Cyber Essentials Plus

What is Cyber Essentials Plus?

The UK government reported that around one-third of businesses had a cyber security breach in 2019 and for some of these businesses the cost of the breach was substantial. As a result, cyber security is becoming a crucial consideration for businesses of all sizes. Cyber Essentials Plus certification will give you and your partners confidence that your organisation is protected against a cyber security breach.

Cyber Essentials Plus has all the simplicity and approach of Cyber Essentials but offers the additional comfort of a hands-on technical audit of your system by an experienced cyber security assessor. We will examine the same FIVE basic security controls as the Cyber Essentials certification and test how effective they have been implemented through a robust technical audit.

Our sister company, Ascentor, is our Certification Body for Cyber Essentials. Part of the Amtivo group and recognised as Cyber Security experts, they boast clients such as the Ministry of Defence and the Houses of Parliament. You can find out more about them on their website: https://ascentor.co.uk/

 

Get Protected, Get Certified – Improve your company’s credentials by having the correct security controls in place.

Cyber Essentials Plus Certification

You are protecting your business now and for the future.

  • Certification gives you peace of mind that your defences will protect against the vast majority of common cyber attacks
  • Stand out from competitors, retain and win more business
  • Increased credibility and reputation, customers feel more confident in sharing information with you
  • Raised awareness of threat with staff reduces risk levels
  • Improved business continuity management
  • Tender for contracts with the MOD, NHS, and central government work
  • Reduce your insurance premiums by reducing your resilience to cyber threats
  • Drive business efficiencies throughout your organisation which helps improve productivity

Cyber Essentials Plus certification process

Cyber Essentials Plus requires you to have an existing Cyber Essentials certificate that is less than 2 months old. You will need to complete an online application form, which will be reviewed by an experienced cyber security assessor before they conduct a hands-on technical audit of your systems.

  • Confirm your existing Cyber Essentials certification

    Start the process by completing providing your existing Cyber Essentials self-assessment certificate.

  • Complete and submit your online application for a technical audit

    Our online application form will provide our cyber security experts with the information they need to develop a plan for assessing your cyber security protections.

  • In-depth assessment takes place

    Our assessor will book in a time to access and assess your current security protections, based on the information supplied in your application form.

  • Certificate Awarded

    If your assessment is successful you will be notified and you will receive confirmation of your certification.

  • Annual renewal

    It is recommended that the Cyber Essentials Plus certification is reviewed and resubmitted annually to maintain certification.

Cyber Essentials

Cyber Essentials is a self-assessment certification which gives you peace of mind that your defences will protect against the majority of common cyber attacks. Obtaining Cyber Essentials is simple, through completion of a self-assessment questionnaire we assess you against the FIVE basic security controls. A qualified assessor verifies the information provided and if you satisfy the requirements, our Certification Body, Ascentor, will award you with Cyber Essentials certification.

Learn more

What is the purpose of Cyber Essential Plus certification?

Cyber Essentials Plus is a UK Government standard for technical controls to help organisations improve the level of IT infrastructure security and guard your organisation against cyber attack. This certification requires you to have an independent audit of your systems.

This scheme is designed to help organisations prevent highly common internet-based attacks and to implement the right controls to protect the confidentiality, integrity, and availability of stored data on devices on all internet-facing devices.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials certification is a simple process to protect your business guard against common cyber threats. You will need to complete a self-assessment questionnaire which is assessed by a British Assessment Bureau assessor.  They will independently check your completed questionnaire to ensure that you have in place the recommended FIVE cyber key controls necessary to protect your organisation from the most common cyber attacks

Cyber Essentials Plus certification still has the same basic principles as Cyber Essentials but will have a more rigorous test of your organisation’s cyber security systems. It will require a hands-on technical verification with a qualified assessor to check your eligibility for Cyber Essentials Plus certification.

Why should I get Cyber Essentials Plus certified?

Becoming Cyber Essentials Plus certified confirms you have been independently audited and have addressed your cyber security effectively and reduced the risk from internet-based threats and have met the standards set by Cyber Essentials scheme.

Certification gives assurance to stakeholders that you demonstrate compliance to the FIVE key controls, protecting your organisation against cyber threats and this reassurance may help with winning new business. Depending on the industry sectors you work within, central government contracts require Cyber Essentials certification as a minimum.

Key benefits of Cyber Essentials Plus certification?

Protecting your organisation against the majority of common cyber attacks demonstrates to stakeholders your commitment to keeping their data secure which can lead to business retention and potentially new business.

By having a higher level of security of your systems it will help drive business efficiencies throughout your organisation which helps improve productivity through streamlined processes and reducing operational costs.

Bid for UK central government contracts that involve the handling of personal and sensitive information.

Reduce your insurance premiums by reducing your resilience to cyber threats.

Should I get Cyber Essentials or Cyber Essentials Plus?

This all depends on your organisational needs. If you are looking to work within the public sector and bid for central government contracts than they will ask for Cyber Essentials as a minimum. If you want to demonstrate that your organisation is compliant with cyber security and takes data protection seriously and you hold sensitive data, then you may want to also achieve Cyber Essentials Plus certification.

How do I get Cyber Essentials Plus certified?

