Cyber Essentials Plus Certification UK
Cyber Essentials Plus is the independently audited tier: an IASME-accredited assessor tests the same five controls hands-on, with boundary and internal vulnerability scans and device-sample testing. Cyber Essentials Plus requires a valid Cyber Essentials certificate first. We are an active IASME-accredited certification body, issue your certificate directly, and run a pre-audit gap analysis so you pass first time.
- IASME-accredited assessors
- Pre-audit gap analysis
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
from scope to active testing. Pre-audit gap analysis, IASME-accredited assessor delivery and direct certificate issuance, end to end in 5 to 15 working days.
Self-certified Cyber Essentials questionnaires won’t satisfy enterprise procurement. CE+ testing will.
Cyber Essentials, the self-assessment tier, is a starting point, fine for smaller suppliers and lower-risk procurement. Cyber Essentials Plus adds independent technical testing by an IASME-accredited assessor: confirmed boundary firewall, confirmed device patching, confirmed secure configuration, validated user access controls, and validated malware protection.
UK government and enterprise procurement increasingly require CE+ rather than CE. We are an active IASME Cyber Essentials Certification Body, verifiable on the IASME registry. Our assessors deliver the full CE+ technical test, issue certificates directly, and provide pre-audit gap analysis to ensure first-time pass.
Reports satisfy UK government supplier requirements (CCS, G-Cloud), align with NHS DSPT, and provide evidence accepted by cyber-insurance underwriters as a baseline maturity signal.
CE+ TECHNICAL TEST · 5 CONTROLS
What We Test in Cyber Essentials Plus
IASME-accredited assessor-led testing across the five Cyber Essentials Plus technical controls, with pre-audit gap analysis included.
Boundary Firewalls & Internet Gateways
External vulnerability scanning of every internet-facing device. Default credential testing. Configuration review against IASME standard.
Secure Configuration
Sample device build review. Default password audit. Unnecessary service identification. Account and role configuration validation.
User Access Control
MFA enforcement validation, least-privilege role review, joiners, movers and leavers process audit, admin account separation.
Malware Protection
Anti-malware product validation, signature update verification, real-time protection enforcement, sample malicious-file detection test.
Security Update Management
Patch level assessment across all in-scope devices. Operating system, browser and application updates verified. Critical patch lag analysis.
Cloud Service Scoping
Cloud-services-in-scope determination (Microsoft 365, Google Workspace, AWS, Azure, GCP). 2022 update: cloud is now in CE+ scope by default.
Boundary Vulnerability Scan
External authenticated and unauthenticated vulnerability scan. Confirmed via screenshots and device-by-device evidence.
Internal Authenticated Scan
Internal device scan from an authenticated user perspective. Patch level, configuration drift, malware product, secure baseline.
Mobile Device Scan
Where in scope: mobile device build review, MDM enforcement, app store policy, encryption at rest validation.
Pre-Audit Gap Analysis
Pre-engagement gap analysis included with the mid-market and above tier. Identifies issues before formal CE+ assessment, first-time pass rate above 95%.
Remediation Support
Failed control items: 30-day remediation window with IASME-aligned remediation guidance.
Certificate Issuance
Direct issuance of an IASME-stamped Cyber Essentials Plus certificate. Listed in the IASME registry. Branded certificate for procurement portfolios.
FOUR-PHASE METHODOLOGY
Cyber Essentials Plus: From Gap Analysis to Certificate
Pre-audit gap analysis, IASME-accredited assessor delivery, first-time-pass focus and fast certificate issuance.
Pre-Audit Gap Analysis
Sample-device review against the five CE+ controls. Issues identified before the formal assessment. First-time-pass rate above 95% for clients who complete gap analysis.
Self-Assessment Questionnaire
Cyber Essentials self-assessment completed and verified by our assessor. Cyber Essentials certificate issued at this stage if certifying to CE only.
Technical Test
An IASME-accredited assessor runs the formal CE+ technical test: boundary scan, internal scan, sample device review, mobile review, cloud scoping.
Certificate Issuance
IASME-stamped CE+ certificate issued within 5 to 10 working days of test completion. Listed in the IASME registry. Annual renewal cycle.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a fixed Cyber Essentials Plus quote in 24 hours
A fixed-price quote back in one business day from a named IASME-accredited assessor, with a pre-audit gap analysis and a named lead assessor. No sales pipeline.
