SolCo has passed its Cyber Essentials Plus audit. It’s a step up from the base Cyber Essentials certification we’ve held for some time, and unlike the self-assessed base tier, an independent assessor tested our live systems before signing off. Below is what Cyber Essentials Plus certification involves and what having it means depending on how you’re connected to us.
What Cyber Essentials Plus certification involves
Cyber Essentials is the UK government’s baseline cyber security standard, run by the National Cyber Security Centre and delivered through IASME’s network of certification bodies. It’s designed to reduce exposure to the most common internet-based attacks. If you want the ground-up version, we’ve published an explainer of what the base certification covers.
The base certification is a verified self-assessment. You answer a set of questions about how your business handles firewalls, patching, user accounts, malware protection and configuration, and a qualified assessor reviews the answers. It’s a useful benchmark, and the one most SMEs start with.
Cyber Essentials Plus keeps that questionnaire and adds a hands-on technical audit. According to IASME, an independent assessor tests a sample of your live systems using vulnerability scans, device checks, malware protection tests and confirmation that multi-factor authentication is enforced on cloud services. In our case, that meant scans against our internet-facing infrastructure, checks on a sample of devices across the operating systems we run, and verification that MFA is switched on where it should be. The assessor either sees the control working, or they do not. There’s no room for a well-meaning tick in a box.
That preparation involved identifying every server, laptop and cloud service that fell inside the scope, working through the internal prep, and then handing the assessor access to test what they needed to test.
Both tiers cover the same five technical controls, so the Cyber Essentials Plus requirements are identical at a technical level to the base scheme: firewalls, secure configuration, user access control, malware protection, and security update management.
Cyber Essentials vs Cyber Essentials Plus at a glance:
| Cyber Essentials | Cyber Essentials Plus |
Assessment type | Verified self-assessment questionnaire | Self-assessment plus independent technical audit |
Who verifies it | Assessor reviews your written answers | Assessor tests your live systems |
What’s checked | Responses on a form | Sample of real devices, external scans, MFA and malware checks |
Renewal | Annual | Annual |
What Cyber Essentials Plus certification means for you
If you’re already a SolCo client
The Cyber Essentials Plus requirements apply to how we run our own business, but they also shape how we design, secure and support the systems we look after for you. Holding the audited version means an independent assessor has confirmed the controls are actively working on our systems. If you’ve ever asked us how MFA is set up on your Microsoft 365 tenant or what happens if a laptop is lost, the same class of controls sits behind the audit we’ve just passed. Nothing about our services or the way we look after your estate changes because of the audit. The certification simply gives you evidence of the standard we hold ourselves to. The certification is renewed annually, so the audit runs again every year and isn’t a one-off badge. Our team can walk you through what our certification covers if it’s useful.
If you’re considering working with us
One of the harder things to judge when choosing an IT partner is whether they practise what they preach on their own security. Cyber Essentials Plus certification gives you an audited answer to that. It doesn’t replace your own due diligence, but it means you’re starting from a verified baseline rather than a marketing claim. And if you’ve been asked to tighten your own security by a customer or an insurer, working with a partner who has already been through the same audit tends to save time when it’s your turn.
If your customers or insurers are asking about your suppliers
Supply chain questionnaires have got longer over the past few years. If a client, prospect or insurer asks who your IT partner is and what standards they hold, being able to point to an audited certification is more useful than a paragraph about “trusted providers”. Typical questions ask whether your IT partner holds Cyber Essentials or Cyber Essentials Plus, whether they enforce MFA on cloud services, and how they handle staff access to your data. The NCSC has noted that Cyber Essentials is increasingly used as a supply chain security tool, and we’re seeing the same on the ground. We can share the details of what our certification covers so you can pass it on when you’re asked. We support businesses across sectors, including law, insurance and finance, and the underlying question tends to be the same wherever it comes from.
Talk to us
If you’d like to talk through what Cyber Essentials Plus means for your own business, or you’re weighing up whether to certify at either level, book a free technology review with Chris. It’s a 30-minute conversation about your current setup, not a sales pitch. We’ll flag anything obvious we’d tighten up and answer any questions about how Cyber Essentials Plus certification affects the way we support businesses across Reading and the Thames Valley. If your own renewal is coming up, or a customer has started asking questions you’re not sure how to answer, that’s a good moment to have the conversation.



