Cyber Essentials & Cyber Essentials Plus Certification

Achieve Cyber Essentials or Cyber Essentials Plus certification with Claranet's licensed IASME assessors, including a hands-on technical audit and vulnerability assessment for Cyber Essentials Plus. Expert guidance at every step, from self-assessment to final certification.

Get your Cyber Essentials quote

Challenges we solve

Cyber Essentials certification protects your organisation and opens doors — but navigating the process alone can be daunting.

Vulnerable to common cyber threats

Without basic security controls in place, your organisation is exposed to the most common and preventable cyber attacks that target businesses of every size.

Compliance and contract requirements

Many government contracts and supply chains now require Cyber Essentials certification. Without it, you may be locked out of opportunities and unable to demonstrate due diligence.

Uncertainty about your security posture

You know you need to improve your cyber security, but you are not sure whether your firewalls, patching and access controls meet the required standard.

Navigating the certification process

The self-assessment questionnaire covers over 70 questions across five control themes. Getting expert guidance ensures you pass first time and avoid costly delays.

What is Cyber Essentials?

Cyber Essentials is a UK Government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and delivered nationally by IASME, the scheme's official delivery partner. It sets out a baseline of security controls - covering firewalls, secure configuration, access control, malware protection and patch management - designed to protect organisations against the most common, opportunistic cyber-attacks.

Certification is increasingly a commercial requirement, not just a security best practice: many UK government contracts, public-sector tenders and enterprise supply chains now require suppliers to hold a current Cyber Essentials certificate before they can bid or trade.

Claranet Cyber Security is a licensed IASME Certification Body, authorised to certify organisations of any size against both Cyber Essentials (verified self-assessment) and Cyber Essentials Plus (independent technical audit). Our qualified assessors guide you through every step - from completing the self-assessment questionnaire to achieving certification.

For organisations that need a deeper level of assurance, Cyber Essentials Plus adds a technical audit including external and internal vulnerability scanning, MFA validation, and physical testing of end-user devices and infrastructure against the five key control themes.

Key Benefits

  • UK government-backed certification scheme
  • Protects against the most common cyber threats
  • Required for many government and supply chain contracts
  • Expert assessor guidance through the entire process
  • Two certification levels: self-assessment and Plus
  • Demonstrates your commitment to cyber security

Which certification do you need?

Cyber Essentials and Cyber Essentials Plus test the same five security controls, but at different levels of assurance. Most organisations start with Cyber Essentials; some are required - by a contract, a client, or their own risk profile - to go further with Cyber Essentials Plus.

 Cyber EssentialsCyber Essentials Plus
Assurance levelVerified self-assessmentIndependent technical audit
How it worksYou complete a self-assessment questionnaire; your assessor pre-checks and formally scores itA hands-on technical audit, including vulnerability scanning and device testing, verifies the controls are actually in place
Typical forMost SMEs, first-time applicants, lower-risk contractsOrganisations handling sensitive data, government/regulated-sector suppliers, or where a client mandates the higher level
What's checkedYour answers against the five control themesExternal and internal vulnerability scanning, MFA validation, admin account separation, anti-malware testing, MDM review (where applicable)
DeliveryRemote, questionnaire-basedRemote or on-site

Not sure which one applies to you? Talk to our Cyber Essentials specialist and we'll help you work out the right level before you start. If you have 250 or more employees, a different route into certification applies - see our guide to the Cyber Essentials Pathways for larger organisations.

Why Claranet?

IASMELicensed Certification Body
25+Years of cyber security expertise
5Core control themes assessed
2Certification levels available

The five control themes

Cyber Essentials certification is built around five fundamental security controls that every organisation should implement.

Firewalls

Boundary firewalls and internet gateways configured to protect your network

Secure Configuration

Devices and software configured to reduce vulnerabilities

Access Control

User accounts managed with appropriate access privileges

Malware Protection

Anti-malware defences for browsers, email and applications

Patch Management

Software and devices kept up to date with latest patches

Service Components

Comprehensive certification services delivered by qualified IASME assessors.

Verified self-assessment (CE)

Complete a 70+ question self-assessment questionnaire covering the five control themes. Your Claranet assessor pre-checks responses, provides guidance and formally scores the submission.

