Northgate Compliance
All services

Cyber Essentials Plus Certification

£2,495-£3,995·4-6 weeks

The audited tier of Cyber Essentials. Where CE is a self-assessment we complete on your behalf, CE Plus adds a hands-on technical audit by an external IASME assessor: external and internal vulnerability scans, sample device build review, and malicious file delivery tests. We do the preparation, run a full internal pre-audit, and walk you through what the assessor will do.

Founding Client pricing - first ten engagements. Prices increase once Northgate Compliance achieves NCSC Assured Cyber Advisor status.

Your Cyber Essentials certificate must be dated within 3 months of your CE Plus audit. If you're not yet certified, we run both in sequence via the CE + CE Plus Bundle - cheaper than buying them separately.

Who this is for

  • Defence supply chain Tier 2-4 suppliers where DEFCON 658 explicitly requires CE Plus, not just CE.
  • NHS Trust suppliers bidding on DSP Toolkit-gated contracts that mandate CE Plus.
  • Larger professional services firms (15+ users) where the professional indemnity insurer or a regulator has specifically asked for the audited tier.
  • Manufacturers in critical supply chains where a Tier 1 customer audit requires CE Plus.
  • Businesses already holding CE basic whose largest client has tightened supplier requirements mid-contract.

What's included

  • CE Plus scope confirmation

    We review your existing Cyber Essentials scope and confirm what changes (if any) are needed for the CE Plus audit. Often the same scope works.

  • Full internal pre-audit

    We run the assessor's technical checks ourselves first: external vulnerability scan, internal authenticated scan on sample devices, malicious file delivery tests, MFA verification, account separation review. You see the gap report before the assessor does.

  • Remediation guidance

    Plain-English fixes for any gaps, or we apply them for you on managed devices.

  • Device preparation

    We confirm all in-scope devices are configured to the standard. The IASME assessor selects a representative sample to test on audit day.

  • Malicious file test prep

    The assessor sends test files via email and web download to confirm your endpoint protection blocks them. We make sure your email and web filtering are configured to pass.

  • Vulnerability scan prep

    We help you scope the external scan of your internet-facing systems and the internal authenticated scan on sample devices.

  • Audit day coordination

    We schedule with the assessor, brief you on what to expect, and handle questions during the audit.

  • IASME assessor audit fee

    Bundled into your quoted price. No surprise invoice from the assessor.

  • Your certificate

    Issued by IASME on successful audit. Valid for 12 months.

What's not included

  • Cyber Essentials basic certification. Must be held before CE Plus. See CE Certification or the CE + CE Plus Bundle.
  • Penetration testing. CE Plus is a controls audit, not a pen test. Quoted separately if you want both.
  • Remediating fundamental architecture problems. If your environment can't pass without significant infrastructure change, we'll tell you up front and quote the additional scope.
  • Hardware or software purchases. If remediation needs new tools (e.g. an MDM, a different antivirus), that's your spend.

What the assessor will check

  1. 1

    Patch and update status

    Verified across a sample of in-scope devices, confirming critical patches are applied within 14 days.

  2. 2

    External vulnerability scan

    A scan of your internet-facing IP addresses for unpatched services and known vulnerabilities.

  3. 3

    Internal authenticated scan

    An authenticated scan on the sample of devices the assessor selects, checking for unpatched software and misconfiguration.

  4. 4

    Sample device build review

    Confirming secure configuration (firewalls, hardening, default password removal) is actually applied, not just policy.

  5. 5

    Malicious file delivery test

    Test files sent via email and web download to confirm your endpoint protection blocks them in practice.

  6. 6

    MFA and account separation

    Multi-factor authentication enforced on cloud and admin accounts. Admin accounts separated from standard user accounts.

Process

  1. Weeks 1-2

    Scope and pre-audit

    We review your CE scope, run the technical checks ourselves, and produce a gap list. You see exactly what the assessor will find before they look.

  2. Weeks 3-4

    Remediation

    We fix or guide the fix of every gap. Most are configuration changes; some need a tool change (e.g. switching antivirus or enabling MFA on a service that doesn't have it yet).

  3. Week 5

    Audit

    The IASME assessor performs their audit. Typically 1-2 days for a small business. We coordinate the schedule, brief you on the day, and answer any questions raised.

  4. Week 6

    Certification

    On pass, IASME issues your certificate. If anything was flagged, we resolve it and the assessor signs off.

What we need from you

  • A confirmed Cyber Essentials certificate dated within the last 3 months (or a CE Bundle engagement running in parallel).
  • Administrative access to in-scope cloud services. Read-only audit accounts work for most checks.
  • All in-scope devices available for review and configured to the standard before audit day.
  • A point of contact who can answer assessor questions during the audit window.

Pricing

Your businessPrice
1-10 employees, single cloud environment (Microsoft 365 or Google Workspace), no servers£2,495
11-25 employees, mixed cloud and local IT, one or two servers£3,295
26-50 employees, multiple sites or complex hybrid setup£3,995

Fixed price. IASME assessor audit fee included. If your situation falls outside these tiers, book a free discovery call and we'll confirm scope before you commit.

Frequently asked questions

What happens if we fail the audit?
Most CE Plus failures are configuration gaps the assessor flags during the audit. The standard allows a remediation window (typically 30 days), and we fix and re-engage the assessor at no extra cost if the failure is within the original scope. Structural failures (e.g. a deprecated server we couldn't fully retire in time) are different - we'd discuss the path forward together rather than burn the audit.
How is CE Plus different from a penetration test?
A pen test simulates an attacker actively trying to break in. CE Plus is a controls audit - the assessor checks specific things are configured correctly. Different exercises for different reasons. Most businesses need both eventually, but for different stakeholders.
Can we do CE and CE Plus at the same time?
Yes. The CE + CE Plus Bundle runs both engagements in sequence, with CE completing first and CE Plus following immediately. Total delivery is 6-8 weeks for less combined cost than buying them separately.
What counts as 'in scope' for the audit?
Anything used to access business data: employee devices (laptops, desktops, phones, tablets), cloud services holding business data, and internet-facing systems. Personal-use-only devices are out of scope. Genuinely segregated environments (e.g. an isolated test lab with no business data) can be excluded if properly air-gapped. We confirm scope with you during the first call - getting this wrong is the most common reason CE Plus engagements over-run.
Can we use our preferred IASME assessor?
Usually yes. We partner with an IASME-licensed Certification Body for most engagements, but if you have an existing relationship with a different CB we can typically work with theirs at your request. The preparation work doesn't change.
Will the audit disrupt the business?
Minimally. The assessor needs access to a sample of devices (typically 2 hours each), an admin account on your cloud services, and someone available to answer questions. Internal scans run only on the sample devices the assessor selects - no broad network sweep.
Do we need to redo CE Plus every year?
Yes. Both CE and CE Plus are 12-month certifications. Maintaining the badge for tender purposes typically means annual renewal.
Can our managed service provider perform any of this work?
They can implement remediation. They cannot perform the audit itself - that must be done by an IASME-licensed Certification Body. We coordinate the work between you, your MSP, and the assessor.

Ready to start?

Book a free 30-minute discovery call. We'll scope your situation and confirm which tier applies. No obligation, no sales pressure.