Cyber Essentials Plus
Cyber Essentials Plus adds independent hands-on testing to the Cyber Essentials self-assessment. Same five control areas; higher assurance for buyers.
Who it applies to
UK organisations needing the assured version of Cyber Essentials — often required for higher-value government or regulated buyers.
How ISO-STANDARD.app helps with Cyber Essentials Plus
10 in-depth articles
CE+ audit day: what actually happens
A calm, structured half-day if you're prepared; a scramble if you're not.
External vulnerability scan
Your public-facing IPs are scanned. Any medium+ severity finding needs to be fixed or convincingly justified before certification.
Endpoint sample
The assessor selects endpoints from your device list. They verify patch levels, malware protection, secure config, and MFA on cloud services.
Malware and email test
The assessor sends test files and links. Your controls should block them without human intervention.
Debrief and remediation
Findings are shared same-day where possible. Low-severity findings can usually be remediated during a short remediation window.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
Preparing your device sample for CE+
The sample is not random. Get the inventory right and half the audit is done.
Accurate inventory
You supply the device inventory the assessor samples from. Missing devices = missing scope = fail.
OS and version coverage
The sample covers each OS and version in use. If you have three OS versions, expect at least three samples.
Cloud-managed vs unmanaged
Cloud-managed devices are usually easier to sample. Unmanaged laptops need a defined process before audit day.
BYOD and remote
Sample includes remote and BYOD if in scope. Have the process to reach those devices ready.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
Hardening for the CE+ external vulnerability scan
Run the scan yourself first. Fix findings before the assessor sees them.
Own your external footprint
You need a list of every internet-facing IP and hostname. Shadow subdomains are the #1 source of surprise findings.
Pre-scan
Run a free or low-cost scanner (OpenVAS, Nessus Essentials, Nuclei) before the audit. Fix the medium+ findings first.
Certificate and configuration issues
Expired certs, weak ciphers, missing HSTS — these are common CE+ findings. Fix them ahead of scan day.
Third-party assets
Managed vendor domains (support portals, marketing sites) can appear on the scan. Involve vendors early.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
The CE+ malware protection test explained
EICAR-style tests plus real-world benign payloads. Your controls should block quietly.
What's tested
EICAR string variants delivered by download, email attachment and drive-by. The malware protection control should block without user intervention.
Email flow
Test emails hit your inbound gateway. If they land in inbox and download successfully, that's a fail.
Browser download
Test files are downloaded via browser. Both file-based AV and browser-based safe-browsing controls matter.
Human-in-the-loop
Controls that only work if the user reports don't count. The block must be automatic.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
CE+ remote audit vs on-site: what's changed
Post-pandemic, most CE+ audits are remote. The bar hasn't changed; the mechanics have.
Remote is now standard
Video call, screen sharing, remote-scan tools. Efficient for both sides but requires more preparation.
Screen sharing hygiene
You'll share screens showing endpoints, admin consoles, patch reports. Prepare a clean desktop and closed personal tabs.
Time zone and availability
Remote makes it easier to book — and easier to overbook. Assessor availability is often the bottleneck.
On-site still available
Some assessors and clients prefer on-site. It doesn't change the technical bar.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
CE+ vs ISO 27001: complementary, not competing
CE+ is a technical baseline check. ISO 27001 is a management system. Sophisticated programmes have both.
Different questions answered
CE+ answers 'do the five controls actually work?'. ISO 27001 answers 'do you have a working management system for security?'.
Buyer signal
UK SME buyers often ask for CE+ first, ISO 27001 for larger contracts. Both together cover the widest procurement gate.
Shared evidence
Access control, patching, malware, MFA evidence for CE+ is also Annex A evidence for ISO 27001. Collect once, use twice.
Sequence
Most maturing programmes go CE → CE+ → ISO 27001. It's a defensible trajectory.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
The CE+ remediation window: how to use it
Small findings on audit day can often be fixed and re-verified before certification is issued.
The window
IASME allows a short remediation window (typically 30 days) for minor findings identified during CE+. Major failures don't qualify.
Prioritise
Fix findings that require re-testing first (patch levels, config changes). Documentation-only fixes can wait a day or two.
Re-verification
The assessor re-tests the fixed items. Screenshots and reports usually suffice; some items may need re-scan.
Root cause
The finding tells you something about your controls. Fix the root cause, not just the instance — you'll thank yourself at next audit.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
How much CE+ costs and how long it takes
Cost varies by size. Timing is fairly predictable if you prepare properly.
Cost
Typical range for a small/medium organisation: £1,500–£5,000 for the assessor's time, on top of the CE application fee. Complex estates cost more.
Timeline
From application to certificate: 6–10 weeks for well-prepared organisations. Unprepared ones can drag to 3+ months.
Renewal
Annual. If you keep the controls running between audits, renewal is faster and cheaper each year.
Hidden costs
Remediation costs (tooling upgrades, extra licences) can dwarf the audit fee. Budget for them in the first cycle.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
CE+ for servers, mobile devices and cloud VMs
The estate is more than laptops. Every device that meets the definition is potentially in sample.
Servers
Physical, virtual and cloud servers all count if in scope. Patch reports and endpoint config are checked.
Mobile devices
Corporate-owned mobiles used for email or corporate apps are in scope. BYOD is in scope if used for the same.
Cloud VMs
IaaS VMs are endpoints for CE+ purposes. PaaS is generally treated as a cloud service.
Containerised workloads
Not endpoints in the classical sense — but the host cluster and admin controls are. The assessor will look for defensible boundaries.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
Life after CE+: monitoring the controls year-round
The badge is a moment. The trust it earns comes from what you do between audits.
Monthly control checks
Patch coverage, MFA coverage, endpoint compliance. Automate reports and review them monthly.
Quarterly BYOD/joiner audit
Cover the drift areas that fail most often between audits.
Publish in the Trust Center
Buyers ask 'do you still have CE+?'. Publish it with expiry. Cuts the questionnaire tail.
Continuous evidence
Evidence collected continuously is dramatically cheaper than a pre-audit scramble. Instrument the controls, not the audit.
How ISO-STANDARD.app helps with Cyber Essentials Plus
Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.
Ready to evidence Cyber Essentials Plus?
Load the pre-mapped controls, capture evidence continuously, and publish your Cyber Essentials Plus posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.