Skip to main content
Validate your cyber hygiene with a hands-on independent technical audit.
Cyber Essentials Plus is the higher tier of the UK’s Cyber Essentials scheme. It covers the same five technical controls as Cyber Essentials but adds an independent, hands-on technical assessment — including vulnerability scans and tests — performed by a certified assessor.
Cyber Essentials Plus provides stronger assurance than the base certification because controls are independently tested rather than self-declared.

Who needs Cyber Essentials Plus?

Higher-assurance suppliers

Organizations needing to prove controls are not just declared but verified.

Government contractors

Contracts handling more sensitive information may require the Plus tier.

Key components

All five base controls

Firewalls, secure configuration, access control, malware protection, and patching.

Internal vulnerability scan

Authenticated scans of a sample of devices.

External vulnerability scan

Testing of internet-facing systems for vulnerabilities.

Assessor verification

Hands-on testing by an independent certified assessor.

How DSALTA helps with Cyber Essentials Plus

1

Activate Cyber Essentials Plus

Select Cyber Essentials Plus from the Frameworks page. DSALTA maps the five control areas.
2

Achieve base controls

Ensure all five Cyber Essentials controls are in place and evidenced.
3

Collect evidence automatically

Connect integrations to verify patching, malware protection, and configuration.
4

Remediate vulnerabilities

Use DSALTA’s vulnerability tracking to close gaps before the audit.
5

Pass the technical audit

Prepare for the assessor’s hands-on testing.

Frequently asked questions

You must hold or achieve Cyber Essentials certification as part of obtaining the Plus tier.
The assessor performs internal and external vulnerability scans and verifies the five controls on a sample of devices.