Cyber Essentials Plus Certification
The independently audited tier, delivered as a service: £400 + VAT per month, all-in — everything in Cyber Essentials, plus the hands-on technical audit preparation, evidence collection, and continuous external monitoring of your internet-facing estate. Typically audited and certified in 45–60 days, in partnership with an IASME-accredited certification body.
AMVIA's Cyber Essentials Plus service costs £400 + VAT per month, all-in for standard scope (up to 49 employees): the full Cyber Essentials service — gap analysis, hands-on remediation, submission with official fees included, annual re-certification — plus preparation for the independent technical audit, evidence collection, and continuous external attack surface monitoring. Initial certification typically takes 45–60 days, delivered in partnership with an IASME-accredited certification body. Larger organisations are tiered from the same floor.
What Cyber Essentials Plus is
Cyber Essentials Plus certifies exactly the same five technical controls as basic Cyber Essentials — firewalls, secure configuration, user access control, malware protection and security update management. The difference is proof. Basic CE is a verified self-assessment: you declare, a qualified assessor reviews. Plus adds an independent technical audit in which an assessor tests your actual systems — sampling devices, checking patch levels, attempting to deliver test malware by email and browser, and verifying that MFA and access controls really behave the way the questionnaire claims. Same standard, harder evidence. Our CE vs CE Plus comparison covers the decision in depth.
What the technical audit involves
The assessor works from the official CE Plus test specification against a representative sample of your in-scope estate. In practice that means: patch verification — sampled devices scanned to confirm no high or critical vulnerabilities older than 14 days; malware protection tests — benign test files delivered by email and download to confirm your defences catch or block them; browser and email client checks — confirming executable content from the internet can't run without protection; account and MFA verification — admin separation and multi-factor authentication demonstrated, not just declared; and a device and mobile sample covering the estate shape you declared, home workers included. Basic CE must also be certified within three months before the Plus audit completes — which is why our delivery sequences the self-assessment first, then runs the audit on systems already proven against it.
Who Plus is for
Supply chains and enterprise buyers: where basic CE gets you past the questionnaire, Plus is increasingly what larger customers, prime contractors and certain government and MoD frameworks name specifically — the audit is what they're buying. The insured: UK cyber insurers don't generally mandate the badge, but their proposal forms ask for precisely the controls Plus independently verifies, and the NCSC reports that organisations with Cyber Essentials controls are 92% less likely to make a cyber insurance claim than those without. Our guide to cyber insurance requirements maps the overlap in detail. Anyone whose word isn't enough: if your customers handle sensitive data, a self-declaration carries limited weight — an independent audit changes the conversation.
What's included, in full
£400 + VAT per month for standard scope (up to 49 employees) covers the complete basic CE service — gap analysis, remediation done by our engineers, submission with official IASME fees included, annual re-certification — plus everything the audit adds: preparation of every in-scope device and account, evidence collection, assessor coordination with us in the room, and remediation of anything the audit surfaces, at no extra charge. It also includes continuous external attack surface monitoring: SurfaceLoop, our attack surface monitoring capability, continuously discovers and watches your internet-facing assets — domains, subdomains, certificates, exposed services — so the drift that fails audits gets caught when it appears, not when the assessor does. Larger and multi-site organisations are tiered from the same floor and quoted on a 15-minute call before any commitment.
CE or Plus — the honest answer
If no contract, insurer or customer has named Plus, basic Cyber Essentials at £250 + VAT/month is the right starting point for most SMEs — the controls are identical, and upgrading later transfers all the work. Choose Plus from the start when a requirement already names it, when you're bidding into supply chains that demand audited evidence, or when self-assessment simply won't satisfy the people you need to convince. If you're unsure which side you're on, the 15-minute call is genuinely about fit — the pricing is already on this page either way.
Why the audited tier
What £400/month actually includes
All-in for standard scope (up to 49 employees). Larger organisations are tiered from the same floor.
