Cyber Essentials and Cyber Essentials Plus
ProCheckUp helps organisations prepare for Cyber Essentials Plus and understand the technical checks involved.
Both certifications use the same five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. Cyber Essentials uses a verified self-assessment. Cyber Essentials Plus adds independent technical testing to check that the controls are implemented.
Plus is not a full penetration test or a broader set of security controls. Certification addresses the scheme’s baseline protection against common cyber threats; it does not guarantee that an organisation cannot be compromised. See IASME’s Cyber Essentials guidance for the scheme’s explanation.

Discuss Cyber Essentials Plus readiness with your current certification position and the deadline you need to work towards.
Plan the assessment
Confirm scope: identify the organisation, locations, users, devices and services covered, including remote working and relevant cloud services.
Check prerequisites: confirm the Cyber Essentials certification position and applicable requirements before scheduling Plus testing.
Prepare the controls: compare the environment with the current scheme requirements and address readiness gaps.
Coordinate technical verification: agree the required access, evidence, technical contacts and assessment arrangements.
Resolve findings: address any issues through the scheme’s assessment process. Certification depends on meeting its requirements.
What to bring to a readiness discussion
An up-to-date inventory of devices, operating systems, software and relevant cloud services.
Details of remote working, device management and who administers the environment.
Your current Cyber Essentials certificate or assessment status and the scope it covers.
Known gaps, planned changes, supplier dependencies and the business deadline.
A contact who can coordinate access and remediation with the IT team or service provider.
What affects the work and schedule?
Scope, device diversity, management arrangements, access readiness and unresolved gaps affect preparation and coordination. Agree the assessment arrangements and any remediation dependencies before booking. A readiness review does not guarantee a certification result.
Keep certification and wider assurance distinct
Cyber Essentials Plus provides assurance about the scheme controls in the assessed scope. A separate penetration test may be appropriate when you need to investigate application logic, specific attack paths or other risks beyond those checks. Backups, staff training and wider monitoring can support security, but should not be presented as extra Plus control categories.
Further guidance
Use the current IASME questions and requirements when preparing. Our Cyber Essentials overview provides background; current scheme documents govern assessment requirements.
Discuss Cyber Essentials Plus readiness
Discuss Cyber Essentials Plus readiness. Tell us the organisation and environment to be covered, your certification status and any timing constraints. We can discuss the appropriate scope and next steps.
For More Information Please Contact Us
ACCREDITATIONS
