Fast-Track · Weeks, Not Months

Cyber Essentials Plus Certification

NCSC Cyber Essentials & Cyber Essentials Plus - Readiness, Remediation and Audit Support for UK Organisations

Praxis-Q prepares UK organisations for Cyber Essentials and Cyber Essentials Plus under the NCSC scheme operated by IASME: scoping, gap assessment against the five technical controls, remediation of firewalls, secure configuration, access control, malware protection and patching, self-assessment submission and full support through the Plus technical audit by an IASME-licensed certification body. Typical time to certificate is 3-6 weeks.

Cyber Essentials is the UK government's baseline cyber security certification, run by the NCSC and delivered through IASME. It tests five technical control themes: boundary firewalls, secure configuration, user access control, malware protection and security update management. Cyber Essentials Plus adds an independent hands-on audit of those controls. Praxis-Q takes UK organisations from first scoping call to certificate, doing the remediation work that most first-time applicants fail on, and coordinating the assessment with an IASME-licensed certification body. The programme is designed for organisations bidding for UK public-sector, NHS and MoD work, SaaS and fintech vendors answering enterprise security questionnaires, and any business that wants the free cyber insurance and the reduced breach risk the scheme provides.

At a Glance

SchemeNCSC / IASME
Delivery3-6 weeks
Controls5 technical
Valid12 months

Cyber Essentials Plus

Cyber Essentials Plus Certification

NCSC Cyber Essentials & Cyber Essentials Plus - Readiness, Remediation and Audit Support for UK Organisations

The Problem

UK public-sector tenders, MoD supply chains and most enterprise vendor questionnaires now ask for Cyber Essentials Plus. Without the certificate you are excluded before pricing is even discussed, and the self-assessment alone no longer satisfies buyers.

What We Do

  • Scope
  • Gap Assessment
  • Remediation
  • Self-Assessment
  • Plus Audit

What You Get

  • Cyber Essentials self-assessment scoping and submission
  • Cyber Essentials Plus technical audit preparation
  • Gap assessment against all five NCSC control themes
  • Remediation of patching, MFA, firewall and device configuration
  • Evidence pack for external vulnerability scan and on-device testing
  • Eligibility for UK government and MoD (DEFCON 658) contracts
  • Free cyber liability insurance for eligible UK organisations under GBP 20M turnover
  • Annual renewal support and alignment with ISO 27001 and UK GDPR

The Five Cyber Essentials Controls, Explained

Firewalls: every device and the network boundary must block unauthenticated inbound connections, with any open services justified and documented. Secure configuration: default passwords removed, unnecessary software and accounts removed, auto-run disabled, device unlock protected by PIN, password or biometrics. User access control: unique accounts, least privilege, administrative accounts separated from daily use, and multi-factor authentication on all cloud services. Malware protection: anti-malware or application allow-listing on every in-scope device, including mobiles. Security update management: all software licensed and supported, with high and critical vulnerabilities patched within 14 days of release. Praxis-Q assesses each theme against the current IASME question set and produces a remediation plan with owners and dates.

Where First-Time Applicants Fail

The same gaps appear in most failed assessments: unsupported operating systems or browsers still in use, patches applied later than 14 days, MFA missing on Microsoft 365 or Google Workspace admin accounts, shared administrator credentials, home-worker devices not in scope statements, and cloud services omitted from the boundary. The Plus audit also fails devices where the authenticated scan finds vulnerabilities older than 14 days. We find these in the gap assessment and fix them before anything is submitted.

Scoping: Whole Organisation or Sub-Set

The scheme allows a whole-organisation scope or a defined sub-set, but the sub-set must be separated by a firewall or VLAN and clearly described. Whole-organisation scope is expected for government and MoD suppliers and is required to claim the free cyber liability insurance. Praxis-Q writes the scope statement, the device and cloud-service inventory, and the network diagram the assessor asks for.

The Cyber Essentials Plus Audit

Within three months of passing the self-assessment, a licensed assessor performs an external vulnerability scan of internet-facing IPs, an authenticated vulnerability scan of a representative sample of user devices and servers, tests that email and web downloads of malware samples are blocked, and confirms MFA and account separation. We run the same scans first, remediate, and attend the audit so questions are answered on the day.

Cyber Essentials Alongside ISO 27001, UK GDPR and Penetration Testing

Cyber Essentials is a technical baseline, not a management system. Organisations that also need ISO 27001, UK GDPR compliance or a CREST-aligned penetration test benefit from running them together: the device inventory, patch process and access control built for Cyber Essentials become ISO 27001 Annex A evidence, and the penetration test satisfies both the ISO 27001 technical vulnerability control and enterprise buyer requirements. Praxis-Q delivers all four, and the hardening, patching and monitoring work itself can be operated by our sister firm Techtweek Infotech under managed server and NOC services.

Cost and Timeline

Certification body fees for Cyber Essentials are set by IASME on a sliding scale by organisation size; Cyber Essentials Plus audit fees depend on the number of devices and locations sampled. Praxis-Q readiness and audit-support fees are fixed-price after scoping. Most organisations under 250 staff reach the Plus certificate in three to six weeks; renewal is annual and is faster once the controls are embedded.

Frequently Asked Questions

What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment against five technical controls. Cyber Essentials Plus covers the same controls but adds an independent technical audit: an external vulnerability scan, an authenticated scan of a sample of devices, and malware protection tests, carried out by an IASME-licensed certification body within three months of the basic certificate.
Is Praxis-Q a Cyber Essentials certification body?
No. Certificates are issued by certification bodies licensed by IASME on behalf of the NCSC. Praxis-Q delivers the readiness, remediation and audit-support work, and coordinates the assessment with a licensed certification body so you pass first time.
How long does Cyber Essentials Plus take?
Three to six weeks for most organisations with fewer than 250 staff, depending on the remediation required. The Plus audit itself takes one to two days. The certificate is valid for twelve months.
Who needs Cyber Essentials Plus?
Any supplier to UK central government handling personal or sensitive data (mandatory since 2014), MoD suppliers under DEFCON 658, NHS suppliers, and increasingly any organisation answering enterprise security questionnaires or seeking cyber insurance in the UK.
Can Cyber Essentials Plus be combined with ISO 27001?
Yes. Cyber Essentials covers the technical baseline and ISO 27001 covers governance and risk management. We map the five Cyber Essentials controls to the relevant ISO 27001:2022 Annex A controls so one remediation programme feeds both certifications.
Does Cyber Essentials Plus require a penetration test?
No. The Plus audit is a vulnerability scan and control verification, not a penetration test. Many buyers ask for both; Praxis-Q can run a CREST-aligned penetration test in the same engagement.
Are home workers and personal devices in scope?
Devices used to access organisational data or services are in scope, including staff-owned devices under a BYOD policy. Home routers are out of scope where the scheme's software firewall requirement is met on the device.
What happens if we fail the Plus audit?
You are given a short window to remediate and be re-tested by the certification body. Because Praxis-Q runs the same scans and tests beforehand, our clients rarely need it.
Does Cyber Essentials cover cloud services such as Microsoft 365 and AWS?
Yes. Cloud services the organisation controls data or configuration in are in scope, and the scheme requires MFA on all of them. Infrastructure-as-a-service and platform-as-a-service accounts must meet the same five controls.
Can Praxis-Q help non-UK companies get Cyber Essentials?
Yes. Companies outside the UK selling to UK government or enterprise buyers can certify. The controls and audit are the same; assessment is arranged remotely with a licensed certification body.

Ready to Get Started?

Free gap analysis · Proposal in 24hrs · Delivery in weeks