Cyber Essentials Plus Requirements 2026: Complete UK Guide

17 August 2026

Learn the exact Cyber Essentials Plus requirements for 2026. What's tested, how to prepare, and the cost for UK businesses.

What Is Cyber Essentials Plus?

Cyber Essentials Plus is a UK government-backed certification scheme managed by the National Cyber Security Centre (NCSC) and delivered by IASME. It builds on the standard Cyber Essentials self-assessment by adding independent validation and internal vulnerability scanning. For 2026, the requirements remain aligned with the five core technical controls: boundary firewalls, secure configuration, user access control, malware protection, and patch management. Certification demonstrates to clients and regulators that your organisation takes cyber security seriously. It's increasingly demanded in supply chains for public sector contracts and critical infrastructure. Achieving Cyber Essentials Plus signals that your systems have been technically verified, not just self-reported.

The Five Core Technical Controls

Cyber Essentials Plus requirements centre on five controls that every UK business must implement. First, boundary firewalls protect your internet connection and must be configured correctly to block unauthorised access. Second, secure configuration means default passwords are changed, unnecessary software is removed, and settings are hardened. Third, user access control ensures that only authorised individuals have administrative rights and access is limited per role. Fourth, malware protection requires anti-malware software, filters, and restrictions on removable media. Finally, patch management mandates that all devices and software are kept up to date with security patches. In the 2026 assessment, each control is verified through a combination of documentation, sample checks, and automated scanning.

The Independent Assessment Process

Unlike standard Cyber Essentials, where you complete a self-assessment questionnaire, Cyber Essentials Plus requires an external independent assessment. An IASME-approved assessor reviews your answers, inspects your systems, and performs a technical vulnerability scan. The scan covers all internet-facing IP addresses and internal devices, looking for known vulnerabilities, weak configurations, and missing patches. For 2026, the scan is conducted from the assessor's infrastructure and includes both external and internal testing. You need to provide evidence that your controls are in place and effective. The assessment typically takes one to two days, and after successful completion you receive a certificate valid for 12 months. The process is rigorous but manageable with proper preparation.

Differences Between Cyber Essentials and Plus

The main difference lies in verification. Cyber Essentials is a self-certified scheme; you fill out a questionnaire and upload evidence, with no hands-on technical testing. Cyber Essentials Plus, however, involves a physical audit of your systems by an external assessor. That means the requirements themselves are identical, but the assurance level is higher. In 2026, many UK government contracts now specify Cyber Essentials Plus as mandatory, especially for handling sensitive personal data or delivering services to central government. Additionally, Cyber Essentials Plus is often required by larger enterprises as part of their supply chain due diligence. Because the technical standards are the same, organisations that already pass Cyber Essentials typically need to fine-tune patching, user access, and device configuration before the Plus audit.

How to Achieve Certification

Start by completing the Cyber Essentials self-assessment to identify gaps. Then, fix any weaknesses in patch management, firewall rules, and user permissions. Before the external assessment, run an internal vulnerability scan using tools like Nessus or OpenVAS to uncover issues. Ensure all critical patches are applied within the 14-day limit set by the scheme. Prepare a clear list of all internet-facing IP addresses and internal devices. Purchase Cyber Essentials Plus through an IASME-approved certification body; they will guide you through the process. Expect the whole exercise to take four to six weeks from preparation to certification. Once achieved, review your systems quarterly to maintain standards and stay ready for re-certification, as the certificate expires after 12 months.

FAQ

Cyber Essentials is a self-assessment questionnaire that lets you certify your technical controls without independent verification. Cyber Essentials Plus adds an external audit and vulnerability scan performed by an IASME-approved assessor. The core requirements are the same, but Plus offers higher assurance because your systems are actually tested. For 2026, many UK contracts require Plus for access to sensitive data.

Latest guides