Cyber Essentials Plus

We assess Cyber Essentials Plus from late October 2026. Slots are open to book now, and your Cyber Essentials can be certified with us this week so you go straight into the audit.

Solusec is Cyber Essentials Plus certified

Cyber Essentials Plus is the hands-on, technically audited step up from Cyber Essentials. We assess it from late October 2026, and slots are open to book now.

What Cyber Essentials Plus is

Where Cyber Essentials is a verified self-assessment, Cyber Essentials Plus adds an independent technical audit. An assessor tests a sample of your devices, your email and web browsing, and your cloud services, to confirm the five controls are genuinely in place rather than genuinely described. It is the level of assurance larger contracts, public-sector buyers and a growing number of insurers now ask for by name.

Our dates

We are an appointed IASME Certification Body for Cyber Essentials and IASME Cyber Assurance today, and we assess Cyber Essentials Plus from late October 2026. That is a date rather than an aspiration, which is why this page has one.

If your deadline falls before then, say so and we will tell you straight away whether we can help or whether you need another assessor. We would rather lose the booking than lose you the contract.

Book an October slot →

What to do between now and October

The waiting is not dead time. Three things make the difference between a Plus audit that passes first time and one that does not, and all three can be done now:

  1. Get Cyber Essentials certified. It is a prerequisite for Plus and the certificate has to be under three months old when the Plus audit starts. We certify it today.
  2. Fix what the audit will actually test. Unsupported operating systems, missing patches beyond fourteen days, local administrator accounts used for daily work, and multi-factor authentication missing from a cloud service. These are what fail people, and none of them are a surprise.
  3. Settle your scope. Which devices, which cloud services, which people work from home on their own hardware. Scope arguments on audit day are the other reason a Plus assessment overruns.

Who does the audit

A Cyber Essentials Plus audit is a technical exercise, not a paperwork exercise. It is carried out here by Daly Whyte, who holds OSCP, OSWE, CRT and CISSP and works as a CREST-certified penetration tester, which means the person testing whether your controls hold is someone who spends the rest of the week getting past controls for a living. The full credentials are published, which is not universally true in this market.

Testing and certification from one place

Most organisations that need Cyber Essentials Plus also need a penetration test, usually for the same contract or the same insurer. We are a CREST-accredited testing provider and a certification body, so both can come from one engagement with one scope conversation and one point of contact. See how the testing side works.

Book your Cyber Essentials Plus slot

Tell us about your estate and we will confirm a date and a fixed price. We assess and certify directly as an appointed IASME Certification Body, so there are no handoffs to a third party.

Your details are handled by a real person, never fed into AI.

Common questions

When can Solusec assess Cyber Essentials Plus?

From late October 2026. We are an appointed IASME Certification Body for Cyber Essentials and IASME Cyber Assurance now, and Cyber Essentials Plus is being added to that scope for late October. You can book an audit slot before then.

Can I book a Plus audit before October?

Yes. Book the slot now and we will hold the date. The work that has to happen first, your Cyber Essentials certificate and the remediation the audit will test, is work you can do with us in the meantime, so the waiting time is not wasted.

Can you certify my Cyber Essentials today?

Yes, today, not in October. We are an appointed Certification Body for Cyber Essentials and assess submissions now. Cyber Essentials is a prerequisite for Plus, so getting it done before October is the sensible order anyway.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment that we verify. Cyber Essentials Plus adds an independent, hands-on technical audit: an assessor tests a sample of your devices and cloud services to confirm the five controls are genuinely in place, rather than taking your word for it.

Who carries out the audit?

Daly Whyte, who is a CREST-certified penetration tester as well as an IASME assessor. The Plus audit is a technical test, and it is done here by someone whose day job is testing systems rather than filling in an audit form.

What happens if we fail the audit?

You get a written account of what failed and why, and a period to fix it and be retested rather than a refusal. Most failures are patch levels, unsupported software or a multi-factor gap on a cloud service, and most are fixable in days.

Related

Cyber Essentials Plus, from late October 2026.

Book your audit slot now, and get Cyber Essentials certified with us today so you go straight into Plus.