Technical audit (CE Plus)

Hands-on technical audit including external and internal vulnerability scanning, MFA validation, admin account separation checks, anti-malware testing and MDM review where applicable.

Assessor-guided process

A dedicated Claranet assessor supports you throughout — from account setup and questionnaire completion through marking, remediation guidance and formal certification.

Remediation support

If non-compliance is found during pre-check or technical audit, you receive a detailed report with guidance on what needs to change. Up to 30 days remediation window is provided.

Remote or on-site delivery

Cyber Essentials Plus technical audits can be delivered remotely or on-site, including physical assessment of end-user devices, servers, mobile phones and cloud services.

Certificate management

Your Claranet assessor manages your certificates through Blockmark, the IASME digital certificate management system, ensuring your certification is properly registered and maintained.

Cyber Essentials as part of a wider security strategy

Cyber Essentials sets a strong security baseline, but it's a starting point rather than a complete security programme. Many of our Cyber Essentials clients go on to strengthen their posture further with penetration testing, continuous vulnerability scanning, managed detection and response, or a wider compliance programme such as ISO 27001 - particularly where they handle sensitive data, operate in a regulated sector, or are building towards more demanding client and government requirements.

Explore our full range of cybersecurity services to see how Cyber Essentials fits alongside the rest of your security programme.

Accreditations & partnerships

Certified expertise you can trust.

iasme-logo-1.png
Crest logos in a white circle
NCSC certificação
iso 27001 outlined
Cyber Essentials Plus certificação

Ready to get certified?

Talk to a licensed IASME assessor about whether Cyber Essentials or Cyber Essentials Plus is right for your organisation, and what's involved in getting there.

Talk to a Cyber Essentials specialist

Or call us on 0330 390 0507

Frequently asked questions

  • Cyber Essentials is a verified self-assessment — you answer a questionnaire and your assessor checks and scores it. Cyber Essentials Plus adds an independent technical audit, including vulnerability scanning and device testing, to verify the same controls are genuinely in place.

  • It's not mandatory for every UK organisation, but it is required for many government contracts involving sensitive or personal data, and it's increasingly requested by supply chains and enterprise clients as a condition of doing business.

  • Cyber Essentials typically takes a few days to a few weeks from starting the self-assessment questionnaire to certification, depending on how quickly any required changes can be made and how promptly your team can respond to assessor feedback.

    Cyber Essentials Plus takes longer, because it adds an independent technical audit on top of the verified self-assessment. From April 2026, the scheme also requires the Cyber Essentials self-assessment to be fully approved before Cyber Essentials Plus testing can begin — so build this into your timeline if you're working towards a contract deadline.

    If gaps are found during the pre-check or technical audit, you'll receive a detailed remediation report, with up to 30 days to put fixes in place before re-assessment.

  • Certification is valid for 12 months, and renewal isn't a formality - you'll need to demonstrate that your controls are still in place, and the scheme's requirements are periodically updated, so processes that passed last year aren't guaranteed to pass again without review. From 27 April 2026, updated requirements apply to all new and renewing applications - including mandatory MFA on all cloud services (with automatic failure if MFA is available but not enabled) and a stricter 14-day window to apply critical and high-severity security updates. If you already hold a valid certificate, the update applies from your next renewal. Our assessors can help you prepare ahead of renewal, including a gap analysis against the current requirements and support with vulnerability scanning to evidence your patching processes. 

    Read our full breakdown of the April 2026 scheme changes for a detailed look at what's new and how to prepare or see our shorter guide to avoiding the most common Cyber Essentials renewal mistakes this year for a practical rundown.

  • Cyber Essentials Plus includes external and internal vulnerability scanning as part of its technical audit. Standard Cyber Essentials doesn't formally require scanning, but from April 2026 the scheme's stricter 14-day patching requirement makes regular vulnerability scanning practically necessary to evidence compliance.

  • It depends on what's being asked of you contractually and how sensitive your data is. If a client, government contract or regulator specifies Cyber Essentials Plus, you'll need the technical audit; otherwise, standard Cyber Essentials is often the right starting point. Our assessors can help you confirm which applies to you.