Ready for the Cyber Essentials Plus audit?
Plus adds an independent technical audit on top of the standard self-assessment, internal and external vulnerability scans, verified by a certified assessor. Most businesses that fail do so on things a readiness review would have caught in advance.
External + internal scan
Both required, run by a certified assessor.
Assessor-verified
Not self-assessed. Independently checked.
Often contract-required
Common ask for NHS & public sector work.
Plus is the higher tier of Cyber Essentials: everything in the standard self-assessment, plus a hands-on technical audit. An external vulnerability scan checks how your organisation looks from the internet; an internal scan (usually via a sample of devices) checks your build standard. Where the standard check tells you where the gaps probably are, Plus readiness prep is about making sure nothing gets found on the day.
What a readiness call covers
A walkthrough of your current setup against the Plus test specification, what a certified assessor will actually check, and where businesses in your position usually get caught out.