What Happens During a Cyber Essentials Plus Assessment?

Introduction

Many organisations achieve Cyber Essentials certification and then wonder whether Cyber Essentials Plus is worth the additional effort.

Cyber Essentials Plus builds upon the standard certification by independently validating that security controls are functioning correctly.

What Will Be Tested?

The assessment typically includes:

Vulnerability Scanning

Devices are scanned for common weaknesses and missing updates.

External Testing

Internet-facing systems are reviewed to identify exposed services and vulnerabilities.

Malware Protection Validation

Security controls are checked to ensure malicious software would be detected and prevented.

User Device Testing

Sample devices are examined to verify compliance with Cyber Essentials requirements.

Preparing for Success

Before assessment, organisations should ensure:

  • Devices are patched
  • MFA is enabled
  • Unsupported software is removed
  • Administrative privileges are reviewed


Preparation significantly increases the likelihood of a successful outcome.

Conclusion

Cyber Essentials Plus provides independent assurance that your security controls are operating effectively and demonstrates a higher level of commitment to cyber security.