Forefront IT Security Services
BlogCompliance
Compliance

A Practical Guide to Cyber Essentials Plus

June 2026Forefront IT Security Services4 min read

Cyber Essentials Plus is now the price of entry for a lot of tenders. Here is what the assessor actually does to your machines, where firms fail first time, and how to walk in already knowing you'll pass.

Somewhere in your sales pipeline is a contract you cannot bid for without it. That is what Cyber Essentials has quietly become, not a nice-to-have badge, but a gate written into public-sector tenders, supply-chain contracts and insurance policies. And more and more, the version buyers point at is the harder one: Cyber Essentials Plus.

Self-assessment versus someone actually checking

The two levels differ in exactly one thing, verification. Cyber Essentials is a self-assessment questionnaire that a certifying body reviews. Cyber Essentials Plus sends an independent assessor to technically test a sample of your devices and confirm the controls you declared are genuinely there. One asks you to describe your security; the other checks the description is true. Plus has to be done within three months of your Cyber Essentials certificate, and it is the one buyers trust, because the assurance is independent, not self-reported.

The five controls (simpler than they sound)

Both levels rest on the same five technical controls. They are unglamorous, and that is precisely the point: the overwhelming majority of real-world attacks simply fail against an organisation that genuinely has all five in place.

1. Firewalls

Every internet-connected device sits behind a correctly configured firewall, home-worker routers and cloud instances included. Default admin passwords changed, inbound services justified rather than left open by default.

2. Secure configuration

Devices and software hardened from their out-of-the-box state: unnecessary accounts and software removed, default passwords changed, auto-run of untrusted content switched off.

3. User access control

Each account gets only the access that user needs. Administrative privilege is tightly held and used only for admin tasks, and multi-factor authentication guards your cloud services.

4. Malware protection

Devices protected against malware, anti-malware, application allow-listing or sandboxing, kept current and actually switched on.

5. Security update management

Software licensed, supported and patched. High-risk and critical updates applied within 14 days of release; anything unsupported removed from scope or from the estate entirely.

Where firms fail, and it's the same short list

First-time failures are boringly predictable, and every one is avoidable with a fortnight's notice:

  • Unsupported software still in use an end-of-life Windows build, an old server, an unsupported browser. Automatic fail.
  • High-severity patches outside the 14-day window usually on the apps people forget: PDF readers, Java runtimes, browser plugins.
  • Local admin rights handed out far too freely, so ordinary accounts can install software and switch off protections.
  • Missing MFA on cloud services and administrative accounts.
  • Scope confusion forgetting that home-worker devices and cloud services are in scope too, not just the office.

What the Plus assessment does to your machines

The assessor tests a representative sample rather than every device. In practice, the hands-on checks are:

  1. Confirm patching is genuinely current on the sampled devices, third-party applications included.
  2. Confirm malware protection is present, enabled and up to date.
  3. Test that the system blocks a set of known-malicious files and email attachments as it should.
  4. Check that browsers and email clients don't auto-run malicious content.
  5. Confirm MFA is enforced on cloud services.

Sample size scales with how many and how varied your in-scope devices are, enough to give confidence, without anyone touching every endpoint you own.

How to walk in already knowing you'll pass

None of this is hard. It just has to happen before the assessment, not during it:

  1. Run a gap analysis first. Test yourself against the five controls exactly as the assessor will, and find the failures on your own terms.
  2. Remediate honestly. Retire unsupported systems, close the patch gaps, pull back local admin, turn on MFA everywhere it belongs.
  3. Nail the scope. Agree precisely which devices, users, cloud services and locations are in and out, before you start.
  4. Re-check, then book. Confirm the fixes hold, then schedule the assessment with no surprises left in it.

Almost every first-time failure we see would have been caught by a proper gap analysis a fortnight earlier.

Treated as a checkbox, it is a badge for the tender pack. Treated properly, the five controls are a genuine baseline that measurably cuts your exposure to the attacks that hit almost everyone, which is exactly why buyers, insurers and government keep asking for it.

Security Front Door

Find the right level of security for your business.

One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.

Forefront
UK Penetration Testing & Red Team Operations
Loading...