Cyber Essentials Plus checklist

Cyber Essentials Plus Checklist for 2026

Ronan Grobler

Head of GRC

Linkedin

TL;DR: Cyber Essentials Plus checklist

  • Cyber Essentials Plus is the advanced level of Cyber Essentials, requiring an independent technical assessment.
  • Both certifications assess the same five security controls: firewalls, secure configuration, user access control, malware protection, and security update management.
  • Organizations must first achieve Cyber Essentials certification before completing the Cyber Essentials Plus assessment within three months.
  • Preparation is essential, as assessors verify that your security controls are correctly implemented and operating effectively.
  • Scytale’s AI GRC platform streamlines Cyber Essentials Plus with automated evidence collection, continuous monitoring, and expert GRC support.

Cyber Essentials Plus is one of the most widely recognized cybersecurity certifications for organizations looking to demonstrate that their security controls have been independently verified. By providing a higher level of assurance than a self-assessment alone, the certification helps organizations strengthen customer trust, meet compliance requirements, and better defend against modern cyberattacks.

In this guide, we’ll cover what Cyber Essentials Plus is, its requirements, the certification process, and the key steps to achieving certification successfully. We’ll also explain how to prepare for the assessment and avoid common pitfalls that could delay certification.

Understanding Cyber Essentials Plus

Cyber Essentials consists of two certification levels, both backed by the UK’s National Cyber Security Centre (NCSC). While both certifications help organizations establish a strong cybersecurity foundation, Cyber Essentials Plus requires an independent technical assessment to verify that your security controls are operating as intended. Here’s how the two certifications compare:

Cyber Essentials

Cyber Essentials is a self-assessment certification that enables organizations to evaluate their cybersecurity posture against five core technical controls. It provides a practical framework for mitigating the most common cyber threats while strengthening cybersecurity risk management across the organization. 

Cyber Essentials Plus

Cyber Essentials Plus builds upon the Cyber Essentials certification by introducing an independent technical assessment conducted by a certified external assessor. Rather than relying solely on a self-assessment questionnaire, organizations undergo a series of technical tests to verify that the required security controls are properly implemented across their environment.

This assessment typically includes vulnerability scanning, device configuration reviews, malware protection testing, and other technical verification procedures. As a result, Cyber Essentials Plus provides customers, partners, and stakeholders with independent assurance that your organization has successfully implemented the required cybersecurity controls.

Which certification is right for your organization?

The appropriate certification depends on the level of assurance your organization needs to demonstrate to customers, partners, regulators, and other stakeholders. For many organizations, Cyber Essentials provides a strong foundation by demonstrating that fundamental cybersecurity controls are in place. However, organizations working with enterprise customers, government contracts, or handling sensitive data often benefit from Cyber Essentials Plus, which offers independent validation that these controls have been effectively implemented.

As cybersecurity expectations continue to rise, independent validation is increasingly viewed as a competitive advantage rather than simply a compliance exercise. By independently verifying that your cybersecurity controls are operating effectively, Cyber Essentials Plus gives customers, partners, and other stakeholders greater confidence in your organization’s security posture.

Cyber Essentials Plus requirements

Cyber Essentials Plus assesses the same five technical controls as Cyber Essentials but verifies them through an independent technical assessment rather than a self-assessment questionnaire. To achieve certification, organizations must demonstrate that these controls have been correctly implemented and are operating effectively across their IT environment. Here are the five technical controls required for Cyber Essentials Plus: 

Firewalls and internet gateways

Organizations must use firewalls or equivalent network devices to protect systems from unauthorized access and control inbound and outbound network traffic. Firewall configurations should follow security best practices by blocking unnecessary connections, restricting administrative access, and monitoring network activity.

Secure configuration

Systems, devices, and applications should be securely configured to minimize unnecessary security risks. This includes removing unused software and services, changing default passwords, disabling unnecessary features, and implementing secure configuration baselines across the organization.

User access control

Access to systems and data should be limited to authorized users based on business need. Organizations should enforce strong authentication, regularly review user permissions, promptly remove unnecessary access, and implement multi-factor authentication where appropriate.

