Cyber Essentials Plus: UK Government Cybersecurity Certification

Cyber Essentials Plus is the UK government's independently verified cybersecurity certification, required for MOD contracts and central government suppliers handling sensitive data.

🛡️ STATUS BADGE: 🔵 CERTIFIED (SaaS) | 🟢 ELIGIBLE (Self-Hosted)

Executive Summary: What is it?

Cyber Essentials Plus is a UK government-backed cybersecurity certification owned by the NCSC (National Cyber Security Centre) and delivered by the IASME Consortium. Unlike basic Cyber Essentials — which is a self-assessment questionnaire — Plus requires an independent technical audit by a licensed Certification Body, including vulnerability scanning, device configuration checks, and malware testing. It covers five control areas: firewalls, secure configuration, user access control, malware protection, and patch management. Certification is valid for 12 months and must be renewed annually.

CFO / Business Impact: What does it cost/risk?

Technical Reality: How does it work?