Book FREE Consultation

URM is pleased to provide a FREE 30 minute consultation on Transitioning to ISO 27001:2022 for any UK-based organisation. Once an enquiry form has been submitted, we will be in touch to understand the nature of your enquiry and to book a mutually convenient time for a 30-minute consultation slot with one of URM’s specialists.

Cyber Essentials PLUS Assured

Achieve Cyber Essentials and Cyber Essentials Plus certification with our team of qualified experts.

Speak to a certified advisor

URM is an accredited Assured Service Provider under the NCSC Cyber Advisor scheme. We are able to provide you with practical, cost effective and reliable advice to improve your cyber security and achieve  ‘Cyber Essentials’ and ‘Cyber Essentials Plus’ certifications.

Speak to one of our experts for more information on how we can help you certify. Simply call 0118 206 5410 or request a call back using the form below.

Cyber Essentials PLUS Assured

This is our recommended route if you want the smoothest path to Cyber Essentials (CE) and Cyber Essentials PLUS (CE+) certification, supported by ongoing compliance assurance.

It includes targeted advisory support and key activities focused on areas that, based on our assessors’ experience, most commonly create challenges during assessment.  It also provides ongoing monthly scanning to help you maintain compliance, together with enhanced scanning during the CE+ assessment process.

This offering includes Cyber Essentials Assured, 1 year of access to the Abriska CE+ module, a half-day sample-based CE+ pre assessment, the formal CE+ assessment, and 1 included retest within the NCSC remediation window in line with the Danzell scheme’s remediation process, plus:

  • An additional half day of ad hoc advisory time
  • Additional scans in the 3 days immediately preceding the CE+ assessment
  • Daily internal vulnerability scans (on all assets) if the initial assessment is not successful
  • Unlimited CE+ certification attempts* within 3 months of your CE certification date.

Because this offering includes Cyber Essentials Assured, your journey includes both the initial  scoping workshop and the Technical Scope Verification where evidence will be captured.  This ensures your certification scope is defined fully and accurately before the CE submission is finalised and that any issues likely to cause problems later in the certification journey are identified as early as possible.

* If additional retests are as a result of a scope change or the same vulnerabilities are identified and not addressed or URM’s advice and guidance is not followed then charges may apply.  Please note that once you have undertaken a CE+ assessment you have 30 days to remediate all issues and for there to be a retest including a second sample.

Abriska CE+ Module (Assured)

Your 1 year access to the Abriska CE+ module (Assured) provides:

  • Monthly compliance scans of all external IP addresses in scope for CE
  • Monthly compliance scans of all servers and end user devices in scope**
  • An interactive view of the assets and vulnerabilities that could cause a compliance failure
  • Actionable recommendations aligned to CE and CE + requirements
  • 1 daily authenticated internal Qualys scan of all assets in the 3 working days prior to the official CE+ assessment
  • 1 daily authenticated internal vulnerability scan of all assets if the initial CE+ assessment is not successful until the scheduled retest date within the NCSC remediation window.

** You are responsible for ensuring all in scope devices are correctly enrolled. URM can only provide scan results for devices that have been correctly enrolled

CE+ Pre Assessment and Advisory Support

A sample-based CE+ pre assessment is typically scheduled within the 2 weeks prior to your official CE+ assessment.  This pre assessment tests a small, representative sample of your devices, identifies likely failure points before the formal assessment, and provides initial advice on any issues identified.

In addition, half a day of advisory time is included.  This can be used to review pre assessment findings, discuss required remediation actions, answer questions, or provide targeted advice ahead of the formal CE+ assessment.

To provide further assurance immediately before the official CE+ assessment, this offering also includes daily internal vulnerability scans for all in scope devices during the 3 working days prior to assessment.  This allows compliance to be monitored in the days preceding the assessment and avoids any unforeseen issues.

Technical Scope Verification (TSV)

In most cases, the Technical Scope Verification is conducted separately from the CE+ assessment and must be passed at least seven working days before the assessment start date.  For this Cyber Essentials PLUS Assured offering, the TSV is typically conducted as part of the review included within Cyber Essentials Assured.

