Cyber Essentials Plus — The Independent Technical Audit That Goes Beyond Self-Assessment
Cyber Essentials Plus takes everything in Basic and adds an independent technical audit of your systems. A GEEX assessor tests your controls from the outside — the same way an attacker would — and confirms they hold up under scrutiny.
20+ Years in Business
Trading since 2004. We have seen every kind of IT failure and know how to stop it before it starts.
1,000+ Clients
From accountancy firms to architectural practices. West Midlands and beyond.
700+ Endpoints
Managed and monitored.
Growing to 1,000.
FCA Regulated
We’re regulated so your lease is straightforward, protected, and professionally handled.
20+ Years in Business
Trading since 2004. We have seen every kind of IT failure and know how to stop it before it starts.
1,000+ Clients
From accountancy firms to architectural practices. West Midlands and beyond.
700+ Endpoints
Managed and monitored.
Growing to 1,000.
FCA Regulated
We’re regulated so your lease is straightforward, protected, and professionally handled.
What Is Cyber Essentials Plus?
Cyber Essentials Plus is the higher tier of the NCSC’s Cyber Essentials scheme. It includes everything in Cyber Essentials Basic — the self-assessment and the verified questionnaire — and adds an independent technical verification stage.
An accredited GEEX assessor conducts a series of technical tests on your live systems. These tests check that your controls work in practice, not just on paper. The assessor attempts to identify vulnerabilities in your network perimeter, your endpoint protection, and your patch management — the same way a real attacker would.
If your controls hold, you receive the Cyber Essentials Plus certificate, which carries significantly more weight than Basic in procurement, insurance, and enterprise supply chain contexts.
The process
The Certification Process — Step by Step
1
Step 1: Pre-Assessment Review (1–2 days)
We review your current IT environment and identify any gaps against the five Cyber Essentials controls. We tell you what you need to fix before you proceed.
2
Step 2: Gap Remediation (1–3 weeks depending on findings)
We fix the gaps. If you are on GEEX One, most gaps will already be closed. If not, we will quote for the remediation work separately.
3
Step 3: Self-Assessment Questionnaire
We work through the questionnaire with you — answering questions based on your documented controls and configuration. We do not leave you to fill it in alone.
4
Step 4: Assessor Review
GEEX submits your completed questionnaire to the IASME certification body for independent verification.
5
Step 5: Certificate Issued
On approval, you receive your Cyber Essentials certificate — valid for 12 months. You can display it on your website, include it in your procurement submissions, and provide it to your insurer.
6
Step 6: Annual Recertification
Cyber Essentials must be renewed annually. We contact you ahead of renewal so it does not lapse.
Cyber Essentials Basic Certification Pricing
**[Pricing TBC — Steve to confirm]**
Indicative market range:- Cyber Essentials Plus assessment: **£1,500–£3,000** (includes technical audit and one round of remediation support)
- Annual recertification: **£1,000–£1,500**
Note: If you are already on GEEX One, significant portions of the technical audit will pass immediately — your EDR, patch management, and password controls are already in place and documented. This typically reduces assessment time and cost.
who is it for?
Who Needs Cyber Essentials Plus?
Cyber Essentials Plus is appropriate for:
-
Businesses bidding for classified government contracts
MoD, GCHQ, and high-security government work often requires Plus specifically
-
NHS and healthcare supply chain
NHS Digital and NHS England require Plus for suppliers handling clinical data
-
PE-backed and high-value businesses
Due diligence processes for investment and acquisition typically include Plus-level verification
-
Enterprise supply chain
FTSE 100 and large corporate clients are increasingly specifying Plus in their supplier questionnaires
-
Businesses that have already achieved Basic
and want to demonstrate a higher level of assurance
What the Technical Audit Covers
The Cyber Essentials Plus audit involves a GEEX assessor testing your systems against the same five control areas as Basic, but from the outside:
-
Network perimeter testing
Scanning your external IP addresses to identify open ports, exposed services, and outdated software
-
Internal vulnerability assessment
Testing your internal network (remotely or onsite) for unpatched systems, misconfigured devices, and weak access controls
-
Endpoint malware detection test
Testing that your malware protection (EDR or antivirus) detects and blocks a known malware sample before it can execute
-
Patch management verification
Confirming that your operating systems and applications are patched within the required 14-day window
-
User account privilege verification
Confirming that administrative privileges are appropriately restricted
FAQs
Common Questions About Cyber Essentials Plus
What is the minimum contract length?
GEEX One is designed to give you the technical posture you need to pass Cyber Essentials. When you are already on GEEX One:
What is the minimum contract length?
GEEX One is designed to give you the technical posture you need to pass Cyber Essentials. When you are already on GEEX One:
What is the minimum contract length?
GEEX One is designed to give you the technical posture you need to pass Cyber Essentials. When you are already on GEEX One:
What is the minimum contract length?
GEEX One is designed to give you the technical posture you need to pass Cyber Essentials. When you are already on GEEX One:
What is the minimum contract length?
GEEX One is designed to give you the technical posture you need to pass Cyber Essentials. When you are already on GEEX One:
20+ Years in Business
Trading since 2004. We have seen every kind of IT failure and know how to stop it before it starts.
1,000+ Clients
From accountancy firms to architectural practices. West Midlands and beyond.
700+ Endpoints
Managed and monitored.
Growing to 1,000.
FCA Regulated
We’re regulated so your lease is straightforward, protected, and professionally handled.
20+ Years in Business
Trading since 2004. We have seen every kind of IT failure and know how to stop it before it starts.
1,000+ Clients
From accountancy firms to architectural practices. West Midlands and beyond.
700+ Endpoints
Managed and monitored.
Growing to 1,000.
FCA Regulated
We’re regulated so your lease is straightforward, protected, and professionally handled.
Let Us Show You What Two Decades of IT Experience Looks Like
A conversation costs nothing. Tell us what your current IT looks like and we will tell you honestly whether we can improve on it — and what it would cost.