In order to achieve Cyber Essentials Plus, you must already be certified to Cyber Essentials. Gaining the extra qualification will also involve a technical expert conducting an on-site or remote audit on your IT systems, including a representative set of user devices, all Internet gateways and all servers with services accessible to unauthenticated Internet users.
The assessor will test a random sample of these systems, in line with the test specification, and then decide whether further testing is required. Having achieved Cyber Essentials, you have 3 months to apply for Cyber Essentials Plus.
If it is longer than 3 months, you will need to repeat the Cyber Essentials self-assessment questionnaire stage.

Cyber Security Case Study: The Human and Organisational Cost of a Breach
URM’s blog shares a Managing Director’s account of navigating & recovering from a major cyber attack, with a focus on the human impact of the breach.
URM’s blog breaks down the latest changes to the Cyber Essentials requirements and outlines why these updates matter for organisations seeking certification.
URM’s blog explores the different forms of phishing attacks, the strategies used to exploit human vulnerabilities, & how to protect against these attacks.
URM’s blog breaks down the new EU Cyber Resilience Act, what products/entities are in scope, the security requirements it imposes on organisations, and more.

