Straight answer first
We assess Cyber Essentials Plus from late October 2026. We are an appointed IASME Certification Body for Cyber Essentials and IASME Cyber Assurance today, and Plus is being added to that scope for late October. Audit slots are open to book now. We are telling you that at the top of the page rather than the bottom, because you are probably here under time pressure.
What follows is what we know from assessing Cyber Essentials and from preparing organisations for Plus audits. If it is useful, take it and use it with whichever assessor you choose.
What Plus adds
Cyber Essentials is a verified self-assessment: you answer the questionnaire, an assessor reviews it, and on a pass the certificate is issued. Cyber Essentials Plus keeps all of that and adds an independent, hands-on technical audit of a sample of your devices and systems, carried out by an assessor.
The difference matters because a self-assessment tests your answers and a Plus audit tests your estate. Organisations that pass Cyber Essentials comfortably fail Plus regularly, and almost always on the same handful of things.
You need current Cyber Essentials first. Plus is not an alternative route, it is an addition.
Cyber Essentials is the prerequisite, and we certify it today. Plus assessment starts late October 2026.
What the assessor actually does
- Authenticated vulnerability scan of a sample of devices, looking for missing high and critical patches.
- Malware protection test, sending known-malicious sample files to see whether email filtering and endpoint protection genuinely stop them.
- Browser download test, checking that a malicious file cannot simply be downloaded and run.
- Account separation check, confirming everyday accounts do not hold local administrator rights on the machines sampled.
- Multi-factor authentication check on cloud services, tested rather than asserted.
The sample is chosen to represent your estate, not chosen by you. That is the point of it.
What commonly fails
Patch currency on one sampled device. Policy says fourteen days; one laptop has been off the network for three weeks. This is the single most common failure and it is entirely preventable with a check the week before.
A browser or plugin nobody tracks. The operating system is current, but a browser on a handful of machines is two versions behind.
Administrator rights that were granted temporarily. Someone needed admin for an install in March and it was never removed.
Email filtering that is more permissive than anyone thinks. Rules added over years to stop a supplier's invoices being quarantined, now letting more through than intended.
Timing
Allow two to three weeks more than plain Cyber Essentials. The audit has to be scheduled into an assessor's diary, it takes time to run, and if something fails you need remediation time before a re-check. If your insurer or tender has given you a fortnight and specified Plus, tell them now rather than later: insurers routinely grant a subjectivity period when they can see you are in progress with a named assessor, and grant nothing at all if you go quiet.
Check you actually need it
Read the requirement before you buy. A surprising share of organisations buy Plus because they assumed a contract needed it when the wording says Cyber Essentials, and Plus costs materially more and takes weeks longer. If the document says Cyber Essentials, that is what it means.
One correction worth making while you are here: Defence Cyber Certification Level 1 does not require Cyber Essentials Plus. Def Stan 05-138 Issue 4 applies Cyber Essentials at all four DCC levels and Plus at Levels 2 and 3 only. If you have been quoted for Plus on the basis of a Level 1 requirement, ask the provider to point at the control.
Our dates, plainly
We assess Cyber Essentials Plus from late October 2026, and audit slots are open to book now. That is a date rather than an aspiration, which is why this page has one. If your deadline falls before then, say so and we will tell you straight away whether we can help or whether you need a different assessor.
Cyber Essentials itself we certify today, as an appointed IASME Certification Body. Since Plus cannot begin without a valid Cyber Essentials certificate less than three months old, doing that first is the right order regardless of who runs your audit.
What to do between now and your audit
The waiting is not dead time, and three things decide whether a Plus audit passes first time. All three can be done now.
Get the Cyber Essentials certificate. It is the prerequisite, and its age matters: under three months old when the Plus audit starts.
Fix what the audit actually tests. Unsupported operating systems and applications, patches outstanding beyond fourteen days, everyday accounts holding local administrator rights, and multi-factor authentication missing from a cloud service. These are what fail people, and none of them are a surprise on the day.
Settle the sample and the scope. Which devices, which cloud services, and who works from home on their own hardware. Scope arguments on audit day are the other reason a Plus assessment overruns.
Who carries out the audit matters here
A Cyber Essentials Plus audit is a technical exercise rather than a paperwork one. The assessor scans a sample of your devices, tries to get a malicious file past your email and browser controls, and checks that the controls work rather than that they are documented.
Ours is carried out by a CREST-registered penetration tester who holds OSCP, OSWE, CRT and CISSP. That is a different proposition from an audit run by a compliance platform, and for a hands-on technical test it is the difference that shows.
Would you pass a Plus audit today?
These are the things an assessor tests by hand, rather than takes your word for. Tick what would survive it.