Cyber Essentials Plus

Cyber Essentials Plus adds independent hands-on testing to the Cyber Essentials self-assessment. Same five control areas; higher assurance for buyers.

Who it applies to

UK organisations needing the assured version of Cyber Essentials — often required for higher-value government or regulated buyers.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Pre-loaded Cyber Essentials Plus control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current Cyber Essentials Plus posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to Cyber Essentials Plus clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

CE+ audit day: what actually happens

A calm, structured half-day if you're prepared; a scramble if you're not.

External vulnerability scan

Your public-facing IPs are scanned. Any medium+ severity finding needs to be fixed or convincingly justified before certification.

Endpoint sample

The assessor selects endpoints from your device list. They verify patch levels, malware protection, secure config, and MFA on cloud services.

Malware and email test

The assessor sends test files and links. Your controls should block them without human intervention.

Debrief and remediation

Findings are shared same-day where possible. Low-severity findings can usually be remediated during a short remediation window.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

Preparing your device sample for CE+

The sample is not random. Get the inventory right and half the audit is done.

Accurate inventory

You supply the device inventory the assessor samples from. Missing devices = missing scope = fail.

OS and version coverage

The sample covers each OS and version in use. If you have three OS versions, expect at least three samples.

Cloud-managed vs unmanaged

Cloud-managed devices are usually easier to sample. Unmanaged laptops need a defined process before audit day.

BYOD and remote

Sample includes remote and BYOD if in scope. Have the process to reach those devices ready.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

Hardening for the CE+ external vulnerability scan

Run the scan yourself first. Fix findings before the assessor sees them.

Own your external footprint

You need a list of every internet-facing IP and hostname. Shadow subdomains are the #1 source of surprise findings.

Pre-scan

Run a free or low-cost scanner (OpenVAS, Nessus Essentials, Nuclei) before the audit. Fix the medium+ findings first.

Certificate and configuration issues

Expired certs, weak ciphers, missing HSTS — these are common CE+ findings. Fix them ahead of scan day.

Third-party assets

Managed vendor domains (support portals, marketing sites) can appear on the scan. Involve vendors early.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

The CE+ malware protection test explained

EICAR-style tests plus real-world benign payloads. Your controls should block quietly.

What's tested

EICAR string variants delivered by download, email attachment and drive-by. The malware protection control should block without user intervention.

Email flow

Test emails hit your inbound gateway. If they land in inbox and download successfully, that's a fail.

Browser download

Test files are downloaded via browser. Both file-based AV and browser-based safe-browsing controls matter.

Human-in-the-loop

Controls that only work if the user reports don't count. The block must be automatic.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

CE+ remote audit vs on-site: what's changed

Post-pandemic, most CE+ audits are remote. The bar hasn't changed; the mechanics have.

Remote is now standard

Video call, screen sharing, remote-scan tools. Efficient for both sides but requires more preparation.

Screen sharing hygiene

You'll share screens showing endpoints, admin consoles, patch reports. Prepare a clean desktop and closed personal tabs.

Time zone and availability

Remote makes it easier to book — and easier to overbook. Assessor availability is often the bottleneck.

On-site still available

Some assessors and clients prefer on-site. It doesn't change the technical bar.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

CE+ vs ISO 27001: complementary, not competing

CE+ is a technical baseline check. ISO 27001 is a management system. Sophisticated programmes have both.

Different questions answered

CE+ answers 'do the five controls actually work?'. ISO 27001 answers 'do you have a working management system for security?'.

Buyer signal

UK SME buyers often ask for CE+ first, ISO 27001 for larger contracts. Both together cover the widest procurement gate.

Shared evidence

Access control, patching, malware, MFA evidence for CE+ is also Annex A evidence for ISO 27001. Collect once, use twice.

Sequence

Most maturing programmes go CE → CE+ → ISO 27001. It's a defensible trajectory.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

The CE+ remediation window: how to use it

Small findings on audit day can often be fixed and re-verified before certification is issued.

The window

IASME allows a short remediation window (typically 30 days) for minor findings identified during CE+. Major failures don't qualify.

Prioritise

Fix findings that require re-testing first (patch levels, config changes). Documentation-only fixes can wait a day or two.

Re-verification

The assessor re-tests the fixed items. Screenshots and reports usually suffice; some items may need re-scan.

Root cause

The finding tells you something about your controls. Fix the root cause, not just the instance — you'll thank yourself at next audit.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

How much CE+ costs and how long it takes

Cost varies by size. Timing is fairly predictable if you prepare properly.

Cost

Typical range for a small/medium organisation: £1,500–£5,000 for the assessor's time, on top of the CE application fee. Complex estates cost more.

Timeline

From application to certificate: 6–10 weeks for well-prepared organisations. Unprepared ones can drag to 3+ months.

Renewal

Annual. If you keep the controls running between audits, renewal is faster and cheaper each year.

Hidden costs

Remediation costs (tooling upgrades, extra licences) can dwarf the audit fee. Budget for them in the first cycle.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

CE+ for servers, mobile devices and cloud VMs

The estate is more than laptops. Every device that meets the definition is potentially in sample.

Servers

Physical, virtual and cloud servers all count if in scope. Patch reports and endpoint config are checked.

Mobile devices

Corporate-owned mobiles used for email or corporate apps are in scope. BYOD is in scope if used for the same.

Cloud VMs

IaaS VMs are endpoints for CE+ purposes. PaaS is generally treated as a cloud service.

Containerised workloads

Not endpoints in the classical sense — but the host cluster and admin controls are. The assessor will look for defensible boundaries.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

Life after CE+: monitoring the controls year-round

The badge is a moment. The trust it earns comes from what you do between audits.

Monthly control checks

Patch coverage, MFA coverage, endpoint compliance. Automate reports and review them monthly.

Quarterly BYOD/joiner audit

Cover the drift areas that fail most often between audits.

Publish in the Trust Center

Buyers ask 'do you still have CE+?'. Publish it with expiry. Cuts the questionnaire tail.

Continuous evidence

Evidence collected continuously is dramatically cheaper than a pre-audit scramble. Instrument the controls, not the audit.

How ISO-STANDARD.app helps with Cyber Essentials Plus

Inside the workspace, this topic maps to concrete artefacts: pre-loaded Cyber Essentials Plus controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the Cyber Essentials Plus shape.

Ready to evidence Cyber Essentials Plus?

Load the pre-mapped controls, capture evidence continuously, and publish your Cyber Essentials Plus posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.