top of page
Cyber Essentials Certified

Cyber Essentials Plus Certification in Devon and the UK

Cyber Essentials Plus is the independently audited level of the UK government's Cyber Essentials scheme. Where the standard Cyber Essentials certification is based on a self-assessment questionnaire, CE+ goes further: a qualified assessor uses NCSC-approved tools to physically verify that your security controls are in place and working on your actual systems.

Regola is a licensed Certification Body based in Torquay. We support businesses across Devon, the South West, and the wider UK through the full CE+ process.

✓ Pricing quoted individually based on your network size and complexity
✓ Devon-based licensed Certification Body 
✓ Independent technical audit of your live systems
✓ Stronger assurance for contracts, tenders, and supply chains

What is Cyber Essentials Plus?

Cyber Essentials Plus builds directly on the standard Cyber Essentials certification. The technical requirements are exactly the same. What changes is the level of assurance.

  • With standard Cyber Essentials, a qualified assessor reviews your self-assessment answers and checks that they meet the scheme requirements. With CE+, an assessor goes further by independently testing your systems using approved vulnerability scanning tools. They verify that the controls you declared are actually implemented, not just described on a form.

  • The audit covers a representative set of user devices, all internet gateways, and all servers with services accessible to the internet. The assessor also checks that MFA is in place for cloud services on sampled devices, that screen lock policies are active, and that users on standard accounts cannot perform administrator functions.

  • It is also worth noting that the pass bar is set to a slightly higher level for Cyber Essentials Plus. Whereas it is possible to pass the Cyber Essentials verified self-assessment with one or two non-compliances, these must be fully remediated before CE+ can be passed.

In short: Cyber Essentials says you take security seriously. Cyber Essentials Plus proves it.

Why Businesses Choose Cyber Essentials Plus

Win Government Contracts and Tenders

Cyber Essentials is required for many UK government contracts. CE+ is increasingly specified for contracts involving sensitive or personal data, or where a higher standard of assurance is expected. Having CE+ in place means you can respond to more tenders with confidence.

Higher Assurance for Regulated Sectors

If your organisation works in legal, financial, healthcare, or public sector supply chains, CE+ gives procurement and compliance teams a verifiable independent audit rather than a self-completed questionnaire.

Demonstrate Stronger Security to Clients and Partners

A CE+ badge is verified independently, not self-declared. For clients who want proof that your controls actually work, not just a promise that they do, that distinction matters. It is particularly valued in supply chain due diligence and enterprise vendor onboarding.

Build on What You Already Have

If you hold Cyber Essentials, CE+ is a natural next step. The same five technical controls apply, so there is no need to start from scratch. You simply need to complete the CE+ audit within three months of your Cyber Essentials certificate being issued.

What Does the CE+ Audit Actually Involve?

The Cyber Essentials Plus audit is carried out by a qualified assessor from a licensed Certification Body. It can be conducted on-site or remotely, and covers the following:

 

​External vulnerability scan: The assessor runs an unauthenticated scan against each of your public-facing IP addresses. This checks for open ports, visible vulnerabilities, and missing patches that could be exploited from outside your network. Anything with a CVSS score of 7.0 or higher on an internet-facing system is an automatic failure.

Internal device testing: The assessor will test a suitable random sample of systems (typically around 10 per cent) and then make a decision whether further testing is required. The sample covers servers, desktop computers, laptops, tablets, and mobile phones. Each type of operating system in your environment must be represented.

Malware protection testing: The assessor sends sample phishing emails and test files to check whether your malware protection is catching and blocking them before they can be opened or executed.

User access and MFA checks: The auditor asks each user from every sampled device to confirm they cannot carry out administrator functions on their standard user accounts, and checks that a multi-factor authentication challenge is presented when logging on to all cloud services used.

Patch and update compliance: An authenticated vulnerability scan checks sampled devices for missing patches. All high or critical security updates must have been applied within 14 days of release. Unsupported software in scope is an automatic failure.

The audit does not require any changes to your answers after the CE+ testing has begun. From April 2026, organisations are no longer allowed to adjust their verified self-assessment responses based on the results of the CE+ assessment.

The CE+ Certification Process, Step by Step

Step 1: Achieve Cyber Essentials CE+ requires a valid Cyber Essentials certificate. If you do not yet hold one, Regola can guide you through the standard certification first. Find out more about Cyber Essentials.

Step 2: Book your CE+ audit quickly CE+ must be completed within 3 months of your Cyber Essentials certification date. Miss that window and you need to recertify Basic first. The clock starts the day your CE certificate is issued, so it is worth planning ahead and not leaving the plus audit until later.

 

Step 3: Assessor confirms scope and sample Regola confirms the scope of your CE+ assessment (which must match the scope of your Cyber Essentials certificate) and works out the device sample using the IASME sampling methodology. The sample is declared to IASME at least 72 hours before testing begins.

 

Step 4: Technical audit The assessor conducts external and internal vulnerability scans, malware protection tests, and user access checks across the sampled devices. The audit can be run remotely or on-site.

 

Step 5: Findings and remediation If issues are found, you will receive clear feedback. If an organisation fails the initial test of a random sample of devices for update management, they will be required to remediate the issues and undergo a retest, during which the assessor will also test a new random sample of devices. You will not be asked to just fix the devices that were tested.

 

Step 6: Certification Once all tests pass, your Cyber Essentials Plus certificate is issued through the IASME portal. It is valid for 12 months and appears on the public IASME register. You receive the CE+ badge for your website and marketing materials.

How Much Does Cyber Essentials Cost?

From £1600 + VAT
(Contact us for a fixed quote)

CE+ is priced individually based on the size and complexity of your network. Unlike standard Cyber Essentials, there is no fixed price band. The assessor time required to run external and internal scans, test a representative sample of devices, and check user access across the environment means the cost varies depending on what is in scope.

Regola will give you a clear quote once we understand your infrastructure. To get a quote, contact us with a brief summary of your network: how many devices are in scope, what operating systems you use, and whether the assessment would need to be on-site or remote.

Why Choose Regola for Cyber Essentials Plus?

Regola is a Torquay-based licensed Certification Body working with businesses across Devon, the South West, and the UK. Richard Henson, who leads our assessments, brings deep technical knowledge of the scheme and a clear, plain-English approach to explaining findings.

We work with you before the audit, not just during it. If you are unsure whether your current controls will hold up to scrutiny, we can help you identify gaps before the formal assessment starts, so the audit is less likely to produce surprises.

Our assessments can be run remotely or, for Devon and South West clients, in person at your site.

Frequently Asked Questions about Cyber Essentials Plus

Ready to take the next step?

If you hold Cyber Essentials and want to move to the independently audited level, or if you are starting from scratch and want both certifications, speak to Regola.

 

We are based in Torquay and support organisations across Devon, the South West, and the UK.

bottom of page