Skip to contentAbout Fig Group
Independent technical verification

Cyber Essentials Plus certification

The Cyber Essentials Plus certification service for UK organisations, audited from £1,499 + VAT. Cyber Essentials Plus adds a third-party technical audit on top of Cyber Essentials, including external vulnerability scanning and sampled device checks.

Cyber Essentials Plus pricing

Priced by organisation size. These packages cover the Plus assessment and assume a valid Cyber Essentials certificate.

Cyber Essentials Plus

Third-party verified · 1-3 days

Micro

1-9 employees

£1,499+ VAT

One-off · no recurring fee

  • Independent Plus technical assessment
  • External vulnerability scan
  • Remote technical audit
  • 1-3 working days turnaround
Buy now

Medium

50-249 employees

£2,799+ VAT

One-off · no recurring fee

  • Independent Plus technical assessment
  • External vulnerability scan
  • Remote technical audit
  • 1-3 working days turnaround
Buy now

Large

250 - 9,999 employees

£4,499+ VAT

One-off · no recurring fee

  • Independent Plus technical assessment
  • External vulnerability scan
  • Remote technical audit
  • 1-3 working days turnaround
Buy now

What is audited in Cyber Essentials Plus

The Plus audit verifies your controls in the real environment.

  • External vulnerability scan of internet-facing assets.
  • Sampled device checks for secure configuration and malware protection.
  • MFA and user-access control verification.
  • Patch status and supported software checks.
  • Independent assessor evidence review and certification decision.

How to prepare for Cyber Essentials Plus

Plus is fastest when the baseline scope is already clear.

Cyber Essentials Plus is a verification exercise, not a last-minute paperwork task. Plan the audit with the same rigour as the baseline self-assessment so the assessor can move straight from scope review to control testing.

Have these ready before the audit

  • A valid Cyber Essentials baseline certificate covering the same organisation and scope.
  • A written scope statement listing in-scope users, devices, networks, and cloud services.
  • Sampled devices available for the assessor to test (representative across OS, role, location).
  • Permission to run the external vulnerability scan against your internet-facing services.
  • Evidence prepared for any remote workers, BYOD, multi-site, or hybrid cloud arrangements.

Common reasons applicants are delayed

  • Unsupported software still in production (legacy Windows, end-of-life browsers, EOL plugins).
  • Gaps in multi-factor authentication coverage on cloud, admin, or remote-access accounts.
  • Internet-facing services with high or critical vulnerabilities at scan time.
  • Sampled devices unavailable in the audit window or no remote-access agent installed.
  • Scope ambiguity around BYOD, contractors, or third-party managed assets.

Fig separates the baseline Cyber Essentials review from the Plus audit so applicants understand which issues block certification and which issues can be remediated during the process - no surprises mid-audit.

Cyber Essentials Plus FAQ

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds an independent technical audit with external vulnerability scanning and sampled device testing.

How long does Cyber Essentials Plus take?

Most assessments complete in 2 to 3 working days depending on availability of sampled devices and remediation turnaround.

Do I need a Cyber Essentials certificate before Plus?

Yes. Cyber Essentials Plus requires a valid Cyber Essentials baseline and then performs independent verification.

Is Plus required for UK procurement?

Some frameworks and enterprise buyers require Cyber Essentials Plus for higher-risk supplier contracts. Always confirm your bid requirement.

How much does Cyber Essentials Plus cost?

Fig Group prices Cyber Essentials Plus from £1,499 + VAT to £4,499 + VAT by organisation size.