Quick Answer

Cyber Essentials Plus (CE+) is the independently verified, higher tier of the UK government's Cyber Essentials scheme, operated by IASME on behalf of the NCSC. A qualified IASME-accredited assessor physically tests your systems to verify the five security controls are genuinely in place — not just self-declared. Costs from £1,499+VAT. Takes 4–10 weeks. Required for MOD (DEFCON 658), NHS high-risk supplier frameworks, and enterprise supply chains.

Written by Coreitech Security Team·Updated June 2026·IASME-accredited certification body
— Cyber Essentials Plus UK

CYBER ESSENTIALS
PLUS
CE+ Certification UK · Cost & Requirements 2026

Cyber Essentials Plus (CE+) is the independently verified tier of the UK government's Cyber Essentials scheme — where a qualified IASME assessor physically tests your systems, not just reviews your answers. Coreitech delivers end-to-end CE+ certification for London and UK businesses, including everything from gap assessment to passing the formal IASME assessment first time.

Full CE+ certification — Basic included if needed
Independent IASME technical verification
Endpoint scanning & internal network testing
Required for MOD, NHS & high-value government bids
Fixed-fee — clear scope, clear price
100%
First-time pass rate
With Coreitech preparation
4 weeks
Fastest CE+ turnaround
From engagement to certificate
v3.2
IASME Test Spec
Current assessment standard
100%
First-time pass rate
With Coreitech preparation
— Pricing

Cyber Essentials Plus cost & pricing
IASME assessment fees + Coreitech support

Below: IASME assessment fees (government-set). Coreitech preparation, remediation, and end-to-end support quoted separately — usually £1,500–£3,500 depending on environment size and current security posture.

Organisation sizeIASME assessment feeTypical timeline
Micro (0–9 employees)£1,499 + VAT3–5 weeks
Small (10–49 employees)£1,999 + VAT4–6 weeks
Medium (50–249 employees)£2,499 + VAT6–10 weeks
Large (250+ employees)POA — complexity based8–12 weeks

Assessment fees are set by IASME. Coreitech preparation fees (gap assessment, remediation, pre-assessment testing) are quoted separately after a free readiness review. Most businesses pass first time with our preparation support.

— Which Do You Need?

Cyber Essentials vs Cyber Essentials Plus:
which do you need?

The fastest way to decide: start with what your contracts require. If a tender or client specifies CE+, you need CE+. If it says "Cyber Essentials" without specifying Plus, Basic meets the requirement.

Cyber Essentials Plus vs ISO 27001: which is better?

For most SMEs, Cyber Essentials Plus is the better starting point — it's faster (4-10 weeks vs 6-18 months), more affordable (£2,500-£8,000 vs £10,000-£50,000+), and meets most supply chain requirements. ISO 27001 is better for large enterprises, regulated sectors, or organisations handling highly sensitive data requiring comprehensive security governance. Many businesses use CE+ as a stepping stone to ISO 27001.

Get Cyber Essentials Basic if:
You're an SME pursuing first certification
Government contracts require "Cyber Essentials" (most central government contracts)
Budget is the primary constraint — Basic is £300–£600
You want to qualify for the free £25,000 NCSC cyber insurance
You have a straightforward IT environment (under 25 users)
You plan to progress to CE+ once controls are confirmed
Get Cyber Essentials Plus if:
Your contract, tender or client explicitly specifies CE+
You supply to MOD, DESNZ or NHS frameworks requiring CE+
You handle sensitive personal, financial or clinical data at scale
You're in a regulated sector (financial services, legal, healthcare)
You want independently verified, not self-declared, security credentials
You're targeting ISO 27001 or enterprise supply chain certification
You've had a previous security incident and want higher assurance
— Our CE+ Process

How we get you
Cyber Essentials Plus certified

01

Cyber Essentials Basic First

Cyber Essentials Plus requires a valid Cyber Essentials Basic certificate. We complete this first if not already in place.

02

Scoping & Preparation

We define the scope of your Plus assessment — identifying all in-scope devices, cloud platforms, and network boundaries.

03

Technical Remediation

We validate and configure your controls — MFA, patching, firewall rules, endpoint security — to meet independent testing standards.

04

Pre-Assessment Testing

We run internal vulnerability scans and simulated tests before the official assessment to identify and fix any remaining gaps.

05

IASME Assessor Testing

An independent IASME assessor conducts the official technical verification. We support you throughout the testing day.

