Framework · UK baseline cyber hygiene
Cyber Essentials Plus, and what the assessment covers
The UK government-backed scheme for baseline cyber hygiene, verified by a hands-on technical assessment rather than a self-assessment questionnaire.
Cyber Essentials Plus is mandatory for many UK government and NHS supplier contracts and frequently required by defence primes across Tier 2 and Tier 3 supply chains.
WHERE THIS FRAMEWORK FITS
Where this framework fits at Goldline
Goldline does not deliver Cyber Essentials Plus as a standalone certification service. For organisations approaching this framework, we typically recommend a partner referral to an IASME-licensed Certification Body for the technical assessment, and where appropriate, we deliver the ISO 27001 implementation that gives you a broader information security management system foundation.
For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.
Book the Free DiagnosticWhat is Cyber Essentials Plus?
Cyber Essentials Plus is a UK government-backed scheme administered by IASME under National Cyber Security Centre (NCSC) governance. It evaluates an organisation against five technical controls foundational to cyber hygiene. Unlike the self-assessed Cyber Essentials, the Plus level requires independent technical verification by an accredited certifying body. Certification is annual.
What Cyber Essentials Plus covers
Five technical controls, evaluated through documentation review and independent technical audit covering external vulnerability scans, internal authenticated scans, and malware protection testing.
Firewalls
Boundary firewalls and internet gateways configured to block unauthorised network traffic to and from the internal network.
Secure configuration
Devices and software configured to reduce inherent vulnerabilities. Default passwords, unnecessary services, and unused accounts removed.
User access control
User accounts assigned only to authorised individuals. Administrative privileges restricted and tightly managed.
Malware protection
Anti-malware deployed across devices, with signature updates and execution restrictions on untrusted code.
Security update management
Security updates installed within 14 days of release across operating systems, applications, and firmware.
Independent technical audit
Cyber Essentials Plus adds independent technical verification of all five controls by a certifying body.
Why UK organisations adopt Cyber Essentials Plus
Procurement gating across UK central government, NHS, defence, and regulated commercial supply chains has made CE+ a baseline expectation rather than an optional differentiator.
Required for UK central government supplier contracts handling sensitive information under MoD, MoJ, and Cabinet Office expectations.
Mandatory for many NHS supplier contracts under the Data Security and Protection Toolkit.
Frequently required by UK Tier 1 defence primes flowing down to Tier 2 and Tier 3 supply chain organisations.
Strong foundation for ISO 27001 implementation; many CE+ controls map directly to Annex A:2022 requirements.
Cost-effective entry point for first-time security certification with annual renewal cycle.
Recognised across UK public sector, defence, and regulated commercial procurement as baseline cyber hygiene.
Cyber Essentials Plus vs basic CE vs ISO 27001
| Cyber Essentials Plus | Cyber Essentials (basic) | ISO 27001 | |
|---|---|---|---|
| Type | UK government scheme. IASME-accredited certification. | Self-assessed version of the same scheme. | International ISMS standard. |
| Scope | Five technical controls with independent technical audit. | Five technical controls. No independent audit. | Risk-based with 93 Annex A controls. |
| Cycle | Annual renewal cycle. | Annual renewal cycle. | Three-year cycle with annual surveillance. |
| Recognition | Recognised across UK public sector, defence, NHS, and commercial procurement. | Recognised but treated as weaker than CE+ in regulated procurement. | Globally recognised; deeper scope than CE+. |
How the assessment is carried out
Cyber Essentials is a self-assessment questionnaire, signed off by a board-level representative and reviewed by a Certification Body. Cyber Essentials Plus keeps the same five control themes and adds a hands-on technical assessment carried out by an assessor working for an IASME-licensed Certification Body. The assessor tests the estate rather than reading a description of it.
- A representative sample of end user devices, servers and cloud services inside the declared scope, chosen by the assessor rather than by the organisation.
- An external vulnerability scan of internet-facing addresses, looking for unpatched or misconfigured services.
- An authenticated internal scan of the sampled devices, checking patch levels, unsupported software and account configuration.
- Malware protection tested in practice, including the handling of test files delivered by email and by web download.
- Multi-factor authentication and account separation checked on cloud services and administrative accounts.
A certificate is valid for twelve months. There is no surveillance cycle: the whole assessment is repeated each year on the estate as it stands then.
Frequently asked
Where to go next
- Cyber Essentials Plus Readiness
The preparation work that gets the estate into a state where it passes. The assessment itself is carried out by a Certification Body, not by Goldline.
- Cyber Essentials
The self-assessed level, and the precondition for the Plus assessment.
