In order to achieve Cyber Essentials Plus, you must already be certified to Cyber Essentials. Gaining the extra qualification will also involve a technical expert conducting an on-site or remote audit on your IT systems, including a representative set of user devices, all Internet gateways and all servers with services accessible to unauthenticated Internet users.
The assessor will test a random sample of these systems, in line with the test specification, and then decide whether further testing is required. Having achieved Cyber Essentials, you have 3 months to apply for Cyber Essentials Plus.
If it is longer than 3 months, you will need to repeat the Cyber Essentials self-assessment questionnaire stage.

Cyber Essentials Questions Answered: Technical Requirements, BYOD Compliance and the Future of the Scheme
URM’s blog answers key questions about CE, focusing specifically on its technical requirements, use of BYOD, and how the scheme may change in the future.
URM’s blog answers key technical questions about Cyber Essentials and Cyber Essentials Plus, what’s in scope, CE compliant use of BYOD, and more.
URM’s blog discusses upcoming changes to Cyber Essentials, including the changes seen in the Willow Question Set and how they may impact your organisation.
URM’s blog offers advice on answering questions in the Cyber Essentials SAQ which relate to access control, admin accounts and authentication methods.

