traibcert whatsapp icon
Updated for April 2026 · v3.3

Cyber Essentials Plus
Certification

Prove your defences work — not just that they exist. An independent technical audit of your systems, conducted by an IASME-accredited assessor, confirming the five core controls are genuinely in place.

IASME Accredited
Crown & Tick Mark
Free Cyber Insurance Included

Two Levels. Same Controls.
Different Assurance.

Both certifications cover the same five technical controls. The difference is how compliance is verified — and the level of trust it signals.

🔒
Foundation

Cyber Essentials

  • Verified self-assessment questionnaire
  • Your declared answers are reviewed
  • Confirms controls are documented
  • No prerequisite required
🛡️
Advanced · Recommended

Cyber Essentials Plus

  • Independent hands-on technical audit
  • Your actual systems are tested
  • Confirms controls are working
  • Requires valid CE certificate (<3 months)

Why Organisations Get Certified

01

Win Contracts

Public-sector tenders involving personal data have required Cyber Essentials since 2014. The MOD extended this in 2016. An increasing number of private-sector supply chains now expect it.

02

Reduce Measurable Risk

82% of medium and large UK businesses experienced a cyber incident in the last 12 months. Certified organisations see a measurable reduction in successful attacks and insurance claims.

03

Free Cyber Insurance

UK organisations with turnover under £20 million receive automatic cyber liability insurance through IASME — including 24/7 incident response with technical, legal, and crisis support.

04

Demonstrate Due Diligence

An independently verified baseline of security controls is evidence that your organisation acted responsibly — critical when dealing with regulators, clients, or breach investigations.

05

Operational Resilience

The five controls directly address the most common attack vectors. Getting them right means fewer disruptions, lower recovery costs, and less time fighting fires.

06

Competitive Differentiation

The Crown & Tick badge on your website and proposals signals trust instantly. In competitive bids, it can be the deciding factor between you and an uncertified competitor.

Five Controls. Tested for Real.

Every Cyber Essentials Plus audit validates these controls through practical testing — not paperwork.

01

Firewalls & Internet Gateways

Boundary devices correctly configured to control inbound and outbound traffic.

02

Secure Configuration

Devices and software configured to reduce their attack surface. Defaults removed.

03

User Access Control

Admin privileges limited to those who need them. Standard accounts for daily work.

04

Malware Protection

Anti-malware active and current. Tested against malicious email and browser downloads.

05

Patch Management

Critical patches applied within 14 days. The control organisations fail most often.

What Changed in
April 2026

From 27 April 2026, all new assessments use Requirements for IT Infrastructure v3.3 (codenamed "Danzell"). The five controls are unchanged, but verification is stricter. Our assessors are trained and ready.

MFA Is Now Mandatory Auto-Fail

If any cloud service offers MFA and you have not enabled it for all users, you will automatically fail. No exceptions.

Cloud Services Cannot Be Excluded

The standard now formally defines cloud services. All must be declared and assessed — they can no longer be scoped out.

Self-Assessment Answers Are Locked

You can no longer amend your Cyber Essentials answers based on the outcome of the Plus audit. Answers must be accurate before testing begins.

Patching Failures Trigger Second Sample Revocation Risk

If the first device sample fails on patches, a second sample is scanned. Further failures mean a Plus fail — and may revoke your basic certificate.

Clear Pricing. No Surprises.

Full technical audit, assessor report, and certificate issuance included. Final price confirmed before you commit.

Micro
0 – 9 employees
£1,499
ex. VAT
Get Quote
Medium
50 – 249 employees
£2,499
ex. VAT
Get Quote
Large
250+ employees
£2,999
ex. VAT
Get Quote

Choose Your Level

Standard

Included
  • Full technical audit
  • Detailed findings report
  • 30-day remediation window
  • One free re-scan

Extra Help

+ £1,200 ex. VAT
  • Everything in Standard
  • Dedicated pre-audit preparation call
  • Ongoing guidance throughout
  • Multiple free re-scans

Fast Track

+ £800 ex. VAT
  • First audit within 1 week
  • Priority assessor scheduling
  • Dedicated focus throughout
  • Combine with any support level

Enquiry to Certificate in Four Steps

1

Scope & Quote

Tell us about your organisation. We confirm scope, check CE status, and send a fixed-price quote.

2

Schedule

Accept the quote and we book the remote technical audit at a time that suits your team.

3

Audit & Report

Our assessor runs the full test suite. You receive a detailed report. 30 days to remediate if needed.

4

Certificate Issued

On success, your certificate is issued within five working days. Publicly registered on the IASME portal.

Frequently Asked

Both cover the same five technical controls. Cyber Essentials is a verified self-assessment — you answer questions and an assessor reviews your answers. Plus adds a hands-on technical audit where an assessor tests your actual systems, providing a higher level of assurance.

Twelve months. We contact you before expiry to arrange renewal. Certificates must be renewed annually to remain on the IASME certified organisations list.

You receive a detailed report explaining what failed and why. You then have 30 days to fix the issues and request a re-scan (included with Standard). If the second attempt does not pass, a new assessment purchase is required.

Yes. Any employee-owned device that accesses company data or connects to your network is in scope. You must demonstrate these devices run supported operating systems and are patched to the current standard.

No. ISO 27001 is a broader information security management system. Cyber Essentials Plus focuses on five specific technical controls and may be a contractual requirement for UK Government work. Many organisations hold both — they are complementary.

The main changes in v3.3 are mandatory MFA on all cloud services that offer it (automatic fail if not enabled), tighter scoping rules, locked self-assessment answers, and stricter patch management verification with dual-sample testing.

Standard audits are typically scheduled within two to three weeks. With Fast Track, the first audit is booked within one week. Reports are delivered within five working days of a successful audit.

Yes. We assess organisations globally. The audit is conducted remotely.

Prove Your Defences Work

Get a personalised quote for Cyber Essentials Plus — or talk to our team
about preparing for the April 2026 changes.