Skip to content

Compliance

Cyber Essentials Plus
Readiness Testing

Component tests from $4,200, one fixed quote for your scope, free retest included. See all pricing →

Get a Fixed Quote

Three fields. A senior tester reads it and replies within one business day.

Prefer the full scoping questionnaire? 
OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need cyber essentials plus readiness testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • A UK public-sector contract, or a prime contractor bidding on one, requires Cyber Essentials Plus from your company before award.
  • A UK customer’s security review lists Cyber Essentials Plus alongside ISO 27001 and SOC 2, and you hold neither yet.
  • You passed the self-assessed Cyber Essentials baseline and now need the audited Plus level within the three-month window.
  • A previous Plus assessment failed on patching or configuration checks and you want the estate verified before paying for another audit.

Comparison

Cyber Essentials vs Cyber Essentials Plus vs ISO 27001

Cyber Essentials

What it is
A self-assessed questionnaire against five technical controls, verified by a certification body
Who audits
Your own answers, reviewed by an assessor
Effort
Days
Who asks for it
UK public-sector suppliers as a minimum
Our role
Guidance on the questionnaire

Cyber Essentials Plus

What it is
The same five controls, verified by an independent hands-on technical audit
Who audits
An IASME-licensed certification body, on your systems
Effort
Weeks, including remediation
Who asks for it
UK government and defense supply chains, UK enterprise customers
Our role
Readiness testing of every control, and a free retest of failed checks

ISO 27001

What it is
A certified management system covering people, process, and technology, audited against Annex A
Who audits
An accredited certification body, over multiple audit stages
Effort
Months
Who asks for it
Enterprise customers worldwide, regulators, and partners
Our role
The penetration testing that evidences Annex A controls

For US companies

Can a US company get Cyber Essentials Plus? Yes, and here is how

Cyber Essentials is a UK National Cyber Security Centre scheme delivered through IASME and its licensed certification bodies, but certification is not restricted to UK organizations. US companies certify because a buyer requires it: UK central government contracts involving personal data or certain ICT services, Ministry of Defence supply-chain obligations that flow down through primes, and UK enterprise customers who treat it as a minimum bar.

The audit itself is performed remotely by the certification body, sampling devices and testing the boundary from the internet. Our readiness testing runs the same checks first, internal and external, on the same sample logic, so the audit finds what we already fixed. We do not issue the certificate, and we say so plainly; we make sure you pass when the certification body does.

What we assess

What your Cyber Essentials+ test covers

We run the independent, hands-on verification Cyber Essentials Plus requires across all five technical controls, formatted so your assessor can act on it directly.

Firewalls & Gateways

Whether your boundary firewalls are configured to block untrusted traffic.

We test for

  • Boundary firewall configuration
  • Default rule review
  • Exposed service testing
  • Remote access controls

Secure Configuration

Whether systems are hardened and free of unnecessary, exploitable defaults.

We test for

  • System hardening
  • Default account and password checks
  • Unnecessary services
  • Auto-run and software controls

Access Control

Whether user accounts and privileges are properly managed and restricted.

We test for

  • User account management
  • Least privilege
  • Administrative account controls
  • Authentication checks

Malware & Patching

Whether malware protection is effective and systems are kept up to date.

We test for

  • Malware protection verification
  • Patch and update status
  • End-of-life software
  • Email and web protection

The controls

The five controls and the current question set

  • Firewalls: boundary and host firewalls configured to block unauthenticated inbound connections, with any open services justified and documented.
  • Secure configuration: default accounts and passwords removed, unnecessary software and services disabled, auto-run disabled, and device locking enforced.
  • Security update management: supported software only, high and critical vulnerabilities patched within 14 days of a fix being released.
  • User access control: unique accounts, least privilege, multi-factor authentication on cloud services, and administrative accounts used only for administration.
  • Malware protection: anti-malware software active and updated on in-scope devices, or application allow-listing where it is used instead.
  • The requirements and question set are revised roughly annually by NCSC and IASME, with each version named and dated. We test against the version your certification body will assess against.

Cost

What it costs

Readiness testing is priced as a fixed scope after we confirm the size of your estate and the device sample set, built from our external and internal testing, with a free retest of any failed checks before your assessment. The certification body fee is separate, set by IASME according to organization size, and paid directly to your certifier.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your compliance test runs through.

  1. 01

    Scope the boundary

    The systems your framework actually covers, and nothing you would pay to test twice.

  2. 02

    Test

    The component penetration tests run to PTES and OWASP standards by senior testers.

  3. 03

    Map to controls

    Every finding tied to the requirement or control it evidences.

  4. 04

    Report for the auditor

    Evidence formatted the way your assessor, examiner, or QSA expects to read it.

  5. 05

    Fix & retest

    A free retest so the audit shows closed findings, not open ones.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    CE baseline

    You first complete the self-assessed Cyber Essentials baseline questionnaire.

  2. 02

    Scope & plan

    We agree the in-scope systems, the device sample set, and a testing timeline.

  3. 03

    Readiness testing

    We run the internal and external testing your certification body will require.

  4. 04

    Submit & certify

    An assessor-ready evidence pack for your licensed body, plus a free retest of any failed checks.

Industries that need thisLaw FirmsAll industries

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type. The findings and outcomes are real.

All case studies →

Free

Retest on every penetration test

150+

Years combined experience

13

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before Cyber Essentials+ testing.

Still have questions? 
01What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment. Cyber Essentials Plus adds an independent, hands-on technical audit of your systems against the same five controls. We perform readiness testing to that standard so you pass, while the certificate itself is issued by your IASME-licensed certification body.

02Do you issue the Cyber Essentials Plus certificate?

No. Only an IASME-licensed certification body can issue the certificate. We run the internal and external technical testing and hand you an assessor-ready evidence pack, so your certification body can complete the audit and certify without surprises.

03How long does the assessment take?

Most assessments are completed within a few days depending on the size of your estate and sample set, followed by an evidence pack and a complimentary retest of any failed checks before your deadline.

04What happens if we fail a control?

We give you a prioritized remediation list and a complimentary retest, so you can close the gaps and certify without starting over.

05How much does Cyber Essentials Plus readiness testing cost?

Readiness testing is priced as a fixed scope after we confirm the size of your estate and the device sample set. It is quoted like our other engagements, with a free retest of any failed checks included. Starting prices for every service are on our pricing page. Note the certification-body fee is separate and paid to your IASME-licensed certifier.

06Can a US company get Cyber Essentials Plus?

Yes. The scheme is UK-run, but certification is open to organizations anywhere, and IASME-licensed certification bodies perform the Plus audit remotely for overseas companies. US companies usually pursue it because a UK central government contract, a Ministry of Defence supply-chain requirement, or a UK enterprise customer requires it. Scope can be limited to the part of the business that serves the UK, and we help you draw that boundary before testing.

07Which version of the Cyber Essentials requirements do you test against?

The version current at the time of your assessment. NCSC and IASME revise the requirements and question set roughly once a year, with each version named and dated, so we confirm the version your certification body will assess against during scoping and test to that. If your baseline self-assessment was submitted under a previous version, we flag anything the newer requirements changed.

Ready to test your defenses?

Talk to our team about what your Cyber Essentials+ compliance requires.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.