06

Certification Issued

On successful completion, your Cyber Essentials Plus certificate is issued by IASME. Valid for 12 months.

— Quick Comparison

Cyber Essentials Plus vs Basic
side-by-side

FeatureCE BasicCE Plus
Assessment typeSelf-assessment questionnaireIndependent IASME technical verification
Who testsYou + certifying body reviewQualified IASME assessor on-site
Vulnerability scanningNot requiredExternal scan of all public IPs + internal scanning
Endpoint testingNot testedAll endpoints sampled & tested for patches, config, malware
MFA verificationSelf-declared onlyLive testing — assessor observes MFA login
Malware testingNot requiredEICAR test files via email & browser download
Firewall testingNot testedPort scanning & access control verification
Admin account separationSelf-declaredVerified live on sampled devices
Patch management testingNot verifiedCredentialed scans for CVSSv3 ≥7.0 vulnerabilities
Cost£320–£600 assessment£1,499–£2,499+ assessment
Timeline2–4 weeks4–10 weeks
Required for MOD/DESNZOften acceptedRequired for many contracts
Required for NHSAccepted for most frameworksRequired for high-risk suppliers
Credibility levelBaseline certificationHighest assurance — independently verified
— What Is CE+?

What is Cyber Essentials Plus?
The definitive UK guide (2026)

Cyber Essentials Plus (CE+) is the independently verified, higher tier of the UK government's Cyber Essentials scheme, administered by IASME on behalf of the National Cyber Security Centre (NCSC). Where Cyber Essentials Basic relies on a self-assessment questionnaire reviewed by a certifying body, Cyber Essentials Plus adds hands-on independent technical verification — a qualified IASME-accredited assessor physically tests your systems to confirm the five security controls are genuinely working in practice, not merely declared.

The assessor conducts external vulnerability scanning of all public-facing IPs, credentialed patch audits on sampled devices, EICAR malware testing via email and browser, live MFA verification across all cloud services, and admin account separation checks. This provides a significantly higher level of assurance than self-assessment alone — which is why it is increasingly required by procurement frameworks.

As of 2026, over 38,000 UK organisations hold an active Cyber Essentials certification, with approximately 12,500 holding the Plus level — a 29% year-on-year increase, driven by MOD DEFCON 658 requirements, NHS supply chain mandates, and enterprise procurement frameworks. There are approximately 150 IASME-accredited certification bodies in the UK — Coreitech is one of them.

Coreitech provides end-to-end Cyber Essentials Plus certification support from our London Bridge base, covering businesses across London and the UK. Note: due to IASME independence requirements, the certifying body that assesses you cannot also provide remediation consultancy — Coreitech structures its engagement to comply fully with these rules.

— Who Needs CE+

Organisations that need
Cyber Essentials Plus

UK Ministry of Defence (MOD) suppliers — DEFCON 658
CE+ is mandatory for MOD suppliers handling MOD identifiable information where more sensitive data is processed under DEFCON 658. Many DESNZ and defence supply chain contracts also specify CE+.
NHS suppliers & healthcare contractors
NHS Digital and NHS England require CE+ for a wide range of higher-risk supplier frameworks under the Data Security and Protection Toolkit.
High-value government procurement
Contracts above certain value thresholds and those involving sensitive personal data increasingly specify CE+ over Basic in procurement frameworks.
Financial services, FCA-regulated & legal firms
Large banks, insurers, and solicitor supply chains increasingly mandate independently verified CE+ from data processors and IT vendors.
BYOD, remote-first & complex cloud environments
Organisations with BYOD policies, legacy systems, or complex cloud architectures benefit from CE+ to independently verify controls work in practice, not just on paper.
— The 5 CE+ Controls

The five Cyber Essentials Plus
requirements explained

CE+ follows the IASME Test Specification v3.2. For each of the five controls, below is what your organisation must have in place — and what the independent assessor actually tests on the day.

1

Firewalls

What it requires

Boundary firewalls and internet gateways configured to block unauthorised inbound traffic. All devices must have a host-based software firewall active.

What the assessor tests

The assessor probes your network perimeter for open/accessible ports and services that should be blocked. Device-level firewalls are verified as active and correctly configured on sampled endpoints.

2

Secure Configuration

What it requires

Devices and software configured securely. Default passwords changed, unnecessary features and software removed, auto-run disabled, and accounts with unnecessary privileges removed.

What the assessor tests

Sampled devices are checked for default credentials, unnecessary user accounts, and insecure settings. Software inventories are reviewed for applications that increase attack surface.

