Countdown until the UK analogue phone switch-off on 31 January 2027.Is your business affected?
Audited Certification Service

Cyber Essentials Plus Certification

The independently audited tier, delivered as a service: £400 + VAT per month, all-in — everything in Cyber Essentials, plus the hands-on technical audit preparation, evidence collection, and continuous external monitoring of your internet-facing estate. Typically audited and certified in 45–60 days, in partnership with an IASME-accredited certification body.

£400+ VAT / month, all-in — standard scope
45–60days to initial certification, typically
0surprise invoices — audit and fees included

AMVIA's Cyber Essentials Plus service costs £400 + VAT per month, all-in for standard scope (up to 49 employees): the full Cyber Essentials service — gap analysis, hands-on remediation, submission with official fees included, annual re-certification — plus preparation for the independent technical audit, evidence collection, and continuous external attack surface monitoring. Initial certification typically takes 45–60 days, delivered in partnership with an IASME-accredited certification body. Larger organisations are tiered from the same floor.

What Cyber Essentials Plus is

Cyber Essentials Plus certifies exactly the same five technical controls as basic Cyber Essentials — firewalls, secure configuration, user access control, malware protection and security update management. The difference is proof. Basic CE is a verified self-assessment: you declare, a qualified assessor reviews. Plus adds an independent technical audit in which an assessor tests your actual systems — sampling devices, checking patch levels, attempting to deliver test malware by email and browser, and verifying that MFA and access controls really behave the way the questionnaire claims. Same standard, harder evidence. Our CE vs CE Plus comparison covers the decision in depth.

What the technical audit involves

The assessor works from the official CE Plus test specification against a representative sample of your in-scope estate. In practice that means: patch verification — sampled devices scanned to confirm no high or critical vulnerabilities older than 14 days; malware protection tests — benign test files delivered by email and download to confirm your defences catch or block them; browser and email client checks — confirming executable content from the internet can't run without protection; account and MFA verification — admin separation and multi-factor authentication demonstrated, not just declared; and a device and mobile sample covering the estate shape you declared, home workers included. Basic CE must also be certified within three months before the Plus audit completes — which is why our delivery sequences the self-assessment first, then runs the audit on systems already proven against it.

Who Plus is for

Supply chains and enterprise buyers: where basic CE gets you past the questionnaire, Plus is increasingly what larger customers, prime contractors and certain government and MoD frameworks name specifically — the audit is what they're buying. The insured: UK cyber insurers don't generally mandate the badge, but their proposal forms ask for precisely the controls Plus independently verifies, and the NCSC reports that organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than those without. Our guide to cyber insurance requirements maps the overlap in detail. Anyone whose word isn't enough: if your customers handle sensitive data, a self-declaration carries limited weight — an independent audit changes the conversation.

What's included, in full

£400 + VAT per month for standard scope (up to 49 employees) covers the complete basic CE service — gap analysis, remediation done by our engineers, submission with official IASME fees included, annual re-certification — plus everything the audit adds: preparation of every in-scope device and account, evidence collection, assessor coordination with us in the room, and remediation of anything the audit surfaces, at no extra charge. It also includes continuous external attack surface monitoring: SurfaceLoop, our attack surface monitoring capability, continuously discovers and watches your internet-facing assets — domains, subdomains, certificates, exposed services — so the drift that fails audits gets caught when it appears, not when the assessor does. Larger and multi-site organisations are tiered from the same floor and quoted on a 15-minute call before any commitment.

CE or Plus — the honest answer

If no contract, insurer or customer has named Plus, basic Cyber Essentials at £250 + VAT/month is the right starting point for most SMEs — the controls are identical, and upgrading later transfers all the work. Choose Plus from the start when a requirement already names it, when you're bidding into supply chains that demand audited evidence, or when self-assessment simply won't satisfy the people you need to convince. If you're unsure which side you're on, the 15-minute call is genuinely about fit — the pricing is already on this page either way.