- IASME-accredited assessor delivery. Certification your auditors and clients already recognise.
- Pre-audit gap analysis to ensure first-time pass. Issues identified before the formal assessment.
- Direct IASME certificate issuance, listed on the IASME registry.
- Fixed price, agreed after a short scoping call. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named IASME-accredited assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Pre-audit gap analysis identifies issues before the formal assessment, and we advise you on exactly what to implement so you pass first time.
- We send the Cyber Essentials questionnaire and analyse your responses.
- Once you pass, we issue your IASME-stamped certificate and list it on the IASME registry.
Get your fixed Cyber Essentials Plus quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named IASME-accredited assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Cyber Essentials Plus Mapped to Every Framework
CE+ as a foundation control set, recognised across UK procurement, regulatory and insurance frameworks.
UK Government Supplier
CE+ is mandatory for HMG suppliers handling sensitive government data. CCS framework, G-Cloud framework, NHS supplier framework alignment.
NHS DSPT
CE+ is recognised evidence for NHS DSPT Standard 9 (Asset 7): boundary control, secure configuration, malware protection.
Cyber Insurance
UK cyber-insurance underwriters typically reduce premiums by 5 to 15% for CE+ certified businesses. Some cyber insurance policies require CE+ at renewal.
Enterprise Procurement
CE+ is the de facto baseline for enterprise vendor onboarding in regulated industries (banking, insurance, legal).
IASME Cyber Assurance
For organisations needing more than CE+, IASME Cyber Assurance is the next tier. Aligned to ISO 27001 but a lighter-touch certification process.
ISO 27001 Foundation
The CE+ control set maps directly to a subset of ISO 27001 Annex A controls (A.13 networking, A.12.6 vulnerabilities, A.9 access).
PRICING
Transparent Cyber Essentials Plus Pricing
Cyber Essentials Plus pricing scales with your size and cloud scope, fixed-price after a short scoping call. A valid Cyber Essentials certificate is required first. Prices exclude VAT.
+ VAT · the prerequisite certificate
Cyber Essentials Plus requires a valid Cyber Essentials certificate first. We manage the whole certification: the verified self-assessment and direct liaison with IASME.
Get Cyber Essentials+ VAT · 50 to 250 employees £1,200 to £3,500
Independent IASME-accredited technical audit of all five controls, with boundary and internal vulnerability scans and device-sample testing. 5 to 15 working days. Most commissioned by mid-market organisations.
Get a fixed quote+ VAT · 250+ employees or complex cloud
For larger organisations (250+ employees) or complex multi-cloud environments. Independent technical audit scoped to your full estate, with boundary and internal scans across a representative device sample.
Get a fixed quoteAll quotes are fixed-price after a short scoping call.
BY SECTOR
Cyber Essentials Plus for Your Sector
CE+ is increasingly required across sectors; compliance and procurement evidence varies by industry.
Fintech
FCA-regulated firms, Open Banking, payment APIs, PCI scoping.
Fintech sector pageSaaS
Multi-tenant isolation, SSO, SAML and OIDC, customer-data perimeter, SOC 2 evidence.
SaaS sector pageLaw
Privileged-data confidentiality, partner-tier scrutiny, SRA Cyber Standard alignment.
Law firm sector pageHealthcare
NHS DSPT, NHS DTAC, EHR integration, telehealth, patient-data PII.
Healthcare sector pageInsurance
FCA and PRA Operational Resilience, claims data, broker integrations, cyber underwriting evidence.
Insurance sector pagePublic Sector
CCS and G-Cloud framework, NCSC-aligned, SC-cleared testers available.
Public sector pageWHY EJN LABS
What You Actually Get
Six things that distinguish independently audited Cyber Essentials Plus from a DIY self-assessment.
What You Get From CE+
IASME-accredited assessor delivery, pre-audit gap analysis, fast certificate issuance, IASME registry listing, and a branded certificate for procurement portfolios.
Independent Technical Audit
An IASME-accredited assessor tests all five controls hands-on, not a self-declaration. Boundary and internal vulnerability scans plus sample device review.
