> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cyber Essentials Plus

> Validate your cyber hygiene with a hands-on independent technical audit.

> Validate your cyber hygiene with a hands-on independent technical audit.

Cyber Essentials Plus is the higher tier of the UK's Cyber Essentials scheme. It covers the same five technical controls as Cyber Essentials but adds an independent, hands-on technical assessment — including vulnerability scans and tests — performed by a certified assessor.

<Note>
  Cyber Essentials Plus provides stronger assurance than the base certification because controls are independently tested rather than self-declared.
</Note>

## Who needs Cyber Essentials Plus?

<CardGroup cols={2}>
  <Card title="Higher-assurance suppliers" icon="shield-halved">
    Organizations needing to prove controls are not just declared but verified.
  </Card>

  <Card title="Government contractors" icon="flag">
    Contracts handling more sensitive information may require the Plus tier.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="All five base controls" icon="list-check">
    Firewalls, secure configuration, access control, malware protection, and patching.
  </Card>

  <Card title="Internal vulnerability scan" icon="magnifying-glass">
    Authenticated scans of a sample of devices.
  </Card>

  <Card title="External vulnerability scan" icon="globe">
    Testing of internet-facing systems for vulnerabilities.
  </Card>

  <Card title="Assessor verification" icon="user-tie">
    Hands-on testing by an independent certified assessor.
  </Card>
</CardGroup>

## How DSALTA helps with Cyber Essentials Plus

<Steps>
  <Step title="Activate Cyber Essentials Plus">
    Select Cyber Essentials Plus from the Frameworks page. DSALTA maps the five control areas.
  </Step>

  <Step title="Achieve base controls">
    Ensure all five Cyber Essentials controls are in place and evidenced.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to verify patching, malware protection, and configuration.
  </Step>

  <Step title="Remediate vulnerabilities">
    Use DSALTA's vulnerability tracking to close gaps before the audit.
  </Step>

  <Step title="Pass the technical audit">
    Prepare for the assessor's hands-on testing.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Do I need base Cyber Essentials first?" icon="list-ol">
    You must hold or achieve Cyber Essentials certification as part of obtaining the Plus tier.
  </Accordion>

  <Accordion title="What does the assessor test?" icon="vial">
    The assessor performs internal and external vulnerability scans and verifies the five controls on a sample of devices.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