Malware protection

Organizations must implement effective measures to detect, prevent, and respond to malware. This typically includes deploying anti-malware or endpoint protection software, preventing unauthorized applications from running, and ensuring security tools remain up to date.

Security update management

Organizations must keep operating systems, applications, and firmware up to date by installing security patches promptly. Unsupported software should be removed or replaced, and automatic updates should be enabled wherever possible to reduce exposure to known vulnerabilities.

Streamline GRC workflows with seamless automation.

Scytale G2 badge

Key components of the Cyber Essentials Plus checklist

Obtaining Cyber Essentials Plus involves more than completing a technical assessment. Organizations must first achieve Cyber Essentials certification before undergoing an independent technical verification. The certification process consists of three key stages.

1. Complete the Cyber Essentials self-assessment

The first step is to complete the Cyber Essentials self-assessment questionnaire, which evaluates whether your organization has implemented the five required technical controls. The information provided also determines the scope of the Cyber Essentials Plus assessment, including the number of user devices and servers that will be sampled. While user devices undergo technical testing, servers are typically subject to vulnerability scanning rather than a full assessment.

2. Undergo the Cyber Essentials Plus technical assessment

After obtaining Cyber Essentials certification, organizations have three months to complete the Cyber Essentials Plus assessment with an accredited certification body. During this stage, independent assessors verify that the required security controls have been implemented correctly through technical testing, including reviews of device configurations, firewalls, access controls, malware protection, and vulnerability management. Unlike the self-assessment, this process relies on objective evidence rather than organizational attestation.

3. Remediate any findings

Once the assessment is complete, the certification body will provide the results and identify any areas that require remediation before certification can be awarded. Organizations must address these findings within the permitted timeframe by resolving the identified issues and demonstrating compliance with the certification requirements. Failure to do so typically requires submitting a new application and paying the certification fee again.

Cyber Essentials Plus certification stages 

StagePurposeOutcome
1. Self-assessmentComplete the Cyber Essentials questionnaire.Defines the assessment scope.
2. Technical assessmentIndependent testing by an accredited certification body.Verifies the five security controls.
3. RemediationResolve any identified gaps.Achieve Cyber Essentials Plus certification.

Cyber Essentials Plus technical controls 

Cyber Essentials Plus evaluates five core technical controls that help organizations protect their IT environments against common cyber threats. Each control is independently assessed by an accredited certification body to verify it meets the certification standard. The following sections explain each control and the key practices organizations should review before the assessment. 

Firewall and internet gateways

Firewalls and internet gateways protect your organization’s network by controlling traffic between internal systems and external networks. To meet Cyber Essentials Plus requirements, organizations should replace default administrative credentials, block unauthenticated inbound connections by default, remove unnecessary firewall rules, and ensure firewall activity is monitored. Organizations should also secure remote access, protect devices used on untrusted networks with host-based firewalls, and separate guest networks from business-critical systems where appropriate.

Secure configuration

Secure configuration minimizes security risks by ensuring devices, operating systems, and applications are configured according to security best practices. Organizations should remove unnecessary software and services, replace default passwords, disable automatic execution of removable media, implement multi-factor authentication for internet-facing services where appropriate, and promptly disable accounts when employees leave the organization. Maintaining standardized configuration baselines and password policies further helps reduce the organization’s attack surface.

User access control

User access control ensures employees have access only to the systems and information required to perform their roles. Organizations should apply the principle of least privilege, enforce strong authentication methods, limit repeated failed login attempts, and regularly review user permissions to remove unnecessary access. Effective access controls reduce the risk of unauthorized access and help protect sensitive business data.

Malware protection

Malware protection safeguards systems against malicious software that could compromise data, disrupt operations, or provide unauthorized access to attackers. Organizations should deploy and maintain anti-malware or endpoint protection software alongside other essential cybersecurity tools to detect, prevent, and respond to malicious activity. These measures help detect, prevent, and contain malware before it can impact the organization’s environment.

