Skip to main content
    NixInfinity-AI
    Strategy

    When to Upgrade from Cyber Essentials to CE Plus

    Published 15 June 2026

    What CE Plus actually adds

    Standard CE is self-assessed and reviewed by a UK assessor. CE Plus adds a hands-on technical audit – sample devices are tested for patch status, malware protection, account configuration and email/web filtering. It's the same five controls, independently verified. See CE Plus overview for the full scope.

    The four trigger points

    1. A tender requires it

    The most common trigger. Government Commercial Agency lots handling higher-impact data, MoD Profile 2+, and an increasing number of large enterprise procurement teams now ask for CE Plus rather than CE. If you're losing tenders on the cyber line, that's the signal.

    2. Your insurer is pushing for it

    A growing number of cyber insurers price CE Plus separately or insist on it above a certain turnover. The premium reduction often covers the certification cost.

    3. You handle higher-sensitivity client data

    Healthcare, legal, financial advice, payroll, HR services – the moment your clients' data being exposed would be more damaging than the average breach, the audit assurance of CE Plus is justified.

    4. Standard CE has been clean for two cycles

    If you've passed standard CE twice in a row with no significant fixes, the controls are embedded enough to survive an audit. That's the practical test of readiness.

    When to wait

    • If your last CE submission needed a resubmission – fix the underlying process before you sign up for an audit.
    • If you're mid-migration (moving M365 tenants, swapping MDM, BYOD rollout) – stabilise first, audit after.
    • If you've grown by more than 30% in headcount in the last six months – let provisioning settle.

    What changes between CE and CE Plus

    • An assessor connects to a sample of your devices (10% or 5 devices, whichever larger) and runs a vulnerability scan.
    • Email and web filtering are tested with sample malicious-content payloads.
    • Account separation, MFA enforcement and patching status are verified, not just declared.
    • Cloud services in scope are reviewed against admin-access evidence.

    Cost impact

    CE Plus runs £1,400 to £2,000 + VAT depending on your organisation size band. See CE Plus cost UK for the bands.

    Practical sequence

    1. Hold CE for one cycle, fix anything weak.
    2. Schedule CE Plus 60 days before your CE renewal so the certificate covers the gap.
    3. Run an internal mock-audit two weeks before – patch status, MFA coverage, leavers list.
    4. Submit CE Plus and renew CE in the same window.

    Ready to plan the upgrade? Speak to us via the CE Plus page.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions