Cyber Essentials + Cyber Essentials Plus Bundle
Both certifications in a single engagement. We complete Cyber Essentials first and begin CE Plus preparation during the CE assessor wait period - so CE Plus work is well underway by the time your CE certificate arrives. Cheaper than buying the two separately, faster than running them back-to-back, and one engagement to manage instead of two.
Founding Client pricing - first ten engagements. Prices increase once Northgate Compliance achieves NCSC Assured Cyber Advisor status.
Who this is for
- Defence supply chain businesses facing a tender that requires CE Plus when you don't yet hold CE - the only practical route in.
- NHS suppliers where a DSP Toolkit or framework submission window is months away and both certificates need to be in hand by then.
- Manufacturers responding to a Tier 1 customer audit that mandates CE Plus from new suppliers.
- Professional services firms picking up a new client whose PI insurer or regulator needs both tiers.
- Any UK SMB that knows they'll need CE Plus eventually and wants to avoid paying for two separate engagements.
What's included
Everything in CE Certification
Scope definition, gap assessment, remediation guidance, policy pack, IASME self-assessment completion and submission, your CE certificate. Plus the IASME-bundled Cyber Liability Insurance, free for UK organisations under £20m turnover.
Everything in CE Plus Certification
Full internal pre-audit, device preparation, malicious file test prep, vulnerability scan prep, audit day coordination, IASME assessor audit fee bundled in, your CE Plus certificate.
One scope, used twice
We define your scope at the start of CE and reuse it for CE Plus. No re-scoping mid-engagement.
Parallel scheduling
CE Plus preparation starts during the CE assessor wait period, not after. Saves up to 2 weeks versus running the engagements back-to-back.
One point of contact
One project, one engagement, one set of invoices. Easier for your finance team and decision-makers to track.
What's not included
- Hardware or software purchases. If remediation needs new tools (e.g. a different antivirus, an MDM, MFA on a service that doesn't currently support it), that's your spend.
- Penetration testing. CE and CE Plus are controls audits, not pen tests. Quoted separately if needed.
- Remediating fundamental architecture problems. If your environment can't pass without significant infrastructure change, we'll tell you in the scoping call and quote the additional scope.
- Ongoing maintenance after year 1. Covered by the Annual CE Renewal or Compliance Retainer.
Process
Weeks 1-2
Scope, CE gap assessment and remediation
60-minute scoping call. We map your environment, agree the scope used for both certifications, and produce a written CE gap report. Remediation begins immediately.
Week 3
CE submission, CE Plus prep starts
We complete the IASME CE self-assessment and submit on your authorisation. While the CE assessor reviews, we begin the CE Plus internal pre-audit - this overlap is where the bundle saves time.
Weeks 4-5
CE certificate issued, CE Plus remediation
Your CE certificate is issued. We continue the CE Plus internal pre-audit and fix any gaps that weren't required for CE basic but are required for CE Plus - typically MFA enforcement, internal scan findings, additional device hardening.
Weeks 6-7
CE Plus audit
The IASME assessor performs their audit. Typically 1-2 days for a small business. We coordinate the schedule, brief you, and handle assessor questions.
Week 8
CE Plus certification
On pass, IASME issues your CE Plus certificate. You now hold both badges, comfortably within the 3-month CE-to-CE-Plus window.
What we need from you
- A single point of contact who can answer questions about your IT setup across both engagements.
- Administrative access to in-scope cloud services. Read-only audit accounts work for most checks.
- All in-scope devices available for review and configured to the standard before the CE Plus audit day.
- Approval at two gates: CE submission, and CE Plus audit start.
Pricing
| Your business | Price |
|---|---|
| 1-10 employees, single cloud environment (Microsoft 365 or Google Workspace), no servers. Saves £295 vs buying separately. | £3,195 |
| 11-25 employees, mixed cloud and local IT, one or two servers. Saves £695 vs buying separately. | £4,095 |
| 26-50 employees, multiple sites or complex hybrid setup. Saves £895 vs buying separately. | £4,595 |
Fixed price. IASME CE assessment fee and IASME assessor CE Plus audit fee both included. If you're unsure which tier applies, book a free discovery call and we'll confirm before you commit.
Frequently asked questions
- Why bundle instead of buying separately?
- Three reasons: it's cheaper (£295-£895 saving depending on tier), it's faster (CE Plus prep starts during the CE assessor wait period rather than after CE completes), and it's simpler (one engagement, one set of invoices, one point of contact).
- Why not just buy CE first and add CE Plus later if needed?
- Valid path if you're genuinely unsure whether you need CE Plus. But if you know you'll need it within the next 6 months, the bundle is cheaper and faster. Buying CE today and CE Plus in three months means a second engagement fee, a second scoping call, and potentially CE re-certification work if you exceed the 3-month CE-to-CE-Plus window. Decide on the route at the discovery call - we'll tell you honestly which is cheaper for your situation.
- What if we fail the CE basic assessment?
- If we've done the gap assessment properly, failure is rare. If it does happen, the IASME assessor allows a short window to fix the flagged items and resubmit at no extra cost from us. CE Plus preparation continues during this period, so we don't lose time on the overall engagement.
- What if we pass CE but fail CE Plus?
- You'd still hold valid CE certification. For CE Plus, the standard allows a remediation window (typically 30 days) where we fix the flagged items and re-engage the assessor at no extra cost, provided the failure is within the original scope.
- Can we pause between CE and CE Plus?
- Yes, but only briefly. The CE certificate must be dated within 3 months of the CE Plus audit. Longer pauses mean re-running CE, which loses the bundle benefit.
- What if our IT changes during the engagement?
- Common: new hire, new cloud service, new office. Minor changes we absorb. Material changes that need re-scoping (e.g. acquiring another business mid-engagement) get a quick scope-change conversation - usually a small fee adjustment, not a full re-quote.
- Can we use our preferred IASME assessor for CE Plus?
- Usually yes. We partner with an IASME-licensed Certification Body for most engagements, but if you have an existing relationship with a different CB we can typically work with theirs at your request.
Related services
Cyber Essentials Certification
£995-£1,495
Full hand-held route to certification. Includes Cyber Liability Insurance via IASME for UK organisations under £20m turnover.
Read moreCyber Essentials Plus Certification
£2,495-£3,995
The audited tier. Required for many defence and NHS supply chain contracts. Cyber Essentials is a prerequisite.
Read moreCompliance Retainer
£450-£950 / month
Fractional compliance support for businesses without an in-house security lead. Monthly review, policy updates, and certification maintenance.
Read more
Ready to start?
Book a free 30-minute discovery call. We'll scope your situation and confirm which tier applies. No obligation, no sales pressure.