Become Cyber Essential Plus certified through these simple steps

  1. Purchase Cyber Essential Plus certification through one of our sales advisors
  2. Complete self-assessment question (SAQ) for Cyber Essentials and upload for the British Assessment Bureau for assessment review
  3. Once the submission is approved, you will be notified of your systems audit date
  4. Your systems will be rigorously tested during this audit to ensure you have put in place all the steps to meet the required standard
  5. If you have you all the steps in place, we will issue your Cyber Essentials Plus certification.

Where can I find details of full requirements for the Cyber Essentials Plus scheme?

More details on cyber security and the Cyber Essentials and Cyber Essentials Plus scheme can be found at the National Cyber Security Centre website.

Can I see the self-assessment questions before I pay for an assessment?

You can download a copy of the self-assessment questionnaire here and you can find further guidance on the National Cyber Security Centre website.

How are the Cyber Essentials PLUS assessments verified?

The Cyber Essentials question set is part of the Cyber Essentials Plus certification process. It is the same checks as Cyber Essentials scope but involves a technical audit of the systems. This includes a representative set of user devices, all internet gateways, and all servers with services accessible to unauthenticated internet users. If you have achieved the basic level Cyber Essentials certification less than 3 months before certifying to Cyber Essentials Plus and nothing has changed you will not need to repeat the self-assessment questions stage. The assessor will check that you still meet the FIVE security requirements of Cyber Essentials before proceeding with Cyber Essentials Plus certification.

Do I have to complete Cyber Essentials to apply for Cyber Essential Plus?

Cyber Essentials self-assessment forms part of the application for Cyber Essentials Plus and is processed at the same time. You must meet the minimum requirements of Cyber Essentials before we process the Cyber Essentials Plus and complete the Cyber Essentials questionnaire which will verify your compliance as part of achieving Cyber Essentials Plus.

To apply for Cyber Essentials Plus you must possess a Cyber Essentials certificate, supply a copy of the Cyber Essentials questionnaire submitted, and confirm that no changes have been made to your controls since that submission.

How much does it cost for Cyber Essentials Plus certification?

Cyber Essentials Plus assessments involve a technical audit of the system and must be quoted individually. You can request a quotation here.

How quickly can I get certified to Cyber Essentials Plus certified?

You will need to complete and pass the Cyber Essentials requirements and once we have carried out the technical audit, we aim to return a report as quickly as possible. I may take up to five working days from the time you submit your assessment.

How long will I have to complete and submit my assessment?

You can take as long as you want to start your assessment. Once you have started it, you need to complete it including any corrective actions identified by your assessor within one month.

If I fail will I get feedback about why I failed?

If you fail the assessment, we will supply a report back with the answers you gave along with the assessor feedback. This should help you improve your security so you can pass again in the future. You will have 30 days for the remediation of any components of the assessment which received fail status.

My organisation is not based in the UK can still obtain Cyber Essentials Plus certification?

Yes, organisations overseas can get certified, contact us now.

Do certifications have an expiry date?

Certificates expire after 12 months, therefore, we recommend you seek to renew your certification before expiry.

Will I receive a reminder to recertify?

We will email you with a reminder before your expiry date to check your situation and if you want to proceed with another year’s certification.

When I recertify will I have to re-enter all the information again?

If you have made no significant changes to your security setup, you may wish to copy and paste the details from the previous year’s submission into the self-assessment questionnaire. You will still need to book your technical audit and wait for the report which may take up to five days.

If I have ISO 27001 certification, do I still need to Cyber Essentials Plus certification.

This will depend on your motivations for being certified, if you are asked to be Cyber Essentials Plus certified, an ISO 27001 certification although more comprehensive will not show that your security levels are up to the National Cyber Security Centre (NCSC) standards.

ISO 27001 is an international standard that provides specifications for an ISMS (Information Security Management System)–a systematic approach to managing information security risk. It goes considerably further than Cyber Essentials, but they are complementary to one another.

Do I need Cyber Essentials Plus to bid for Government contract?

Some government contracts may require you to be as a minimum Cyber Essentials certified, it is important that you seek clarification for each contract.

Who is IASME?

Cyber security firm IASME was chosen by the National Cyber Security Centre (NCSC) to take over full responsibility for Cyber Essentials delivery and become the Cyber Essentials Partner with the NCSC. The IASME Governance standard allows small companies in a supply chain to demonstrate their level of cyber security cost-effectively to show that they are taking the steps to properly protect their customers’ information.

I have a certificate issued under the previous scheme before 30 June 2020, when will it expire?

All certificates issued under the existing scheme before 30 June 2020, will be valid until 30 June 2021.

If certification is given by an Accreditation Body other than IASME, before 30 March 2020, will I need to be re-certified once IASME takes over the scheme on 1 April 2020?

All certificates issued prior to 1 April 2020 or before 30 June 2020 on the existing scheme are valid until 30 June 2021. This includes those issued by Accreditation Bodies other than IASME.

On 30 June 2021, any certificate issued under the old scheme will expire.

What support will I get during certification?

We understand that certification can appear daunting. Our experts are here to make sure that the process is as smooth as possible and that you gain maximum benefits.

To keep everything running smoothly, you’ll receive access to our e-learning course on Cyber Essentials which includes a suite of template materials that you can use to support your application.

Get a quote