticated vulnerability scan. Confirmed via screenshots and device-by-device evidence.

CE-8

Internal Authenticated Scan

Internal device scan from an authenticated user perspective. Patch level, configuration drift, malware product, secure baseline.

CE-9

Mobile Device Scan

Where in scope: mobile device build review, MDM enforcement, app store policy, encryption at rest validation.

CE-10

Pre-Audit Gap Analysis

Pre-engagement gap analysis included with the mid-market and above tier. Identifies issues before formal CE+ assessment, first-time pass rate above 95%.

CE-11

Remediation Support

Failed control items: 30-day remediation window with IASME-aligned remediation guidance.

CE-12

Certificate Issuance

Direct issuance of an IASME-stamped Cyber Essentials Plus certificate. Listed in the IASME registry. Branded certificate for procurement portfolios.

FOUR-PHASE METHODOLOGY

Cyber Essentials Plus: From Gap Analysis to Certificate

Pre-audit gap analysis, IASME-accredited assessor delivery, first-time-pass focus and fast certificate issuance.

01

Pre-Audit Gap Analysis

Sample-device review against the five CE+ controls. Issues identified before the formal assessment. First-time-pass rate above 95% for clients who complete gap analysis.

02

Self-Assessment Questionnaire

Cyber Essentials self-assessment completed and verified by our assessor. Cyber Essentials certificate issued at this stage if certifying to CE only.

03

Technical Test

An IASME-accredited assessor runs the formal CE+ technical test: boundary scan, internal scan, sample device review, mobile review, cloud scoping.

04

Certificate Issuance

IASME-stamped CE+ certificate issued within 5 to 10 working days of test completion. Listed in the IASME registry. Annual renewal cycle.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a fixed Cyber Essentials Plus quote in 24 hours

A fixed-price quote back in one business day from a named IASME-accredited assessor, with a pre-audit gap analysis and a named lead assessor. No sales pipeline.

  • IASME-accredited assessor delivery. Certification your auditors and clients already recognise.
  • Pre-audit gap analysis to ensure first-time pass. Issues identified before the formal assessment.
  • Direct IASME certificate issuance, listed on the IASME registry.
  • Fixed price, agreed after a short scoping call. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named IASME-accredited assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Pre-audit gap analysis identifies issues before the formal assessment, and we advise you on exactly what to implement so you pass first time.
  4. We send the Cyber Essentials questionnaire and analyse your responses.
  5. Once you pass, we issue your IASME-stamped certificate and list it on the IASME registry.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed Cyber Essentials Plus quote in 24 hours

24h reply IASME assessor Gap analysis

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Cyber Essentials Plus Mapped to Every Framework

CE+ as a foundation control set, recognised across UK procurement, regulatory and insurance frameworks.

UK Government Supplier

CE+ is mandatory for HMG suppliers handling sensitive government data. CCS framework, G-Cloud framework, NHS supplier framework alignment.

NHS DSPT

CE+ is recognised evidence for NHS DSPT Standard 9 (Asset 7): boundary control, secure configuration, malware protection.

Cyber Insurance

UK cyber-insurance underwriters typically reduce premiums by 5 to 15% for CE+ certified businesses. Some cyber insurance policies require CE+ at renewal.

Enterprise Procurement

CE+ is the de facto baseline for enterprise vendor onboarding in regulated industries (banking, insurance, legal).

IASME Cyber Assurance

For organisations needing more than CE+, IASME Cyber Assurance is the next tier. Aligned to ISO 27001 but a lighter-touch certification process.

ISO 27001 Foundation

The CE+ control set maps directly to a subset of ISO 27001 Annex A controls (A.13 networking, A.12.6 vulnerabilities, A.9 access).

PRICING

Transparent Cyber Essentials Plus Pricing

Cyber Essentials Plus pricing scales with your size and cloud scope, fixed-price after a short scoping call. A valid Cyber Essentials certificate is required first. Prices exclude VAT.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
IASME registry listing
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-minute walkthrough call
Letter of attestation
CYBER ESSENTIALS (REQUIRED FIRST)
From £400
+ VAT · the prerequisite certificate

Cyber Essentials Plus requires a valid Cyber Essentials certificate first. We manage the whole certification: the verified self-assessment and direct liaison with IASME.

Get Cyber Essentials
CYBER ESSENTIALS PLUS
£3,500+
+ VAT · 250+ employees or complex cloud

For larger organisations (250+ employees) or complex multi-cloud environments. Independent technical audit scoped to your full estate, with boundary and internal scans across a representative device sample.

Get a fixed quote

All quotes are fixed-price after a short scoping call.

