What is Cyber Essentials Plus?

In order to achieve Cyber Essentials Plus, you must already be certified to Cyber Essentials. Gaining the extra qualification will also involve a technical expert conducting an on-site or remote audit on your IT systems, including a representative set of user devices, all Internet gateways and all servers with services accessible to unauthenticated Internet users.

The assessor will test a random sample of these systems, in line with the test specification, and then decide whether further testing is required. Having achieved Cyber Essentials, you have 3 months to apply for Cyber Essentials Plus.

If it is longer than 3 months, you will need to repeat the Cyber Essentials self-assessment questionnaire stage.

Our assessor was really helpful – he didn't just tell us what to do but also explained everything to us, which was a real benefit, very happy.
Digital consultancy
Apply for Cyber Essentials Plus

Cyber Security and the Board: A Sign of What’s to Come

Published on
11 Mar
2026

URM’s blog explains recent amendments to the Cyber Security and Resilience Bill, how they align with broader regulatory shifts, & practical steps to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/2/2026
NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
19/1/2026
Minimising the Impact When a Breach Occurs

URM’s blog explores the importance of cyber resilience & the steps organisations can take to prepare for and mitigate the impact of a cyber incident.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
9/1/2026
Strengthening Your Cyber Defences: Practical Steps for Every Business

URM’s blog explores common weaknesses in organisations’ security programmes, & outlines practical, cost-effective measures to reduce the likelihood of a breach

Read more
"
The feedback on URM’s report was that it was the best document the developer had ever received due to it being so concise and clear. He has saved it on his desktop and suggested that the business should use a similar template for internal docs. This great feedback reflects not only on the URM penetration tester who conducted the test, but also on the senior members of URM’s Cyber Team for all the work they have put in to producing such a brilliant reporting template.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.