Cyber Essentials Plus Certification Support

Cyber Essentials and Cyber Essentials Plus

ProCheckUp helps organisations prepare for Cyber Essentials Plus and understand the technical checks involved.

Both certifications use the same five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. Cyber Essentials uses a verified self-assessment. Cyber Essentials Plus adds independent technical testing to check that the controls are implemented.

Plus is not a full penetration test or a broader set of security controls. Certification addresses the scheme’s baseline protection against common cyber threats; it does not guarantee that an organisation cannot be compromised. See IASME’s Cyber Essentials guidance for the scheme’s explanation.

Cyber Essentials Plus scheme logo

Discuss Cyber Essentials Plus readiness with your current certification position and the deadline you need to work towards.

Plan the assessment

  • Confirm scope: identify the organisation, locations, users, devices and services covered, including remote working and relevant cloud services.

  • Check prerequisites: confirm the Cyber Essentials certification position and applicable requirements before scheduling Plus testing.

  • Prepare the controls: compare the environment with the current scheme requirements and address readiness gaps.

  • Coordinate technical verification: agree the required access, evidence, technical contacts and assessment arrangements.

  • Resolve findings: address any issues through the scheme’s assessment process. Certification depends on meeting its requirements.

What to bring to a readiness discussion

  • An up-to-date inventory of devices, operating systems, software and relevant cloud services.

  • Details of remote working, device management and who administers the environment.

  • Your current Cyber Essentials certificate or assessment status and the scope it covers.

  • Known gaps, planned changes, supplier dependencies and the business deadline.

  • A contact who can coordinate access and remediation with the IT team or service provider.

What affects the work and schedule?

Scope, device diversity, management arrangements, access readiness and unresolved gaps affect preparation and coordination. Agree the assessment arrangements and any remediation dependencies before booking. A readiness review does not guarantee a certification result.

Keep certification and wider assurance distinct

Cyber Essentials Plus provides assurance about the scheme controls in the assessed scope. A separate penetration test may be appropriate when you need to investigate application logic, specific attack paths or other risks beyond those checks. Backups, staff training and wider monitoring can support security, but should not be presented as extra Plus control categories.

Further guidance

Use the current IASME questions and requirements when preparing. Our Cyber Essentials overview provides background; current scheme documents govern assessment requirements.

Discuss Cyber Essentials Plus readiness

Discuss Cyber Essentials Plus readiness. Tell us the organisation and environment to be covered, your certification status and any timing constraints. We can discuss the appropriate scope and next steps.

Need Help?

If you have any questions about cyber security or would like a free consultation, don't hesitate to give us a call!

Our Services

Keep up to date!


For More Information Please Contact Us

Smiling Person

ACCREDITATIONS