Cyber Essentials Plus Certification
NCSC Cyber Essentials & Cyber Essentials Plus - Readiness, Remediation and Audit Support for UK Organisations
Praxis-Q prepares UK organisations for Cyber Essentials and Cyber Essentials Plus under the NCSC scheme operated by IASME: scoping, gap assessment against the five technical controls, remediation of firewalls, secure configuration, access control, malware protection and patching, self-assessment submission and full support through the Plus technical audit by an IASME-licensed certification body. Typical time to certificate is 3-6 weeks.
At a Glance
Cyber Essentials Plus
Cyber Essentials Plus Certification
NCSC Cyber Essentials & Cyber Essentials Plus - Readiness, Remediation and Audit Support for UK Organisations
The Problem
UK public-sector tenders, MoD supply chains and most enterprise vendor questionnaires now ask for Cyber Essentials Plus. Without the certificate you are excluded before pricing is even discussed, and the self-assessment alone no longer satisfies buyers.
What We Do
- Scope
- Gap Assessment
- Remediation
- Self-Assessment
- Plus Audit
What You Get
- Cyber Essentials self-assessment scoping and submission
- Cyber Essentials Plus technical audit preparation
- Gap assessment against all five NCSC control themes
- Remediation of patching, MFA, firewall and device configuration
- Evidence pack for external vulnerability scan and on-device testing
- Eligibility for UK government and MoD (DEFCON 658) contracts
- Free cyber liability insurance for eligible UK organisations under GBP 20M turnover
- Annual renewal support and alignment with ISO 27001 and UK GDPR
The Five Cyber Essentials Controls, Explained
Firewalls: every device and the network boundary must block unauthenticated inbound connections, with any open services justified and documented. Secure configuration: default passwords removed, unnecessary software and accounts removed, auto-run disabled, device unlock protected by PIN, password or biometrics. User access control: unique accounts, least privilege, administrative accounts separated from daily use, and multi-factor authentication on all cloud services. Malware protection: anti-malware or application allow-listing on every in-scope device, including mobiles. Security update management: all software licensed and supported, with high and critical vulnerabilities patched within 14 days of release. Praxis-Q assesses each theme against the current IASME question set and produces a remediation plan with owners and dates.
Where First-Time Applicants Fail
The same gaps appear in most failed assessments: unsupported operating systems or browsers still in use, patches applied later than 14 days, MFA missing on Microsoft 365 or Google Workspace admin accounts, shared administrator credentials, home-worker devices not in scope statements, and cloud services omitted from the boundary. The Plus audit also fails devices where the authenticated scan finds vulnerabilities older than 14 days. We find these in the gap assessment and fix them before anything is submitted.
Scoping: Whole Organisation or Sub-Set
The scheme allows a whole-organisation scope or a defined sub-set, but the sub-set must be separated by a firewall or VLAN and clearly described. Whole-organisation scope is expected for government and MoD suppliers and is required to claim the free cyber liability insurance. Praxis-Q writes the scope statement, the device and cloud-service inventory, and the network diagram the assessor asks for.
The Cyber Essentials Plus Audit
Within three months of passing the self-assessment, a licensed assessor performs an external vulnerability scan of internet-facing IPs, an authenticated vulnerability scan of a representative sample of user devices and servers, tests that email and web downloads of malware samples are blocked, and confirms MFA and account separation. We run the same scans first, remediate, and attend the audit so questions are answered on the day.
Cyber Essentials Alongside ISO 27001, UK GDPR and Penetration Testing
Cyber Essentials is a technical baseline, not a management system. Organisations that also need ISO 27001, UK GDPR compliance or a CREST-aligned penetration test benefit from running them together: the device inventory, patch process and access control built for Cyber Essentials become ISO 27001 Annex A evidence, and the penetration test satisfies both the ISO 27001 technical vulnerability control and enterprise buyer requirements. Praxis-Q delivers all four, and the hardening, patching and monitoring work itself can be operated by our sister firm Techtweek Infotech under managed server and NOC services.
Cost and Timeline
Certification body fees for Cyber Essentials are set by IASME on a sliding scale by organisation size; Cyber Essentials Plus audit fees depend on the number of devices and locations sampled. Praxis-Q readiness and audit-support fees are fixed-price after scoping. Most organisations under 250 staff reach the Plus certificate in three to six weeks; renewal is annual and is faster once the controls are embedded.
Related Services
Frequently Asked Questions
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Is Praxis-Q a Cyber Essentials certification body?
How long does Cyber Essentials Plus take?
Who needs Cyber Essentials Plus?
Can Cyber Essentials Plus be combined with ISO 27001?
Does Cyber Essentials Plus require a penetration test?
Are home workers and personal devices in scope?
What happens if we fail the Plus audit?
Does Cyber Essentials cover cloud services such as Microsoft 365 and AWS?
Can Praxis-Q help non-UK companies get Cyber Essentials?
Ready to Get Started?
Free gap analysis · Proposal in 24hrs · Delivery in weeks