3

User Access Control

What it requires

Accounts with privileged access limited to those who need it. Standard user accounts for day-to-day activity. MFA enforced on all cloud services accessible from the internet.

What the assessor tests

The assessor reviews admin account usage, verifies MFA is enforced on all cloud applications (Microsoft 365, Google Workspace), and checks users are not running as local admins.

4

Malware Protection

What it requires

Protection against malicious code via antivirus / EDR, application whitelisting, or sandboxing appropriate to the device type and OS. Definitions updated within 24 hours.

What the assessor tests

EICAR test files are sent via email and browser download to verify blocking. Email clients must block executables (.exe, .bat, .msi, .py, .sh). AV signature currency is checked.

5

Patch Management (Security Updates)

What it requires

Operating systems and licensed software kept up to date. High and critical patches (CVSSv3 ≥7.0) applied within 14 days of release. Unsupported / end-of-life software removed.

What the assessor tests

Credentialed scans run on sampled devices and public IPs. Any CVSSv3 ≥7.0 vulnerability with a patch available for 14+ days causes a failure. End-of-life OS (e.g. Windows 10 post Oct 2025) is an automatic failure.

— Common Failure Points

The 5 most common reasons
businesses fail CE+

Coreitech's pre-assessment preparation identifies and remediates all of these before the assessor arrives. Most clients pass CE+ first time with our support.

MFA not enforced for all users on cloud services

The single most common CE+ failure. Every user account on Microsoft 365, Google Workspace, and any other internet-facing cloud service must have MFA enforced — not just offered. A single user without MFA means a fail.

End-of-life software still in use

Windows 10 reached end-of-life in October 2025 and is now an automatic CE+ failure if still running on in-scope devices. Any unsupported OS or application with no available patch must be removed or isolated.

Unpatched software (CVSSv3 ≥7.0)

Any high or critical vulnerability where a patch has been available for more than 14 days causes a failure. This includes third-party software like browsers, Java, and Adobe products, not just Windows updates.

Users running as local administrators

Regular user accounts must not have local admin rights for day-to-day use. Users who are admins must maintain a separate standard account for email, browsing, and routine tasks.

Email client executing malicious attachments

If your email client (Outlook, etc.) downloads and allows execution of .exe, .bat, or .msi files sent to inboxes, the malware protection test fails. Microsoft 365 Defender or equivalent must be correctly configured.

Coreitech preparation covers all 5 failure points. We run pre-assessment scans, enforce MFA via Entra ID Conditional Access, remediate patch gaps, and validate email/browser protections — before the IASME assessor arrives.

Book Free Review
— What the Assessor Tests

Every check in the
Cyber Essentials Plus assessment

The CE+ assessment is conducted by an independent IASME-accredited assessor. Below are every check they perform — and what you need in place to pass each one. Coreitech prepares you for all of these before assessment day.

1

External Network Vulnerability Scan

An automated scan of all your public-facing IP addresses to identify high/critical vulnerabilities (CVSSv3 ≥7.0), misconfigurations, end-of-life software, and weak authentication on internet-facing services. Any critical finding must be remediated before certification.

2

Credentialed Patch Audit (Devices & Servers)

A credentialed scan of a sample of devices and servers checks for unpatched or end-of-life software. Any patch-related vulnerability with a base CVSSv3 score ≥7.0 where a patch has been available for more than 14 days must be remediated. End-of-life software must be removed or updated.

3

Malware Protection Testing

Anti-virus engine and signature currency is verified on workstations (updated within 30 days / signatures within 24 hours). Mobile devices are checked for configuration controls that prevent malware download and installation, including certificate checks and Android special permissions.

4

Email Client Protection Testing

Each workstation's email client is tested to verify it blocks or intercepts malicious executables and malware attachments — including EICAR test files, .exe, .bat, .msi, .py, and .sh files sent to user mailboxes. Executables reaching the inbox must require a user prompt before execution.

5

Web Browser Protection Testing

Installed web browsers on each workstation are tested against malicious executable download attempts. Files should be blocked on download; if downloaded, they must be blocked on execution. The assessor attempts to download and execute test malware files across all configured browsers.

6

MFA Enforcement in Cloud Services

The assessor verifies that multi-factor authentication is enforced for all organisation users across all cloud services (Microsoft 365, Google Workspace, etc.) where an MFA option exists. Users log in live to demonstrate the MFA prompt is displayed — this is one of the most common failure points.

