Skip to main content

Framework · UK baseline cyber hygiene

Cyber Essentials Plus, and what the assessment covers

The UK government-backed scheme for baseline cyber hygiene, verified by a hands-on technical assessment rather than a self-assessment questionnaire.

Cyber Essentials Plus is mandatory for many UK government and NHS supplier contracts and frequently required by defence primes across Tier 2 and Tier 3 supply chains.

WHERE THIS FRAMEWORK FITS

Where this framework fits at Goldline

Goldline does not deliver Cyber Essentials Plus as a standalone certification service. For organisations approaching this framework, we typically recommend a partner referral to an IASME-licensed Certification Body for the technical assessment, and where appropriate, we deliver the ISO 27001 implementation that gives you a broader information security management system foundation.

For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.

Book the Free Diagnostic

Browse all frameworks

What is Cyber Essentials Plus?

Cyber Essentials Plus is a UK government-backed scheme administered by IASME under National Cyber Security Centre (NCSC) governance. It evaluates an organisation against five technical controls foundational to cyber hygiene. Unlike the self-assessed Cyber Essentials, the Plus level requires independent technical verification by an accredited certifying body. Certification is annual.

What Cyber Essentials Plus covers

Five technical controls, evaluated through documentation review and independent technical audit covering external vulnerability scans, internal authenticated scans, and malware protection testing.

Firewalls

Boundary firewalls and internet gateways configured to block unauthorised network traffic to and from the internal network.

Secure configuration

Devices and software configured to reduce inherent vulnerabilities. Default passwords, unnecessary services, and unused accounts removed.

User access control

User accounts assigned only to authorised individuals. Administrative privileges restricted and tightly managed.

Malware protection

Anti-malware deployed across devices, with signature updates and execution restrictions on untrusted code.

Security update management

Security updates installed within 14 days of release across operating systems, applications, and firmware.

Independent technical audit

Cyber Essentials Plus adds independent technical verification of all five controls by a certifying body.

Why UK organisations adopt Cyber Essentials Plus

Procurement gating across UK central government, NHS, defence, and regulated commercial supply chains has made CE+ a baseline expectation rather than an optional differentiator.

Required for UK central government supplier contracts handling sensitive information under MoD, MoJ, and Cabinet Office expectations.

Mandatory for many NHS supplier contracts under the Data Security and Protection Toolkit.

Frequently required by UK Tier 1 defence primes flowing down to Tier 2 and Tier 3 supply chain organisations.

Strong foundation for ISO 27001 implementation; many CE+ controls map directly to Annex A:2022 requirements.

Cost-effective entry point for first-time security certification with annual renewal cycle.

Recognised across UK public sector, defence, and regulated commercial procurement as baseline cyber hygiene.

Cyber Essentials Plus vs basic CE vs ISO 27001

 Cyber Essentials PlusCyber Essentials (basic)ISO 27001
TypeUK government scheme. IASME-accredited certification.Self-assessed version of the same scheme.International ISMS standard.
ScopeFive technical controls with independent technical audit.Five technical controls. No independent audit.Risk-based with 93 Annex A controls.
CycleAnnual renewal cycle.Annual renewal cycle.Three-year cycle with annual surveillance.
RecognitionRecognised across UK public sector, defence, NHS, and commercial procurement.Recognised but treated as weaker than CE+ in regulated procurement.Globally recognised; deeper scope than CE+.

How the assessment is carried out

Cyber Essentials is a self-assessment questionnaire, signed off by a board-level representative and reviewed by a Certification Body. Cyber Essentials Plus keeps the same five control themes and adds a hands-on technical assessment carried out by an assessor working for an IASME-licensed Certification Body. The assessor tests the estate rather than reading a description of it.

  • A representative sample of end user devices, servers and cloud services inside the declared scope, chosen by the assessor rather than by the organisation.
  • An external vulnerability scan of internet-facing addresses, looking for unpatched or misconfigured services.
  • An authenticated internal scan of the sampled devices, checking patch levels, unsupported software and account configuration.
  • Malware protection tested in practice, including the handling of test files delivered by email and by web download.
  • Multi-factor authentication and account separation checked on cloud services and administrative accounts.

A certificate is valid for twelve months. There is no surveillance cycle: the whole assessment is repeated each year on the estate as it stands then.

Frequently asked

Where to go next

  • Cyber Essentials Plus Readiness

    The preparation work that gets the estate into a state where it passes. The assessment itself is carried out by a Certification Body, not by Goldline.

  • Cyber Essentials

    The self-assessed level, and the precondition for the Plus assessment.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.