Why the audited tier

92%less likely to make a cyber insurance claim — organisations with Cyber Essentials controls vs those without (NCSC, 10 Years of Cyber Essentials)
5controls — identical to Cyber Essentials; Plus proves them with an independent technical audit
12 mocertificate validity, with basic CE re-certified within 3 months of each Plus audit
24/7external attack surface monitoring included, powered by SurfaceLoop

What £400/month actually includes

All-in for standard scope (up to 49 employees). Larger organisations are tiered from the same floor.

Everything in Cyber Essentials

Gap analysis, hands-on remediation of the five controls, questionnaire submission with official fees included, and annual re-certification — the full CE service is the foundation.

Technical audit, prepared for

Plus adds an independent assessor testing your actual systems. We prepare every in-scope device and account so the audit confirms what we already know — and we're in the room when it runs.

Evidence collection

Device inventories, patch states, MFA coverage, malware protection status — collected and organised before the assessor asks, which is most of what separates a smooth audit from a stalled one.

Continuous external monitoring

Your internet-facing estate — domains, subdomains, certificates, exposed services — monitored continuously by SurfaceLoop, our attack surface monitoring capability. Drift that would fail next year's audit gets caught the week it appears.

Accredited delivery

Audit conducted through our IASME-accredited certification body partner — the certificate is the standard, register-verifiable Cyber Essentials Plus.

We hold it ourselves

AMVIA is Cyber Essentials Plus certified. The people preparing your audit sit the same audit — and pass it.

From signup to audited

Typically 45–60 days to initial certification: the CE foundation first, then the technical audit on systems we've already proven.

01

Gap analysis (week 1)

Estate mapped against the five controls — with the extra Plus lens: which devices and accounts will the assessor sample, and would they pass today?

02

Remediation (weeks 2–5)

MFA everywhere it's required, admin rights tightened, patching inside the 14-day window, malware protection verified on every in-scope device — done by our engineers, evidenced as we go.

03

Basic CE, then the audit (weeks 5–8)

The Cyber Essentials self-assessment is certified first (Plus requires it within three months), then the independent assessor tests a sample of your real systems: patch checks, malware defences, email and browser protections, MFA verification.

04

Stay audit-ready

Monthly control checks plus continuous external monitoring. Next year's audit lands on an estate that never drifted — which is the entire difference between renewal and re-project.

Why do Plus with AMVIA

An audit is only stressful when you don't know what it will find. Our job is making sure you do.

Audit-prepared, not audit-surprised

We remediate and evidence every in-scope system before the assessor arrives. The audit becomes confirmation, not discovery.

Monitoring between audits

SurfaceLoop watches your external estate continuously — new subdomains, expiring certificates, exposed services — so audit-failing drift is fixed in days, not found at renewal.

Published pricing

£400 + VAT/month on the page, audit and official fees included. Larger estates tiered from the same floor, quoted before you commit.

A path, not a ceiling

The same team runs managed detection and response, Microsoft 365 security and vulnerability management — Plus is the audited baseline, not the destination.

Client testimonial coming soon. AMVIA protects over 1,200 UK businesses.

AMVIA Client

Cyber Essentials Certification Service Pricing

PlanFrom / monthResponse TargetIncludes
Cyber Essentialsfrom £250.00Initial certification typically 30–45 daysGap analysis, remediation, submission, annual re-certification
Cyber Essentials PlusAudited tierfrom £400.00Initial certification typically 45–60 daysEverything in CE + independent technical audit with evidence collection

Your certification price, instantly

Two inputs, no email address required. Standard scope is priced flat; larger estates are tiered and confirmed on a 15-minute call.

Ready for the audited tier?

Standard scope is £400 + VAT/month with the audit, official fees and monitoring all included. Tell us about your business and we'll start the gap analysis this week.

Cyber Essentials Plus — your questions

Free tool

Would you pass the audit today?

Take the free 20-question readiness assessment — instant per-control results in your browser, and a printable gap report to bring to the call.

Not sure whether you need Plus?

Fifteen minutes with the certification team: what your contracts and insurers actually require, your scope, your exact price. The pricing is already public — the call is about fit.

Trusted by 1,200+ UK Businesses
Cyber Essentials Plus
IASME-Accredited Delivery Partner
Microsoft MSSP — Managed Security Service Provider