
Cyber Essentials Plus is now the price of entry for a lot of tenders. Here is what the assessor actually does to your machines, where firms fail first time, and how to walk in already knowing you'll pass.
Somewhere in your sales pipeline is a contract you cannot bid for without it. That is what Cyber Essentials has quietly become, not a nice-to-have badge, but a gate written into public-sector tenders, supply-chain contracts and insurance policies. And more and more, the version buyers point at is the harder one: Cyber Essentials Plus.
The two levels differ in exactly one thing, verification. Cyber Essentials is a self-assessment questionnaire that a certifying body reviews. Cyber Essentials Plus sends an independent assessor to technically test a sample of your devices and confirm the controls you declared are genuinely there. One asks you to describe your security; the other checks the description is true. Plus has to be done within three months of your Cyber Essentials certificate, and it is the one buyers trust, because the assurance is independent, not self-reported.
Both levels rest on the same five technical controls. They are unglamorous, and that is precisely the point: the overwhelming majority of real-world attacks simply fail against an organisation that genuinely has all five in place.
Every internet-connected device sits behind a correctly configured firewall, home-worker routers and cloud instances included. Default admin passwords changed, inbound services justified rather than left open by default.
Devices and software hardened from their out-of-the-box state: unnecessary accounts and software removed, default passwords changed, auto-run of untrusted content switched off.
Each account gets only the access that user needs. Administrative privilege is tightly held and used only for admin tasks, and multi-factor authentication guards your cloud services.
Devices protected against malware, anti-malware, application allow-listing or sandboxing, kept current and actually switched on.
Software licensed, supported and patched. High-risk and critical updates applied within 14 days of release; anything unsupported removed from scope or from the estate entirely.
First-time failures are boringly predictable, and every one is avoidable with a fortnight's notice:
The assessor tests a representative sample rather than every device. In practice, the hands-on checks are:
Sample size scales with how many and how varied your in-scope devices are, enough to give confidence, without anyone touching every endpoint you own.
None of this is hard. It just has to happen before the assessment, not during it:
Almost every first-time failure we see would have been caught by a proper gap analysis a fortnight earlier.
Treated as a checkbox, it is a badge for the tender pack. Treated properly, the five controls are a genuine baseline that measurably cuts your exposure to the attacks that hit almost everyone, which is exactly why buyers, insurers and government keep asking for it.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.