Device sampling
An assessor tests a representative sample of your end-user devices and servers rather than accepting a declaration.
- Sampled endpoints
- Servers in scope
- Home-worker devices
The independently tested version of Cyber Essentials. Same five controls, but an assessor verifies them hands-on instead of taking your word for it.
The five technical controls are identical. What changes is how they are verified. Standard Cyber Essentials is a self-assessment questionnaire: you attest that the controls are in place. Cyber Essentials Plus adds an independent technical audit, where a qualified assessor tests a sample of your devices directly.
That audit typically includes an external vulnerability scan, an authenticated scan of sampled end-user devices and servers, and practical tests of whether malware protection and access controls behave as claimed. It is the difference between saying the controls work and demonstrating it.
You must hold valid standard Cyber Essentials before the Plus audit. The Plus assessment then has to follow within three months of that certification, so the order matters.
An assessor tests a representative sample of your end-user devices and servers rather than accepting a declaration.
External and authenticated internal scans looking for missing patches and exposed services.
Practical verification that anti-malware actually blocks what it should, on the devices your staff use.
Evidence that administrator rights are separated and controlled, not just described in a policy.
An audit is a poor time to discover a problem. We run the same tests internally first, checking the controls exactly as an assessor would, and fix whatever turns up. Then we book the assessment.
The most common causes of a failed Plus audit are mundane: a laptop that missed a patch cycle, an old admin account nobody disabled, software past its supported life, or a home worker's device that was never brought into scope. All of them are findable in advance.
Pre-audit testing and remediation, coordination of the independent assessment, and maintenance of the controls across the year.
Not sure which one your contract requires? Start with standard Cyber Essentials. It is a prerequisite for Plus in any case, so nothing is wasted. Broader security work is covered under cybersecurity.
How we work
Most security quotes begin with a conversation and end with a list of products you're asked to trust. Ours begins with a scan.
We built our own audit software, ShadowAudit, because the tools we could buy either cost more than our clients' entire IT budget or produced hundred-page reports nobody reads. It checks fifteen configuration controls on every Windows machine, finds the devices on your network that nobody remembers plugging in, and looks at your business from outside to see what the internet can reach.
Every finding carries the evidence that produced it. Not "your password policy is
weak" but net accounts: minimum length 0, and the setting that fixes it.
You can check our work, and so can anyone you hire after us.
First we look from outside. Before we visit, we scan what your business publishes to the internet from our own systems. Open ports, certificate problems, forgotten subdomains, mail records that let anyone send email as you. This is the half most firms have never had checked, and it's the half an attacker starts with.
Then we look from inside. On site, we check each Windows machine against the same fifteen controls: patching, encryption, firewall, antivirus, account policy, legacy protocols. We sweep the network and list every device on it. That list alone tends to produce a surprise or two.
Then you get a report you can act on. Findings ordered by what an attacker would use first, each with the fix, the effort involved, and what breaks if it's applied carelessly. Written for whoever signs things off, not for an engineer.
We do not touch a system without written authority. The free perimeter check takes one signed form. A paid audit takes three: the engagement letter, a scope schedule naming every machine we may look at and everything we may not, and a data processing agreement covering the personal data an audit inevitably sees.
All four are published on our downloads page, blank and in full. Read exactly what you would be agreeing to, and what we are promising not to do, before you speak to anyone here.
Read the case study: 1,241 password attempts in a day on our own server
| What | Price | What you get |
|---|---|---|
| Perimeter check | Free | What the internet can reach on your domain and public address. Remote, no visit, no obligation. You get the findings whether or not you hire us. |
| Full audit | £450 to £650 | Everything above, plus every Windows machine checked on site, a device inventory, and the written report. |
| Cyber Essentials readiness | £650 to £950 | The full audit mapped to the five controls, with a pass or fail against each and the work needed to close the gaps. |
| Managed Cyber Essentials | £99 per client, per month | Gap assessment, the remediation work, the submission itself, and keeping the controls in place between renewals. |
Prices exclude VAT. The IASME certification fee is set by the scheme and paid separately, from £300 + VAT depending on your size. We're not a certification body, so that fee never comes to us.
Worth being straight about, because plenty of firms aren't.
It isn't a penetration test. Nothing we run exploits anything, guesses a password or tries to break in. It's a configuration and exposure audit. If you need someone to actively attack your systems, that's a different engagement with a signed scope, and we'll tell you so rather than dress this up as one.
The Cyber Essentials mapping is readiness, not certification. We tell you whether you'd pass. The certificate is issued by an IASME-accredited body once the questionnaire goes in, and we handle that submission for you.
It won't find everything. Nothing does. It checks Windows machines properly and treats printers, phones and network kit as devices with open ports rather than auditing them internally. We say that in every report rather than letting a clean page imply more than it should.
Yes. Plus builds on it, and the Plus assessment must take place within three months of your standard certification. We normally run them as one continuous piece of work.
£1,755 per year with us, covering pre-audit testing, remediation, coordination of the independent assessment and keeping the controls maintained through the year. Assessment-body fees vary with the size and complexity of your estate.
Modest. The assessor needs access to a sample of devices for testing and some time with whoever administers your systems. The preparation beforehand takes considerably longer than the audit itself.
There is normally an opportunity to remediate and retest within a defined window rather than starting over. This is exactly why we run the tests ourselves first.
If a contract or insurer specifically asks for Plus, you have no choice. Otherwise it is a judgement call. Plus is stronger evidence because it is tested rather than asserted, and some buyers treat it that way.
Tell us about your setup and we'll come back within one business day with a free, no-obligation IT health check.