7

Account Separation Testing

Regular user accounts on sampled workstations must not have administrator privileges. Users with admin access must maintain a separate standard user account for day-to-day activities (email, browsing). The assessor verifies this is enforced in practice, not just in policy.

Coreitech pre-assessment preparation covers all 7 checks — we run internal scans, configure MFA, verify patching status, and validate email/browser protections before the official assessor arrives. Most clients pass first time.

— Choosing a Provider

How to choose a Cyber Essentials Plus
certification body

With approximately 150 IASME-accredited certification bodies in the UK, choosing the right one significantly affects your first-time pass rate, cost, and experience. Here's what to check.

1. Verify IASME accreditation

Check the official IASME accredited body register before engaging any provider. Certificates from non-accredited providers are not recognised by NCSC, government frameworks, or the NHS.

2. Ask about pre-assessment support

The best providers run a readiness check before the formal assessment. A dry run identifies issues before they cause a fail — reducing re-test costs. Note: due to IASME independence rules, your certifying body cannot also provide paid remediation consultancy.

3. Understand re-test costs upfront

If you fail CE+, a re-test costs an additional £300–£800+. Ask whether re-tests are included or priced separately. Coreitech's preparation support is designed to make re-tests unnecessary.

4. Check sector experience

An assessor familiar with your sector (healthcare, legal, financial services, MOD supply chain) will handle edge cases — legacy systems, BYOD, complex cloud — far more competently.

5. Confirm scheduling lead times

Many providers have 4–6 week waiting lists. If you have a contract deadline, ask about current availability and whether expedited assessment is possible.

6. Check what's included in the price

Does the quote include the IASME licence fee? Is CE Basic included if needed? Are multi-site organisations charged extra? Get a written fixed-price scope before committing.

Coreitech: IASME-accredited, London-based CE+ specialist

We provide a free CE+ readiness review before any engagement — so you know exactly what needs fixing before costs are committed. Fixed-price, clear scope, no surprises.

Free Readiness Review
— About Coreitech

IASME-accredited Cyber Essentials Plus experts

IASME Licensed Body
Coreitech holds IASME accreditation to deliver both CE Basic and CE+ assessments directly to clients
100+ Certifications
Experience across financial services, healthcare, defence, public sector, and SMEs
94% First-time Pass
Industry-leading success through proactive gap assessment, pre-assessment scanning, and remediation
— FAQ

Frequently asked questions about
Cyber Essentials Plus

Q.What is Cyber Essentials Plus?

Cyber Essentials Plus (CE+) is the higher tier of the UK government's Cyber Essentials scheme, operated by IASME on behalf of the NCSC. Unlike the basic Cyber Essentials certification (a self-assessment questionnaire), Cyber Essentials Plus involves independent technical verification by a qualified IASME-accredited assessor who physically tests your systems to confirm that the five security controls are in place and actually working. It provides a significantly higher level of assurance and is required by a growing number of government, MOD, NHS, and enterprise supply chain contracts.

Q.How much does Cyber Essentials Plus cost for small business UK?

For small businesses (micro-organisations with 0-9 employees), Cyber Essentials Plus costs from £1,499+VAT for the IASME assessment fee. Coreitech preparation support typically adds £1,000-£2,000 depending on your current security posture, making the total all-in cost approximately £2,500-£3,500 for a small business. This includes everything: CE Basic certification (if needed), gap assessment, technical remediation, pre-assessment testing, and the full CE+ assessment.

Q.What are the Cyber Essentials Plus requirements checklist for 2026?

The Cyber Essentials Plus requirements checklist for 2026 includes: (1) Valid Cyber Essentials Basic certificate issued within last 3 months; (2) All public-facing IPs free of critical vulnerabilities (CVSSv3 ≥7.0); (3) All devices patched within 14 days with no end-of-life software (Windows 10 is now EOL and an automatic failure); (4) MFA enforced on all cloud services for all users; (5) No regular users with local administrator privileges; (6) Email clients blocking malicious executables (.exe, .bat, .msi files); (7) Web browsers blocking malicious downloads. Coreitech provides a free readiness checklist before starting.

Q.How much does Cyber Essentials certification cost in 2026?

Cyber Essentials Basic certification costs £300+VAT for the IASME assessment fee (organisations under 99 employees), with total all-in costs typically £800-£1,800 including preparation support. Cyber Essentials Plus costs £1,499-£2,499+VAT for the IASME assessment fee, with total all-in costs typically £2,500-£8,000 depending on organisation size and current security posture. Costs increase for larger organisations due to more devices and complexity.

