Skip to main content
Home/ Cyber Essentials Plus
Cyber Essentials Plus

Cyber Essentials Plus certification with independent technical assessment

Move from the Cyber Essentials verified self-assessment to independent technical testing of the same five control areas with Meta Defence Labs, an IASME-licensed Cyber Essentials Plus Certification Body. We coordinate scope, sampling, evidence and assessment planning for organisations that need stronger assurance.

Discuss your CE+ scope

Verify on IASME: search Meta Defence Labs ↗

Cyber Essentials & CE+
Certification Body
NCSC-assured
Cyber Advisor service ↗
DCC Level 0 & Level 1
Assessment capability
Established in 2015
Experienced assessors

Technical verification changes the preparation required.

Cyber Essentials Plus tests whether the Cyber Essentials controls are implemented effectively within the assessed environment. Scope, endpoint sampling, evidence, vulnerability management, remote working and cloud services all need to be understood before the assessment window begins.

What readiness needs to account for

  • Multiple sites, legal entities and stakeholder groups
  • Mixed operating systems and endpoint populations
  • Cloud services, identity platforms and remote working
  • Contractual requirements and fixed procurement milestones

A structured Cyber Essentials Plus engagement

  • Scoping and certification strategy
  • Readiness and technical evidence review
  • Vulnerability readiness and remediation planning
  • Assessment preparation and certification lifecycle planning

Prepare properly. Assess confidently.

01 / Scope

Agree the boundary

Identify the organisation, systems and services to be covered. Make dependencies and responsibilities explicit.

02 / Prepare

Understand readiness

Review scope, patching, evidence, sampled-device readiness and the work needed before formal testing. Agree priorities with the teams responsible for delivery.

03 / Assess

Demonstrate the controls

Complete the independent technical assessment with the required devices, users, evidence and technical controls ready to be tested.

Cyber Essentials Plus questions

What does Cyber Essentials Plus add to Cyber Essentials?

Cyber Essentials Plus adds independent technical testing to verify that the Cyber Essentials controls are implemented effectively within the assessed environment.

How are devices handled during the assessment?

The assessment uses an appropriate sample from the declared in-scope environment. The organisation needs an accurate inventory and must be able to make the required sampled systems available for testing.

Why is readiness important before the assessment?

Technical issues discovered late can put certification deadlines at risk. Readiness work helps confirm scope, evidence, patching, security controls and operational ownership before formal testing begins.

Can MDLabs help before the formal assessment?

Readiness, evidence review and practical technical guidance can form part of an agreed engagement, while assessment responsibilities and any applicable impartiality requirements remain clearly separated.

What should we prepare for an initial Cyber Essentials Plus discussion?

Bring an outline of the intended scope, approximate organisation and device population, current Cyber Essentials status, key platforms, target date and the business requirement behind CE+.

Do we need Cyber Essentials before Cyber Essentials Plus?

Yes. Cyber Essentials Plus builds on Cyber Essentials. IASME requires the associated Cyber Essentials certification to be completed before CE+ and the Plus assessment to be completed within three months of that Cyber Essentials certification.

Scheme reference: NCSC Cyber Essentials resources

Scheme guidance checked 9 September 2026 against the current NCSC Cyber Essentials requirements and Cyber Essentials Plus test specification.

Preparing a complex estate for Cyber Essentials Plus?

For larger environments, our enterprise CE+ guidance focuses on scope, ownership, evidence, sampling and remediation across the wider technology estate.

Explore Enterprise Cyber Essentials Plus →
Client evidence

Cyber Essentials Plus in complex organisations

The route to CE+ can look very different depending on scale, starting point and commercial deadline. These anonymised engagements show three different paths to successful certification.

From gap assessment to Cyber Essentials Plus over approximately a year

A multinational energy organisation used a comprehensive gap assessment to secure investment, remediate significant issues and embed stronger vulnerability and asset-lifecycle practices before achieving CE+.

Read the case study →

Three consecutive years of Cyber Essentials Plus continuity

A multi-entity international organisation has maintained CE+ through an annual assurance cycle that identifies gaps early and coordinates remediation before each assessment window.

“The assessment was rigorous whilst remaining collaborative, which made a real difference.” — Group CISO

Read the case study →

Cyber Essentials Plus within an approximately two-month contractual timeframe

A global enterprise technology company used structured readiness, rapid remediation and coordinated assessment planning to achieve Cyber Essentials and CE+ within its required commercial timeframe.

Read the case study →

Planning Cyber Essentials Plus?

Tell us about your scope, current Cyber Essentials status, technology estate and target date. Start with a conversation about readiness and assessment.

Discuss your CE+ scope