HomeFrameworksNational Cyber & Cloud SchemesCyber Essentials Plus

Framework  National Cyber & Cloud Schemes

Cyber Essentials Plus

Cyber Essentials is the UK government-backed baseline cybersecurity certification, owned by the National Cyber Security Centre and delivered by IASME as the sole delivery partner. It covers five technical control themes: firewalls, secure configuration, security update management, user access control, and malware protection.

The basic level is a verified self-assessment: the applicant answers the current question set ("Willow", version 3.2, introduced April 28, 2025, replacing "Montpellier") and a certification body reviews and signs off the answers.

Cyber Essentials Plus adds independent technical verification: an assessor from a licensed certification body tests a sample of devices and the internet-facing perimeter (vulnerability scans, patch checks, malware protection tests, email and browser download tests, multifactor authentication checks, and account separation checks) within three months of the basic certificate.

In writing, an applicant needs a defined scope (the whole organization or a clearly separated subset), an asset list of in-scope devices, cloud services, and network equipment, documented configuration and patching standards showing the fourteen-day rule for critical and high updates, an account management procedure covering joiners, movers, leavers, administrative accounts, and MFA, a malware protection approach for each device type, and a policy for home and remote working and bring-your-own-device.

Public sector contracts under PPN 014 and many private supply chains require it, and certification comes with included cyber insurance for small UK organizations.

AI-compiled
Share
Sponsored
Cyber
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with Cyber Essentials Plus
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary, but effectively required for suppliers to UK central government contracts involving personal data or ICT services under PPN 014, for many NHS, defense, and local authority contracts, and by a growing number of private customers. Available to organizations of any size anywhere, though the insurance benefit applies to UK organizations under a turnover threshold.

What the assessor asks to see

Scope statement and organization details; asset inventory (end user devices, servers, mobile devices, cloud services, firewalls and routers by make and model); firewall configuration and rule review evidence; secure build and configuration standards; patch status showing updates within fourteen days; user account list, MFA configuration, and administrative account separation; malware protection configuration by device type; remote working policy; for Plus, the assessor's sample device tests, external vulnerability scan results, and email and browser download test results.

Where the requirement sits: Cyber Essentials: firewalls, secure configuration, access control, malware protection, patching

Willow question set (v3.2)

Introduced April 28, 2025. Changes included renaming home working to home and remote working to cover untrusted networks, limiting the network equipment list to firewalls and routers, clarifying passwordless authentication, and aligning vulnerability fix language with NCSC guidance. Certificates issued under Montpellier remained valid until expiry.

Assessors

Who assesses Cyber Essentials Plus

Certification bodies licensed by IASME, employing qualified Cyber Essentials assessors. Cyber Essentials Plus assessments must be performed by a licensed certification body's assessor; the basic level is marked by a certification body against the applicant's self-assessment.

Accredited by IASME licenses and audits certification bodies on behalf of NCSC; NCSC sets scheme policy and the technical requirements.

Public register of assessors: https://iasme.co.uk/cyber-essentials/find-a-certification-body/

No firm has claimed a Cyber Essentials Plus assessor listing yet. Claim yours →

Consultants

Who helps with Cyber Essentials Plus

A large market of IT managed service providers and consultancies prepare organizations, often the same firms that are licensed certification bodies (though not for the same client under the scheme's conflict rules). Readiness for Plus usually takes a few weeks to three months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

Echelon CyberUSANot yet verified
What they do
VCISO
Who they help
Echelon Cyber is a vCISO based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
URM ConsultingUKNot yet verified
What they do
ISO 27001 consultancy
Who they help
URM Consulting is an ISO 27001 consultancy based in UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Precursor SecurityLeeds, UKNot yet verified
What they do
ISO 27001 + CREST pentest
Who they help
Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Nettitude (LRQA Cyber Security)Birmingham, UKNot yet verified
What they do
CREST partner
Who they help
Nettitude (LRQA Cyber Security) is a CREST partner based in Birmingham, UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
BridewellUKNot yet verified
What they do
Cyber posture + ISMS management
Who they help
Bridewell is a cyber posture + ISMS management based in UK. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for Cyber Essentials Plus

Tools that name this framework in their own material.

No firm has claimed a Cyber Essentials Plus tool listing yet. Claim yours →

Related reading

  1. Cyber Essentials and Cyber Essentials Plus: what is the difference?The scheme's own delivery partner on how the Plus technical audit samples devices and gateways beyond the self-assessment.IASME
  2. Cyber Essentials update 2026Tracks the move through the Willow and Danzell question sets and the tightened rules on non-compliances before a Plus audit.URM Consulting
  3. Cyber Essentials frequently asked questionsAnswers the scoping, timing and recertification questions that decide whether a Plus audit can go ahead.IASME

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for Cyber Essentials Plus

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with Cyber Essentials Plus

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.