Everything in Cyber Essentials
Gap analysis, hands-on remediation of the five controls, questionnaire submission with official fees included, and annual re-certification — the full CE service is the foundation.
Technical audit, prepared for
Plus adds an independent assessor testing your actual systems. We prepare every in-scope device and account so the audit confirms what we already know — and we're in the room when it runs.
Evidence collection
Device inventories, patch states, MFA coverage, malware protection status — collected and organised before the assessor asks, which is most of what separates a smooth audit from a stalled one.
Continuous external monitoring
Your internet-facing estate — domains, subdomains, certificates, exposed services — monitored continuously by SurfaceLoop, our attack surface monitoring capability. Drift that would fail next year's audit gets caught the week it appears.
Accredited delivery
Audit conducted through our IASME-accredited certification body partner — the certificate is the standard, register-verifiable Cyber Essentials Plus.
We hold it ourselves
AMVIA is Cyber Essentials Plus certified. The people preparing your audit sit the same audit — and pass it.
From signup to audited
Typically 45–60 days to initial certification: the CE foundation first, then the technical audit on systems we've already proven.
Gap analysis (week 1)
Estate mapped against the five controls — with the extra Plus lens: which devices and accounts will the assessor sample, and would they pass today?
Remediation (weeks 2–5)
MFA everywhere it's required, admin rights tightened, patching inside the 14-day window, malware protection verified on every in-scope device — done by our engineers, evidenced as we go.
Basic CE, then the audit (weeks 5–8)
The Cyber Essentials self-assessment is certified first (Plus requires it within three months), then the independent assessor tests a sample of your real systems: patch checks, malware defences, email and browser protections, MFA verification.
Stay audit-ready
Monthly control checks plus continuous external monitoring. Next year's audit lands on an estate that never drifted — which is the entire difference between renewal and re-project.
Why do Plus with AMVIA
An audit is only stressful when you don't know what it will find. Our job is making sure you do.
Audit-prepared, not audit-surprised
We remediate and evidence every in-scope system before the assessor arrives. The audit becomes confirmation, not discovery.
Monitoring between audits
SurfaceLoop watches your external estate continuously — new subdomains, expiring certificates, exposed services — so audit-failing drift is fixed in days, not found at renewal.
Published pricing
£400 + VAT/month on the page, audit and official fees included. Larger estates tiered from the same floor, quoted before you commit.
A path, not a ceiling
The same team runs managed detection and response, Microsoft 365 security and vulnerability management — Plus is the audited baseline, not the destination.
Client testimonial coming soon. AMVIA protects over 1,200 UK businesses.
AMVIA Client
Cyber Essentials Certification Service Pricing
| Plan | From / month | Response Target | Includes |
|---|---|---|---|
| Cyber Essentials | from £250.00 | Initial certification typically 30–45 days | Gap analysis, remediation, submission, annual re-certification |
| Cyber Essentials PlusAudited tier | from £400.00 | Initial certification typically 45–60 days | Everything in CE + independent technical audit with evidence collection |
Your certification price, instantly
Two inputs, no email address required. Standard scope is priced flat; larger estates are tiered and confirmed on a 15-minute call.
Ready for the audited tier?
Standard scope is £400 + VAT/month with the audit, official fees and monitoring all included. Tell us about your business and we'll start the gap analysis this week.
Cyber Essentials Plus — your questions
£400 + VAT per month, all-in for standard scope (up to 49 employees): the full basic CE service, audit preparation, evidence collection, the independent technical audit through our IASME-accredited certification body partner, official fees, continuous external monitoring, and annual re-certification. Larger organisations are tiered from the same floor and quoted before commitment.
Typically 45–60 days from signup for standard scope: gap analysis in week one, remediation over weeks two to five, then the basic CE self-assessment followed by the technical audit. The scheme requires basic CE to be certified within three months of the Plus audit completing, so the sequence is fixed — and we run it so the audit lands on systems already proven.