This approach significantly reduces the risk of booking CE+ assessment time that cannot be used due to issues with the declared scope.  Any factors that could prevent a successful CE+ assessment are identified and addressed early in the process.

For some small or micro-organisations (e.g., where the whole organisation is in scope and only a very small number of devices are involved) it may be possible to agree that the TSV is performed at the start of the CE+ assessment rather than as a separate activity in advance.***

*** Performing the TSV on the day of the CE+ assessment may reduce cost and administrative effort, but it increases risk.  If issues are identified that cannot be immediately resolved, the CE+ assessment time will need to be either repositioned as advisory activity or postponed, and postponement charges will apply. By choosing this option, you acknowledge that passing the TSV is a prerequisite for proceeding with the formal CE+ assessment and that this approach carries a higher risk.

Retests And Certification Attempts

If the CE+ assessment identifies failing items or vulnerabilities that have not been addressed, URM will perform 1 retest in line with the Danzell scheme’s remediation process.

If the initial CE+ assessment is unsuccessful due to vulnerabilities identified through authenticated scanning, adopting this route will enable you to monitor compliance of all your assets via the daily vulnerability scans included immediately ahead of your retest.

You should be aware that under the Danzell remediation rules, if the retest using a second sample set fails due to the same vulnerabilities, your CE certificate will be revoked and the whole CE and CE+ process will need to be restarted.

URM were excellent from the start- very responsive to the initial enquiry and proactive throughout the process of achieving our first Cyber Essentials. We had a pressing deadline and they worked hard to help us get there in time, offering salient advice that made the whole process smoother. Knowing that we have an easier route to renewal via their portal is also a big plus. Thanks again to the whole team.
Space operations software developer
Request Cyber Essentials review

Client Feedback

Trainer:
/
5
Course:
/
5
Having never gone through the Cyber Essentials Plus process on behalf of a client I was very impressed with how the process went on testing day and I can't wait to take other clients through the process with URM.
Client

Support request

If you are interested in URM’s support, please specify the subject in the form below.

Please note, we can only process business email addresses.

Why URM?

As an accredited certification body, URM has an unrivalled record in assisting organisations of all sizes achieve certification to Cyber Essentials and Cyber Essentials Plus. URM is also an accredited Assured Service Provider under the NCSC Cyber Advisor scheme  and  has a large team of experienced, pragmatic assessors who are here to support you and guide you through the process.

Not only do we bring a wealth of cyber security knowledge, but also a wide and varied experience of all the leading cyber and information security standards.

As such, you can be assured that you are getting advice that is right for you and your organisation, taking into account your sector, size and the information you are looking to protect. Our large team of assessors also enables us to guarantee a super-fast turnaround.

One of the great things about Cyber Essentials is that it is a targetable standard, so you always know exactly where you are.
Charity
Information Security FAQISO 27001 FAQ
URM have been consistently helpful, friendly and efficient in assisting us through the Cyber Essentials and Cyber Essentials Plus accreditation process.
AI solutions provider

Cyber Essentials Update 2026

Published on
26/3/2026

URM’s blog breaks down key changes to the Cyber Essentials scheme coming into force on 27 April 2026, including the new Danzell Question Set.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
10/3/2026
Cyber Security and the Board: A Sign of What’s to Come

URM’s blog explains recent amendments to the Cyber Security and Resilience Bill, how they align with broader regulatory shifts, & practical steps to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
12/2/2026
NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/1/2026
Minimising the Impact When a Breach Occurs

URM’s blog explores the importance of cyber resilience & the steps organisations can take to prepare for and mitigate the impact of a cyber incident.

Read more
"
I thought the training was very good. It was clear and logical. The trainer was very knowledgeable, approachable and friendly, which makes it easy to stop and ask questions or to clarify a point. I was particularly impressed by his explanation of why we need to be mindful of the language we use and what the standard is actually asking for; most of it is common sense, but understanding what it actually means and what is required is key, so that really resonated with me.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.