Cyber Essentials Plus is the same five controls as Cyber Essentials, checked by somebody else. That is the whole distinction: the basic certification is a self-assessment that IASME verifies, while Cyber Essentials Plus adds independent technical testing of whether the controls you claimed actually work on your machines.
The 2026 update — requirements version 3.3, question set “Danzell” — changed both the questions and the way retesting works, and it introduced auto-fail conditions that catch organizations who were previously getting through on good intentions. This guide covers what the audit involves, what changed in 2026, and how to prepare.

What Cyber Essentials Plus tests
Both levels assess the same five technical controls, defined by the NCSC:
- Firewalls — a security filter between the internet and your network.
- Secure configuration — computers set up to minimize the ways in.
- Security update management — vulnerabilities patched before they are used as an entry point.
- User access control — who can reach what, and at what level of privilege.
- Malware protection — malicious software identified and stopped before it does harm.
Cyber Essentials Plus takes those claims and tests them. An assessor samples devices from your estate, runs vulnerability scanning against them, checks that malware protection behaves as claimed when it meets something it should block, and verifies that account and access configuration matches the answers you gave. The sample is the point — you cannot prepare a single laptop and pass.
The audit also has a hard prerequisite: your basic Cyber Essentials certificate must be no more than three months old when the Plus assessment is carried out. Past that, IASME treats the self-assessment as potentially stale and the basic certification has to be redone first. In practice the two should be planned as one project with the Plus audit booked before the basic assessment is submitted.
What changed for Cyber Essentials Plus in 2026
IASME and the NCSC published the Danzell question set on 13 February 2026, alongside requirements version 3.3, and it became mandatory for new assessment accounts from April 2026. Accounts created before that date were given six months to certify under the previous version. The five controls did not change. The evidence bar did.
Multi-factor authentication is now an auto-fail
MFA is mandatory for all cloud services where it is available — whether it comes free, included in your licence, or as a paid option. An organization that has not enabled MFA for all users and administrators fails automatically. “Our tier doesn’t include it” stopped being an answer.
Two new update questions, both auto-fail
Questions A6.4 and A6.5 require high-risk or critical security updates to be installed within fourteen days, across operating systems, firmware and applications. Firmware is the one that catches people: routers, switches and access points are in scope and are rarely on anyone’s patch schedule.
Cloud services cannot be scoped out
Danzell added a definition — an on-demand, scalable service hosted on shared infrastructure and accessible over the internet — and made clear those services cannot be excluded from scope. Alongside it, scope descriptions have to be fuller: out-of-scope areas of the infrastructure must be documented rather than left unmentioned, and the legal entities in scope must be named with addresses and company numbers.
Retesting got stricter
Three changes matter to anyone who has previously scraped through a retest. Retesting now includes a new random sample of devices rather than only the ones that failed, which stops the practice of fixing the tested machines. Self-assessment responses cannot be adjusted once Cyber Essentials Plus testing has begun. And a second retest failure results in the certificate being revoked.
Preparing for a Cyber Essentials Plus audit
The preparation that works is a rehearsal, not a document review.
- Build the asset list first. Every device that connects, including personally owned devices used for work and every cloud service in use. The scope description is now detailed enough that a vague inventory shows.
- Scan yourself. Run an authenticated vulnerability scan across a random sample of devices and look for anything rated high or critical that is older than fourteen days. This is the single most common reason for failure and it is entirely findable in advance.
- Check MFA coverage service by service. Not policy-by-policy. Enumerate the cloud services, confirm MFA is enabled for every user and every administrator, and note where it is enforced rather than merely available.
- Look at firmware. Network equipment, printers and anything else with an update channel nobody owns.
- Remove what you no longer use. Unsupported operating systems, forgotten test servers and leavers’ accounts are cheaper to delete than to explain.
- Fix before you submit. Once Plus testing starts, your self-assessment answers are frozen.
Is Cyber Essentials Plus worth it?
Two reasons say yes. The first is contractual — UK central government contracts involving handling personal information or providing certain ICT services require it, and it increasingly appears in private-sector supply chain requirements. The second is that the audit tells you something true. A self-assessment tells you what you believe about your estate; the Plus test tells you what is actually on the machines, which is regularly a different story.
The honest counter-argument is that Cyber Essentials Plus is a point-in-time check of a small control set, valid for a year. It is a floor, not a security program, and it does not attempt to be one. If your customers are asking for evidence of a managed information security program rather than a baseline, ISO 27001 answers a different question — and the two sit together comfortably, because the five controls are a subset of what an ISMS already governs.
Frequently asked questions
What is the difference between Cyber Essentials and Cyber Essentials Plus?
The controls are identical. Cyber Essentials is a self-assessment that is verified; Cyber Essentials Plus adds independent technical testing of a sample of your devices and services.
How long do we have between the two?
The Plus audit must follow within three months of the basic certification. After that the basic assessment has to be repeated.
What causes an automatic failure?
Under the 2026 requirements, missing MFA on cloud services where it is available, and failing the new security update questions A6.4 and A6.5, which require high-risk and critical updates within fourteen days across operating systems, firmware and applications.
Can we exclude part of the business?
You can certify a defined subset, but the scope has to be described in detail, out-of-scope infrastructure has to be documented, and the legal entities included must be named. Cloud services in use cannot be excluded.
How long is certification valid?
Twelve months, after which you recertify — against whichever requirements version is current at that point.
Where this leaves you
Cyber Essentials Plus in 2026 rewards organizations that maintain their estate and punishes those that prepare for the audit. Get the asset list right, scan a random sample yourself against the fourteen-day rule, enumerate MFA service by service, and book the Plus audit inside the three-month window from the basic certificate. The auto-fail conditions are published in advance, which means every one of them is avoidable.
References
- IASME — Changes to Cyber Essentials for April 2026 — requirements v3.3, the Danzell question set, and the new auto-fail questions.
- NCSC — Cyber Essentials overview — the five technical controls and what Plus adds.
More on UK cyber certification
- Cyber Essentials Plus — you are here
- Cyber Essentials certification explained
- Running an ISO 27001 gap analysis
- Phishing-resistant MFA
Scope documents, policies and evidence templates are in the Cyber Essentials UK Toolkit, or start with the free ISO templates.