Skip to content
Assessment explained

Cyber Essentials audit and assessment: CE versus CE+.

Cyber Essentials and Cyber Essentials Plus assess the same five technical control areas, but the assurance process is different. Cyber Essentials uses a verified self-assessment; Cyber Essentials Plus adds independent technical testing.

Reviewed September 2026Current requirements: v3.3

What happens in Cyber Essentials?

You complete the scheme questionnaire against the required scope and five technical controls. The submission is independently assessed. NCSC currently describes Cyber Essentials as the baseline certification route, priced by organisation size.

What changes for Cyber Essentials Plus?

Cyber Essentials Plus uses the same control framework but adds a technical audit to verify that the controls are working in practice. IASME states that a valid Cyber Essentials verified self-assessment is a prerequisite for Cyber Essentials Plus.

What should you prepare before assessment?

  • Define the organisation and technology that are in scope.
  • Confirm internet gateways, user devices, servers and relevant cloud services.
  • Review account privileges and multi-factor authentication where required.
  • Check supported software and security update management.
  • Collect evidence before the assessor asks for it.

Current security-update rule

Under the current Cyber Essentials Requirements for IT Infrastructure v3.3, in-scope software must be supported and relevant vulnerability fixes must be applied within 14 days where the vendor classifies the issue as critical/high risk, the CVSS v3 base score is 7 or above, or severity information is unavailable.