WHY EJN LABS

What You Actually Get

Six things that distinguish independently audited Cyber Essentials Plus from a DIY self-assessment.

What You Get From CE+

IASME-accredited assessor delivery, pre-audit gap analysis, fast certificate issuance, IASME registry listing, and a branded certificate for procurement portfolios.

Independent Technical Audit

An IASME-accredited assessor tests all five controls hands-on, not a self-declaration. Boundary and internal vulnerability scans plus sample device review.

Pre-Audit Gap Analysis

Identify failures before the formal CE+ assessment. First-time-pass rate above 95% for clients who complete gap analysis.

IASME Certification Body

We issue CE and CE+ certificates directly. Verifiable on the IASME registry. The Cyber Essentials Plus certificate carries the IASME stamp.

Device-Sample Vulnerability Testing

Boundary and internal authenticated scans across a representative sample of in-scope devices, with device-by-device evidence.

UK CREST + IASME + ISO 27001 + ISO 9001

Multi-accredited. Reports accepted by every UK auditor, regulator and procurement framework.

FAQ

Frequently Asked

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials Plus (CE+) is the independently audited tier: an IASME-accredited assessor runs vulnerability scans and sample device testing to verify the same five controls hands-on. Cyber Essentials (CE) is the verified self-assessment that comes first; you confirm your controls in writing and an assessor reviews and issues the certificate. CE+ requires a valid Cyber Essentials certificate first, so most organisations certify to Cyber Essentials and add Plus when a contract requires the independent audit.

How much does Cyber Essentials Plus cost in the UK?

Cyber Essentials Plus is £1,200 to £3,500 for most organisations (50 to 250 employees), and £3,500+ for 250+ employees or complex cloud environments. Pricing depends on your size and cloud scope. CE+ also requires a valid Cyber Essentials certificate first. All quotes are fixed-price after a short scoping call.

How long does Cyber Essentials Plus take?

Pre-audit gap analysis: 2 to 3 working days. Formal CE+ assessment: 1 to 2 days on-site (or remote for cloud-only organisations). Certificate issuance: 5 to 10 working days from assessment completion. Total end to end: 5 to 15 working days for most organisations.

Are you an IASME Certification Body?

Yes. We are an active IASME Cyber Essentials Certification Body, verifiable on the IASME registry. Our IASME accreditation is independent and externally audited.

Will Cyber Essentials Plus reduce our cyber insurance premium?

UK cyber-insurance underwriters typically reduce premiums by 5 to 15% for CE+ certified businesses. In our experience, some cyber insurance policies require Cyber Essentials Plus at renewal, more often at higher premium tiers.

Is CE+ required for UK government work?

For UK government suppliers handling sensitive data, CE+ is typically required (the Cabinet Office Procurement Policy Note 014 sets out when Cyber Essentials and Cyber Essentials Plus apply to public-sector contracts). Crown Commercial Service (CCS) and G-Cloud framework participants commonly need CE+.

Do you offer pre-audit gap analysis?

Yes. Our mid-tier and above engagements include pre-audit gap analysis. We review sample devices and configurations against the CE+ control set before the formal assessment, identify failures, and give your team time to remediate before the official test. First-time-pass rate above 95% for clients who complete gap analysis.

What happens if we fail a CE+ control?

30-day remediation window. We provide IASME-aligned remediation guidance for each failed control, and most clients pass the retest after addressing the gap-analysis findings.

Does CE+ cover cloud services?

Yes. As of 2022, cloud services (Microsoft 365, Google Workspace, AWS, Azure, GCP) are in scope by default for CE+. The assessment validates cloud configuration against the same five technical controls: boundary firewall, secure configuration, user access, malware protection, and security updates.

What is IASME Cyber Assurance?

IASME Cyber Assurance is a more comprehensive certification standard that goes beyond Cyber Essentials Plus. It is aligned to ISO 27001 (covering similar control areas) but uses a lighter-touch certification process. Suitable for organisations that need more rigour than CE+ but find ISO 27001 disproportionate.

How often must we recertify?

Cyber Essentials and Cyber Essentials Plus are annual certifications. Recertification typically takes 80 to 90% of the original engagement effort, with focus on changes since the prior assessment. Annual renewal is included with our enterprise tier.

Do you sign NDAs?

Yes. Standard NDA before any technical detail is shared. We operate under a project-specific master agreement that includes data handling, deliverable IP, and breach notification clauses.

EXPLORE EVERY SERVICE

20+ CREST-certified testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO SCOPE

Get a fixed Cyber Essentials Plus quote in 24 hours

An IASME-accredited assessor will contact you within one business day with a fixed-price quote, a pre-audit gap analysis and a named lead assessor. No sales pipeline.