Pre-Audit Gap Analysis
Identify failures before the formal CE+ assessment. First-time-pass rate above 95% for clients who complete gap analysis.
IASME Certification Body
We issue CE and CE+ certificates directly. Verifiable on the IASME registry. The Cyber Essentials Plus certificate carries the IASME stamp.
Device-Sample Vulnerability Testing
Boundary and internal authenticated scans across a representative sample of in-scope devices, with device-by-device evidence.
UK CREST + IASME + ISO 27001 + ISO 9001
Multi-accredited. Reports accepted by every UK auditor, regulator and procurement framework.
FAQ
Frequently Asked
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials Plus (CE+) is the independently audited tier: an IASME-accredited assessor runs vulnerability scans and sample device testing to verify the same five controls hands-on. Cyber Essentials (CE) is the verified self-assessment that comes first; you confirm your controls in writing and an assessor reviews and issues the certificate. CE+ requires a valid Cyber Essentials certificate first, so most organisations certify to Cyber Essentials and add Plus when a contract requires the independent audit.
How much does Cyber Essentials Plus cost in the UK?
Cyber Essentials Plus is £1,200 to £3,500 for most organisations (50 to 250 employees), and £3,500+ for 250+ employees or complex cloud environments. Pricing depends on your size and cloud scope. CE+ also requires a valid Cyber Essentials certificate first. All quotes are fixed-price after a short scoping call.
How long does Cyber Essentials Plus take?
Pre-audit gap analysis: 2 to 3 working days. Formal CE+ assessment: 1 to 2 days on-site (or remote for cloud-only organisations). Certificate issuance: 5 to 10 working days from assessment completion. Total end to end: 5 to 15 working days for most organisations.
Are you an IASME Certification Body?
Yes. We are an active IASME Cyber Essentials Certification Body, verifiable on the IASME registry. Our IASME accreditation is independent and externally audited.
Will Cyber Essentials Plus reduce our cyber insurance premium?
UK cyber-insurance underwriters typically reduce premiums by 5 to 15% for CE+ certified businesses. In our experience, some cyber insurance policies require Cyber Essentials Plus at renewal, more often at higher premium tiers.
Is CE+ required for UK government work?
For UK government suppliers handling sensitive data, CE+ is typically required (the Cabinet Office Procurement Policy Note 014 sets out when Cyber Essentials and Cyber Essentials Plus apply to public-sector contracts). Crown Commercial Service (CCS) and G-Cloud framework participants commonly need CE+.
Do you offer pre-audit gap analysis?
Yes. Our mid-tier and above engagements include pre-audit gap analysis. We review sample devices and configurations against the CE+ control set before the formal assessment, identify failures, and give your team time to remediate before the official test. First-time-pass rate above 95% for clients who complete gap analysis.
What happens if we fail a CE+ control?
30-day remediation window. We provide IASME-aligned remediation guidance for each failed control, and most clients pass the retest after addressing the gap-analysis findings.
Does CE+ cover cloud services?
Yes. As of 2022, cloud services (Microsoft 365, Google Workspace, AWS, Azure, GCP) are in scope by default for CE+. The assessment validates cloud configuration against the same five technical controls: boundary firewall, secure configuration, user access, malware protection, and security updates.
What is IASME Cyber Assurance?
IASME Cyber Assurance is a more comprehensive certification standard that goes beyond Cyber Essentials Plus. It is aligned to ISO 27001 (covering similar control areas) but uses a lighter-touch certification process. Suitable for organisations that need more rigour than CE+ but find ISO 27001 disproportionate.
How often must we recertify?
Cyber Essentials and Cyber Essentials Plus are annual certifications. Recertification typically takes 80 to 90% of the original engagement effort, with focus on changes since the prior assessment. Annual renewal is included with our enterprise tier.
Do you sign NDAs?
Yes. Standard NDA before any technical detail is shared. We operate under a project-specific master agreement that includes data handling, deliverable IP, and breach notification clauses.
20+ CREST-certified testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed Cyber Essentials Plus quote in 24 hours
An IASME-accredited assessor will contact you within one business day with a fixed-price quote, a pre-audit gap analysis and a named lead assessor. No sales pipeline.



