Compliance

Cyber Essentials Plus

Cyber Essentials Plus certification

Cyber Essentials Plus is the higher-assurance tier of the Cyber Essentials scheme, covering the same five technical control areas: firewalls and internet gateways, secure configuration, user access control, malware protection, and security update management.

Why Cyber Essentials Plus matters in a Microsoft estate

Cyber Essentials Plus matters because customers, resellers, and procurement teams need evidence that controls are defined, operated, and reviewable. A useful glossary definition should help a reader connect the term to audit preparation, policy work, or repeatable assurance activity.

How Cyber Essentials Plus shows up in practice

It replaces standard Cyber Essentials' self-assessment questionnaire with independent, hands-on technical verification carried out by a certification body assessor. Where standard certification is based on an organisation truthfully answering a set of questions about its own controls, Cyber Essentials Plus involves an assessor actually testing a representative sample of the organisation's devices and systems directly. This includes vulnerability scanning, checks that patches have genuinely been applied rather than merely scheduled, and verification that malware protection is actively running and correctly configured rather than simply installed.

It closes the gap between what an organisation believes about its own security posture and what independent testing actually confirms. This distinction matters commercially as much as technically, since certain sectors, contracts, and cyber insurance underwriters specifically require Cyber Essentials Plus rather than accepting standard certification, treating the independent verification as materially stronger assurance that the claimed controls are genuinely operating in production rather than only on paper. An organisation should confirm precisely which tier a given customer or contract requires before assuming standard certification will satisfy it.

Preparing successfully for Cyber Essentials Plus generally means the underlying technical controls need to already be operating consistently in practice, not merely documented as policy, since an assessor testing live systems will surface any gap between the two. This makes achieving standard Cyber Essentials certification first, then treating Cyber Essentials Plus as validation of controls already genuinely in place, a more reliable route than attempting Plus certification cold. Because the assessment is hands-on and device-specific, Cyber Essentials Plus also needs re-verifying annually alongside the underlying Cyber Essentials certification, since a control landscape confirmed sound a year ago provides no assurance about current patch status or configuration drift that may have accumulated since.

Glossary