Do you need Cyber Essentials Plus — and are you ready?

A few minutes. Find out where you stand on the Cyber Essentials Plus journey, what the assessor will actually test, and a realistic timeline. Free, no obligation.

Cyber Essentials is run by IASME on behalf of the NCSC. Nerdster is not a certification body — we prepare you, run the pre-audit scans, and coordinate with the certification body. Your answers stay in your browser until you ask for your summary.

Question 1 of 18
Where are you on the Cyber Essentials journey right now?

Where are you on the Cyber Essentials journey right now?

What the CE Plus audit actually involves

Cyber Essentials Plus verifies the same five controls as the basic certification, but an assessor tests them hands-on. For assessment accounts registered after 27 April 2026, assessments run against the Danzell question set (published 13 February 2026) and Cyber Essentials Requirements for IT Infrastructure v3.3. The audit consists of:

  • An internal and external vulnerability scan.
  • A random sample of user devices (typically around 10%), plus all internet gateways and all internet-accessible servers.
  • An account-separation check — each sampled user demonstrates they cannot perform admin functions from a standard account.
  • An MFA challenge test against every cloud service, using at least one standard and one admin account per service.
  • Malware protection testing on the sampled devices.

There is no phishing simulation in CE Plus. New under Danzell: if the initial test of the device sample fails, the retest rechecks the original sample and a new random sample — and a second failure revokes the verified self-assessment certificate. Another reason to get patching right before the audit, not during it.

Sequencing matters too: the CE Plus audit is completed within 3 months of the Cyber Essentials self-assessment certification — any longer and the self-assessment stage has to be repeated.

Certifying can also make you eligible to opt in to cyber liability insurance with a £25,000 limit of indemnity — but only if the whole organisation is certified (a scoped subset does not qualify), it is domiciled in the UK or Crown Dependencies, annual turnover is under £20m, and you explicitly opt in. It is not automatic.

Replies the same business day

Already know you need CE Plus?

We take firms from wherever they are today to a passed CE Plus audit — preparation, pre-scans and coordination with the certification body.

  • No callout fees
  • No-obligation assessment