New Blog
Working Towards Cyber Essentials Plus for a Higher Level of Assurance
Cyber Essentials Plus offers organisations a higher level of assurance by independently testing whether key cyber security controls are working as intended.
In this blog, we explore what the assessment involves, how to prepare effectively, and the practical steps organisations can take to improve their chances of achieving certification.


The Cyber Essentials verified self-assessment provides a baseline standard for improving an organisation's cyber security.
Cyber Essentials Plus goes a step further in providing assurance by combining the technical requirements of Cyber Essentials with an assessor led audit of an organisation's security controls.
This should help to provide confidence that security measures are working as intended, and that the control requirements of Cyber Essentials are met by the organisation.
What Is Cyber Essentials Plus?
Cyber Essentials Plus covers the same core technical control schemes as the Cyber Essentials verified self-assessment:
Firewalls
Secure Configuration
Security Update Management
User Access Control
Malware Protection
A subset of the controls covered in the self-assessment questionnaire are audited by an assessor through the different test-cases carried out for the Cyber Essentials Plus assessment.
By providing an independent and impartial technical assessment of the organisation's application of the Cyber Essentials control requirements, Cyber Essentials Plus should provide a greater level of assurance that an organisation meets the baseline standard of Cyber Essentials compliance.
This can help organisations to:
Demonstrate that the organisation takes cyber security seriously
Provide assurance to customers and partners
Operate in sectors where compliance is required
Preparing for Cyber Essentials Plus
For organisations working towards Cyber Essentials Plus, preparation for the assessment should begin before submission and completion of the verified self-assessment.
For larger organisations with multiple teams, sites and varied technology, providing accurate answers to the self-assessment may involve and require input from multiple stakeholders within the organisation.
The scope between the Cyber Essentials self-assessment and CE+ assessments must be the same and it is important that the answers provided for the self-assessment questionnaire are accurate and complete, to reflect the networks and systems within the organisation scope.
If any significant differences from the declared scope are identified by the assessor when scoping or conducting a Cyber Essentials Plus test, then the assessment will not be able to proceed, and it will be back to step 1 requiring a new submission of the verified self-assessment.
Use the self-assessment to find and fix gaps:
As you work through the self-assessment with any relevant stakeholders within the organisation, take time to verify the answers rather than relying on assumptions or referring to information provided on previous years’ assessments (if renewing certification).
If you cannot confidently evidence answers provided to the question-set then this is worth investigating.
Consideration should be given to the following for example:
Do you understand the scope and can identify and provide a summary of all system that fall within the boundary of scope (end user devices, mobile devices, servers, virtual machines, network devices etc)
Do you have a complete and accurate asset inventory of all in scope-devices
Do you have up to date and accurate information for Operating System versions and update/patching level for all systems.
Are administrator privileges limited to those who require them and separate from accounts used for day-to-day work
Are you confident that security updates/fixes are applied for all high severity vulnerabilities within 14 days for the devices in scope of assessment.
Do all the cloud services in use within the organisation have MFA enabled for all accounts (administrators and standard users).
Other considerations and preparation steps for Cyber Essentials Plus could include:
Removal of unused/unneeded software, limiting devices only to the required software for the device user.
Tracking any non-standard device builds or software in use.
Identifying and removing old/stale user account profiles.
Where possible, carrying out your own vulnerability scans of devices in scope, to identify any gaps in security update management.
Verifying that MFA is enabled for all accounts for all cloud services in use.
Review of firewall configuration and all firewall enabled services.
Reviewing these points early in the process should provide an opportunity to remediate issues before the Cyber Essentials Plus assessment begins.
Conclusion
Building preparation into your Cyber Essentials journey from the outset can make the move to Cyber Essentials Plus much smoother. By putting the right controls in place early and maintaining them over time, organisations can approach the assessment with greater confidence and a stronger overall security foundation.
If you’re looking to strengthen your cyber security and work towards Cyber Essentials or Cyber Essentials Plus, WorkNest Secure can support you through the process.
Share your challenge with us and we’ll help you find the right level of support for your business.












