---
title: "How to certify to Cyber Essentials Plus"
canonical: "https://ce-knowledge-hub.iasme.co.uk/space/CEKH/4412801084/How%20to%20certify%20to%20Cyber%20Essentials%20Plus"
format: markdown
---
Cyber Essentials Plus is an annually renewable certification and provides a higher level of assurance than Cyber Essentials. It uses the same five technical controls and begins with the Cyber Essentials verified self-assessment. It also includes a technical audit of your IT systems to check that the controls are implemented correctly.

## Step 1: Prepare for Cyber Essentials

Use the Cyber Essentials question set and Requirements for IT Infrastructure document, available from the IASME website, to understand the requirements and prepare your answers. The downloaded question set is for preparation only; it cannot be submitted as your assessment.

The assessment covers five technical controls:

- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection

## Step 2: Complete Cyber Essentials

Register for Cyber Essentials certification and complete the verified self-assessment questionnaire on the secure assessment platform. You can copy and paste answers from your preparation document, but the assessment must be completed on the platform.

A senior member of the board must electronically sign a declaration confirming that the answers are accurate. A qualified external Assessor will then mark the assessment.

You have six months from the date of application to pass the assessment and achieve Cyber Essentials certification.

## Step 3: Get a quote for Cyber Essentials Plus

Once you have passed Cyber Essentials, you can arrange your Cyber Essentials Plus audit. The audit must be completed within three months of your most recent Cyber Essentials certification.

It’s worth noting that the pass bar is set to a slightly higher level for Cyber Essentials Plus. Whereas it is possible to be able to pass the Cyber Essentials verified self-assessment with one or two non-compliances, if this is discovered on Cyber Essentials Plus, then the applicant has 30 days to remediate, but will not be able to pass until it is remediated. This means that even though the technical requirements are the same, the pass bar is set to a higher level. It is an audit of the technical requirements rather than a direct audit of the answers given in your verified self-assessment. Under the Danzell question set (April 2026 version), any non-conformities in the verified self-assessment must be remediated before moving onto Cyber Essentials Plus. 

You can request quotes through the[ IASME website](https://iasme.co.uk/cyber-essentials/). Your request will be sent to three different Certification Bodies who will provide you with their quote directly. Alternatively, you can choose to contact a Certification Body yourself.

The cost depends on the size and complexity of your organisation and its network.

## Step 4: Prepare for the technical audit

Agree the scope of the audit with your chosen Certification Body. The audit may be carried out remotely or on site and will include:

- An external vulnerability scan of each public IP address in scope
- Testing a representative sample of devices, including each operating system in use
- Checks on servers, desktop computers, laptops, thin clients, tablets and mobile phones, where applicable
- Checks that supported software is fully updated and that high and critical vulnerability fixes have been applied within 14 days
- Checks that malware protection or application allow listing is configured correctly
- Checks that standard users cannot carry out administrator tasks
- Checks that multi-factor authentication is used when users access all cloud services in scope

**The Certification Body will explain what information and access they need before the audit begins.**

## Step 5: Complete the audit and achieve certification

The Certification Body will carry out the agreed tests and assess whether each requirement has been met.

If a high or critical vulnerability is found, it must be fixed and the affected system must be rescanned before a pass can be awarded. If it cannot be fixed, the relevant test will fail.

All elements of the audit must be passed to achieve Cyber Essentials Plus certification. If any required test fails, the organisation will fail the overall assessment.