Security update management

Security update management ensures software and operating systems remain protected against known vulnerabilities by applying updates promptly. Organizations should use supported and licensed software, enable automatic updates wherever possible, remove unsupported applications, and install critical security patches within the required timeframes. A consistent patch management process significantly reduces the likelihood of attackers exploiting known security weaknesses.

The Cyber Essentials Plus scope

Defining the scope of your Cyber Essentials Plus assessment is a critical step in the certification process. The scope determines which systems, devices, software, and services will be evaluated and is established using the information submitted in the initial Cyber Essentials self-assessment questionnaire.

While organizations can limit the scope to a specific network or business function where appropriate, best practice is to include the entire organization whenever possible. A broader scope provides more comprehensive assurance that security controls have been consistently implemented across the business and reduces the risk of unmanaged systems introducing security vulnerabilities.

Once the scope has been defined, every in-scope device, application, and system must comply with the Cyber Essentials requirements. Maintaining a clearly defined scope also supports continuous compliance by ensuring security controls are consistently applied across both on-premises and cloud environments. 

Streamline Cyber Essentials Plus certification with Scytale

Scytale simplifies Cyber Essentials Plus by combining AI-powered compliance automation with expert GRC guidance, helping organizations prepare for certification faster and with greater confidence. From automated evidence collection and continuous control monitoring to policy management and remediation tracking, Scytale centralizes every stage of the certification process in a single compliance hub, reducing manual effort and keeping your organization audit-ready.

Through native integrations, Scytale continuously monitors your security controls, identifies compliance gaps, and provides actionable recommendations before they become audit findings. Combined with hands-on support from experienced GRC experts, the platform helps organizations maintain an audit-ready security and compliance program.

FAQs about Cyber Essentials Plus checklist

  1. What’s the difference between Cyber Essentials and Cyber Essentials Plus?

    The main difference between Cyber Essentials and Cyber Essentials Plus is the assessment method. Cyber Essentials is achieved through a self-assessment questionnaire, while Cyber Essentials Plus requires an independent technical assessment conducted by an accredited certification body. Both certifications evaluate the same five security controls, but Cyber Essentials Plus provides a higher level of assurance by verifying that those controls have been implemented and are operating effectively.

  2. What does Cyber Essentials Plus cover?

    Cyber Essentials Plus covers five core technical security controls designed to protect organizations against common cyber threats. These controls include firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management. Leading AI GRC platforms like Scytale help organizations prepare for the assessment by automating evidence collection, continuously monitoring security controls, and identifying compliance gaps before the audit.

  3. How much does Cyber Essentials Plus cost?

    The cost of Cyber Essentials Plus varies depending on the size and complexity of your organization. While Cyber Essentials has fixed pricing for the self-assessment certification, Cyber Essentials Plus includes an independent technical assessment, meaning certification bodies set their own fees. Most organizations can expect costs to range from several hundred to several thousand pounds, depending on factors such as the number of users, devices, and locations included in scope.

  4. How long does Cyber Essentials Plus certification last?

    Cyber Essentials Plus certification is valid for 12 months from the date it is awarded. To maintain certification, organizations must successfully complete the assessment each year and continue demonstrating that their security controls meet the required standard. Maintaining compliance throughout the year also makes the annual renewal process significantly more straightforward.

  5. What happens if my organization fails the Cyber Essentials Plus audit?

    If your organization fails the Cyber Essentials Plus assessment, you’ll need to remediate the identified issues before certification can be awarded. The certification body will provide details of the findings and, in many cases, allow a defined remediation period to address them before a retest is performed. Scytale’s AI GRC platform streamlines remediation by centralizing compliance tasks, tracking corrective actions, and providing expert GRC guidance to help organizations address findings and prepare for a successful reassessment.

Ronan Grobler

Ronan Grobler

As Head of GRC at Scytale, Ronan Grobler leads a team of experts helping companies meet top security and privacy standards like ISO 27001, ISO 9001, ISO 42001, SOC 1, SOC 2, GDPR, HIPAA, CCPA, and DORA. With over four years of experience in governance, risk, and compliance, Ronan has supported businesses of all sizes - from fast-growing... Read more