An independent assessor samples your real systems: vulnerability scans to verify patching, test malware delivered by email and download to verify protection, browser and email client configuration checks, MFA and admin-separation verification, and a device sample representative of your declared estate — home workers included. It tests what the questionnaire declared; our preparation makes sure the two match.
Identical controls, different proof. Basic CE is a verified self-assessment; Plus adds an independent technical audit of your actual systems. Plus carries more weight with enterprise buyers, government frameworks and insurers because someone independent has tested the controls rather than reviewed a declaration. With AMVIA, CE is £250+VAT/month and Plus is £400+VAT/month.
Yes — the scheme requires a valid basic CE certificate, achieved within three months before Plus certification. It's built into our delivery: the self-assessment is completed and certified first, then the audit runs. Both are included in the £400/month; you don't buy them separately.
Failing is rare on our watch because we don't book the assessor until our own checks pass — we've remediated and evidenced every in-scope system first. If the audit does surface something, fixing and re-testing is part of the service, not a new invoice.
SurfaceLoop is AMVIA's external attack surface monitoring capability — it continuously discovers and monitors your internet-facing assets: domains, subdomains, certificates, exposed services and forgotten infrastructure. It's included with Plus because external drift is exactly what fails renewal audits; catching it continuously keeps you genuinely audit-ready between annual assessments. It's a capability inside our services, not a product we sell separately.
Materially, though not usually as a formal mandate. UK insurers' proposal forms ask for the controls Plus verifies — MFA, patching, malware protection, secure configuration — and the NCSC reports organisations with CE controls are 92% less likely to make a claim. An independently audited certificate is stronger underwriting evidence than a self-declaration; some brokers and certification bodies also report premium benefits, though no major UK insurer publishes a fixed discount.
Certain MoD and central government contracts name Plus, particularly where sensitive data or higher-risk services are involved, and prime contractors increasingly flow the Plus requirement down their supply chains. The pattern to watch: if a framework or customer security schedule says 'independently audited' or names Plus, basic CE won't satisfy it — check the wording before choosing your tier.
Very little, because we've done the preparation: access to the sampled devices and accounts, a point of contact, and a few hours of availability. We coordinate the assessor, sit in on the audit, and handle evidence requests as they come — the disruption to your team is deliberately close to zero.
Yes — the audit samples the estate you declared, and devices used for business are in scope wherever they sit, including home-worker laptops and BYOD accessing company data. Remote devices are one of the most common audit trip-ups, which is why bringing them under control is part of our remediation, not an exclusion.
Yes, cleanly — the controls are identical, so everything done for CE transfers. If your basic certificate is less than three months old, the audit can often run against it directly; otherwise the self-assessment is refreshed first. Existing AMVIA CE customers move to the Plus tier by stepping up from £250 to £400/month — no restart, no project fee.
Yes — the audit is conducted through our IASME-accredited certification body partner, and the certificate is the standard Cyber Essentials Plus certificate, verifiable on the official register operated by IASME on behalf of the NCSC. You can confirm it — or check any supplier's — with our free certificate checker.
Would you pass the audit today?
Take the free 20-question readiness assessment — instant per-control results in your browser, and a printable gap report to bring to the call.
Not sure whether you need Plus?
Fifteen minutes with the certification team: what your contracts and insurers actually require, your scope, your exact price. The pricing is already public — the call is about fit.
Certification resources
Cyber Essentials — £250/month
The foundation tier: same five controls, verified self-assessment, all-in monthly service.
Cyber Essentials vs Plus
Same controls, different proof — costs, timelines, and which tier buyers and insurers actually demand.
Cyber insurance requirements
What UK insurers actually ask for, and how the five CE controls map to the proposal form.
SurfaceLoop attack surface monitoring
The continuous external monitoring included with Plus — what it watches and why it matters.
Protect your business → Get Cybersecurity Assessment