Skip to content
Pentesys
Assure

CyberEssentialsPluscertification,preparedandpassedfirsttime

Technical audit preparation, pre-assessment verification and evidence management so your Cyber Essentials Plus audit is a formality.

Cyber Essentials Plus adds independent technical testing to the self-assessed Cyber Essentials questionnaire. Many organisations fail because they assume the self-assessment is enough, or because a sample of devices fails on audit day.

We prepare you thoroughly: technical checks against the same five controls, sampled device testing, vulnerability scans and a complete evidence pack. By the time the auditor arrives, every control has been verified and documented in the Mirage Portal.

Capabilities

What's included in Cyber Essentials Plus

Everything below is delivered and tracked through the Mirage Portal.

Pre-audit technical verification

We run the same checks an auditor will run — malware tests, patch status, secure config, access control and firewall review — before audit day.

Sampled device testing

A representative sample of workstations, servers and mobile devices is tested to surface issues that could cause a fail.

Vulnerability and patch review

Internet-facing and internal systems are checked for unsupported software and unpatched vulnerabilities within the required windows.

Evidence pack production

Screenshots, exports and policy documents are collected, versioned and stored ready for the auditor.

Remediation support

Any gaps are fixed with clear guidance, then re-verified before the audit.

Audit liaison

We support the audit itself, answer technical questions and provide additional evidence if the auditor asks for it.

Coverage

Scope and depth

Plus-specific checks

  • Malware protection effectiveness testing
  • Patch and update management verification
  • Secure configuration review of sampled devices
  • User access control and MFA checks
  • Firewall and boundary review
  • Scope and boundary confirmation

Deliverables

  • Pre-audit technical verification report
  • Sampled device test results
  • Evidence pack for the auditor
  • Remediation plan and closure evidence
  • Audit-day support
  • Certificate and renewal calendar
Pricing

Cyber Essentials Plus fixed-fee pricing

Priced by organisation size. Credits are rounded up to the nearest whole credit at £125 each, and prices exclude UK VAT.

Organisation sizeCreditsCost
Micro (0-9 Employees)12£1,500
Small (10-49 Employees)21£2,625
Medium (50-249 Employees)23£2,875
Large (250+ Employees)34£4,250
See full pricing and bundles
How it works

Our delivery process

A consistent, transparent methodology from first conversation to verified remediation.

  1. 01

    Scope

    We confirm the certification boundary and select representative devices for testing.

  2. 02

    Verify

    Technical checks mirror the audit process across all five control areas.

  3. 03

    Remediate

    Gaps are fixed and re-tested so nothing fails on the day.

  4. 04

    Evidence

    The evidence pack is completed and stored in the portal for auditor review.

  5. 05

    Audit

    We support the audit and confirm certification, then schedule renewal activity.

What you receive

  • Pre-audit technical verification report
  • Sampled device test results
  • Audit-ready evidence pack
  • Remediation closure evidence
  • Audit support and certification confirmation
  • Renewal planning and monitoring

Business outcomes

  • First-time Cyber Essentials Plus certification
  • No surprises or last-minute remediation on audit day
  • Clear evidence trail for auditors and customers
  • Straightforward renewal year after year
FAQs

Common questions

Do we need Cyber Essentials first?

Yes. Cyber Essentials Plus requires the self-assessment questionnaire to be completed and verified before the technical audit.

How many devices are tested?

The auditor samples a representative set. We test a similar sample in advance so issues are found early.

What if we fail the pre-audit checks?

We work with you to remediate and re-test before the audit, so you go into certification with confidence.

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.