Cyber Essentials Plus Readiness ยท Audit-Grade Checks

Cyber Essentials Plus Readiness Check: would you survive the hands-on audit?

Would you pass the Cyber Essentials Plus hands-on audit? Free UK check covering vulnerability scanning, patching, MFA and access controls. Results in minutes.

Frequently asked questions

What is a cyber essentials plus readiness check and why does my organisation need one?

Cyber Essentials Plus covers the same five controls as Cyber Essentials (firewalls, secure configuration, user access control, malware protection and security update management), but an assessor verifies them hands-on through external vulnerability scans and an authenticated test of a sample of your devices. This tool walks you through each requirement and flags where you are likely to fail the audit.

How much does Cyber Essentials Plus cost?

Certification fees vary by assessor and the size of your estate, and the bigger cost is usually the remediation work needed to pass. This readiness check is free and shows you that remediation list first, so you only book the paid audit when you are genuinely ready and not paying twice.

What is checked in the Cyber Essentials Plus audit?

The assessor runs an external vulnerability scan, then an internal authenticated scan on a representative sample of devices, checks that malware protection and account separation work, and confirms high and critical updates are applied within 14 days. Most failures come from missed updates, leftover local admin rights and unmanaged devices. This tool tests against those same checks.

What is Cyber Essentials Plus?

Cyber Essentials Plus is the independently audited version of Cyber Essentials. An IASME-licensed certification body performs hands-on technical testing of your IT systems to verify that the controls you described in the self-assessment questionnaire actually work in practice. It tests the same five themes: firewalls, secure configuration, security update management, user access control, and malware protection.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment: you answer questions and an assessor reviews your answers. Cyber Essentials Plus adds hands-on technical testing by an independent auditor. The same five themes are tested but the auditor verifies the controls on your real systems, which is where the gap between what organisations believe and what an auditor finds tends to emerge.

Why do organisations fail the Plus audit even when they have basic Cyber Essentials?

Because self-assessment and technical testing reveal different things. Secure configuration alone accounts for roughly 40% of Plus failures: organisations believe devices are configured correctly, but audit testing finds exceptions, legacy devices out of policy, or controls that work in principle but not for every machine in scope. The Plus audit is designed to find exactly those gaps.

Is a PASS on this tool the same as the real certificate?

No. This is a readiness signal, not a certificate. Cyber Essentials Plus certification comes only through an IASME-licensed certification body. A PASS prediction here means your self-assessed answers, including the audit-grade checks, are consistent with passing the technical testing. It is the honest picture before you commission the audit.

What do you get?

You answer across the five themes, including the additional audit-grade checks, and receive a pass or fail prediction at theme level, the exact findings an auditor would write up for every non-pass answer, and a prioritised remediation list.

Who should complete this assessment?

Ideally the person who knows your IT estate in detail, not just believes it. That may be your IT manager, your outsourced support provider working with you, or your internal IT lead. The audit-grade checks require honest answers about patch state, device lists, and MFA coverage across the whole scope.