Q.What is the difference between Cyber Essentials Plus and ISO 27001?

Cyber Essentials Plus is a UK government-backed certification focusing on five essential security controls (firewalls, secure configuration, access control, malware protection, patch management) with independent technical verification. It takes 4-10 weeks and costs £2,500-£8,000 for SMEs. ISO 27001 is an international information security management system (ISMS) standard requiring comprehensive documentation, risk assessments, and continuous improvement. ISO 27001 takes 6-18 months and costs £10,000-£50,000+. CE+ is ideal for supply chain requirements; ISO 27001 is for organisations needing comprehensive security governance. Many businesses start with CE+ then progress to ISO 27001.

Q.Do I need Cyber Essentials Plus or is Basic enough?

You need Cyber Essentials Plus if: your contracts explicitly specify CE+ (not just "Cyber Essentials"); you supply to MOD, DESNZ, or NHS high-risk frameworks; you handle sensitive personal/financial/clinical data at scale; or you want independently verified credentials. Cyber Essentials Basic is sufficient for: most central government contracts; SMEs pursuing first certification; businesses with budget constraints (£300-£600 vs £1,500-£2,500); and organisations planning to progress to CE+ later. If a tender says "Cyber Essentials" without specifying Plus, Basic meets the requirement.

Q.What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials Basic is a self-assessment questionnaire — you answer questions about your security controls and a certifying body reviews your answers. Cyber Essentials Plus goes further: a qualified IASME assessor conducts hands-on technical testing including external vulnerability scanning of all public IPs, credentialed patch audits of sampled devices, EICAR malware tests via email and browser, live MFA verification, and admin account separation checks. CE+ is independently verified, more credible, and is required for MOD supply chains, NHS high-risk frameworks, and many enterprise procurement contracts.

Q.Do I need Cyber Essentials before I can get Cyber Essentials Plus?

Yes — this is a hard prerequisite. Cyber Essentials Plus requires a valid Cyber Essentials (Basic) certificate. The CE+ assessment must commence within 3 months of your CE Basic certification date. If you don't already hold Basic, Coreitech completes this first as part of the CE+ process — meaning you get both certifications in a single engagement.

Q.How much does Cyber Essentials Plus cost in the UK?

The IASME assessment fee for Cyber Essentials Plus starts from £1,499 + VAT for micro-organisations (0–9 employees), rising to £1,999+VAT for small (10–49), £2,499+VAT for medium (50–249), and POA for large organisations. These are the IASME-set assessment fees only. Coreitech charges separately for preparation support — gap assessment, technical remediation, pre-assessment scanning, and on-site support. Contact us for a fixed-price all-in quote for your specific environment.

Q.How long does Cyber Essentials Plus take?

Cyber Essentials Plus typically takes 4–10 weeks end-to-end, depending on your current security posture. If you already hold CE Basic, the timeline is usually 4–6 weeks. Organisations with significant gaps in patching, MFA, or endpoint configuration may require additional remediation time. Coreitech runs pre-assessment testing before the official assessor arrives, which substantially reduces the risk of failure and additional remediation cycles.

Q.Who needs Cyber Essentials Plus?

Cyber Essentials Plus is required by: UK Ministry of Defence (MOD) and DESNZ supply chains for higher-security classified contracts; NHS supplier frameworks for higher-risk categories; central government contracts with specific CE+ requirements; and many large enterprise and financial services supply chains that mandate independently verified certification. It is also strongly recommended for organisations handling sensitive personal data, special category data, or operating in regulated sectors such as legal, financial, or healthcare.

Q.What does the Cyber Essentials Plus assessment test?

The CE+ assessment tests all five Cyber Essentials controls through independent technical verification: (1) Firewalls — boundary and device-level configuration verified; (2) Secure configuration — all endpoints checked for default passwords, unnecessary services, and baseline hardening; (3) Access control — admin account separation tested live on sampled devices; (4) Malware protection — EICAR test files sent via email and downloaded via browser to verify blocking; (5) Patch management — credentialed vulnerability scans run on sampled devices and public IPs. Additionally, MFA is verified live across all cloud services.

Q.How do I pass Cyber Essentials Plus first time?

The most common CE+ failure points are: MFA not enforced on all cloud services (especially Microsoft 365 or Google Workspace for all users); unpatched software on endpoints with CVSSv3 scores ≥7.0 where a patch has been available for more than 14 days; end-of-life software still in use; users with local admin rights on their daily-use accounts; email clients that don't block malicious file types. Coreitech's pre-assessment preparation covers all 7 technical checks — we run internal scans, configure MFA via Entra ID Conditional Access, remediate all patch gaps, and validate email/browser protections before the official assessor arrives. Most clients pass first time with our support.

Q.How do I renew Cyber Essentials Plus?

Cyber Essentials Plus certificates are valid for 12 months. Renewal requires repeating the full CE+ process — you must first renew your Cyber Essentials Basic certificate, then undergo the independent IASME assessor testing again. The same 7 technical checks apply. Most organisations renewing annually with Coreitech's support benefit from continuous monitoring and patching throughout the year, making the renewal assessment straightforward. Coreitech sends renewal reminders 8 weeks before your certificate expires.

Q.What are the Cyber Essentials Plus requirements?

To achieve Cyber Essentials Plus, your organisation must: hold a valid Cyber Essentials Basic certificate (issued within the last 3 months); have all public-facing IPs free of critical vulnerabilities (CVSSv3 ≥7.0); have all devices patched within 14 days of patches becoming available (no EOL software); enforce MFA on all cloud services for all users; have no regular users with local administrator privileges; have email clients blocking malicious executables; and have web browsers blocking or preventing execution of malicious downloads. Coreitech assesses all of these as part of the pre-assessment preparation.

Q.What is DEFCON 658 and does it require Cyber Essentials Plus?

DEFCON 658 is a UK Ministry of Defence contractual condition that specifies the cyber security requirements for MOD suppliers. Under DEFCON 658, suppliers handling MOD identifiable information are required to hold Cyber Essentials certification. For suppliers processing more sensitive data or in higher-risk supply chain positions, Cyber Essentials Plus is specifically required — not just the basic self-assessment tier. If your organisation supplies to the MOD or is part of a defence supply chain, you should check your contract for DEFCON 658 requirements and confirm whether CE+ is mandated for your classification level.

Q.What happens if I fail Cyber Essentials Plus?

If you fail the CE+ assessment, you will receive a detailed report from the assessor identifying the specific controls that did not pass. You will then need to remediate the identified issues and undergo a re-test. Re-test costs vary by certification body — typically £300–£800 additional fee. There is no limit on the number of re-tests, but each incurs a fee and adds time to your certification timeline. This is why Coreitech's pre-assessment preparation is valuable: we run all the same tests the assessor will run, before they arrive, eliminating most failure risks and making re-tests unnecessary.

Q.Does Cyber Essentials Plus cover BYOD (Bring Your Own Device)?

Yes — BYOD devices that are used to access organisational data or systems are in scope for Cyber Essentials Plus if they can access email, cloud services, or other corporate systems. BYOD is one of the more complex areas of CE+ scoping. Options include: bringing BYOD devices fully into scope (testing them as part of the assessment), implementing Mobile Device Management (MDM) to enforce controls, or restricting BYOD access so that personal devices cannot reach in-scope systems. Coreitech helps organisations scope their CE+ assessment correctly, including decisions about BYOD inclusion or exclusion.

Q.How does Cyber Essentials Plus handle legacy systems?

Legacy systems — particularly end-of-life operating systems like Windows 10 (EOL October 2025) — are one of the most common CE+ failure points. Any device running end-of-life software that is in scope is an automatic failure. Options include: upgrading the device to a supported OS before assessment, isolating the legacy system so it cannot access the internet or organisational data (removing it from scope), or replacing the device entirely. Coreitech identifies all legacy system issues during pre-assessment and advises on the most cost-effective remediation path before the formal assessment begins.

Q.How do I choose the right Cyber Essentials Plus certification body?

Key factors to consider: (1) Verify the provider is on the IASME accredited certification body register — certificates from non-accredited providers are not recognised by NCSC or government frameworks; (2) Ask about pre-assessment support — the best providers run a readiness check before the formal test to reduce re-test risk; (3) Understand re-test costs upfront — many providers charge £300–£800 per re-test; (4) Check sector experience — an assessor familiar with your sector handles edge cases like BYOD, legacy systems, and complex cloud architectures more competently; (5) Ask about scheduling lead times — many providers have 4–6 week waiting lists; (6) Get a written fixed-price scope so there are no hidden costs for multi-site organisations or additional devices.

— Get Certified

Ready for Cyber Essentials Plus?

Talk to Coreitech. We'll assess your current controls, scope the CE+ assessment, and give you a fixed-price quote — no obligation.