Enterprise GRC Platform
Tyndora for Cyber Essentials Plus
Cyber Essentials Plus (CEP) is the government-recognized enhanced cybersecurity standard for UK government suppliers and defense contractors. Unlike baseline Cyber Essentials (self-assessed), CEP requires independent third-party technical assessment of your security controls. Tyndora automates control implementation and prepares you for third-party assessment.
Cyber Essentials Plus — Government-Grade Assurance
CEP is required for suppliers to UK government, NHS, and defense-related organizations. Third-party assessment verifies actual technical control implementation.
Cyber Essentials Plus Scope
- 5 Core Control Areas: Boundary firewalls, secure configuration, access control, malware prevention, patch management
- Assessment Method: Independent third-party technical assessment (not self-assessment)
- Validity: 12-month certification, annual renewal required
- Difference from Base: CEP adds hands-on technical verification vs. self-assessment
Who Requires Cyber Essentials Plus?
Organizations that supply to UK government, defense, NHS, critical infrastructure, and organizations handling sensitive government information.
- ✓ UK government suppliers
- ✓ Defense contractors and primes
- ✓ NHS IT suppliers
- ✓ Organizations handling Sensitive Personal Data
- ✓ Critical infrastructure operators
- ✓ Larger organizations requiring verified controls
The 5 Technical Controls — Independently Verified
Cyber Essentials Plus covers the same five technical controls as base Cyber Essentials; the difference is that a qualified assessor verifies them hands-on rather than by self-assessment. Select any control to expand it and see representative requirements.
Cyber Essentials Plus assesses the same five technical controls as Cyber Essentials, but verification is by independent hands-on technical testing (including on-device checks and simulated malware) rather than self-assessment. Requirements shown are a faithful plain-language, representative summary — not verbatim scheme text. Refer to the current official Cyber Essentials requirements and the CEP test specification for authoritative wording.
Cyber Essentials Plus Implementation in Tyndora
From control implementation to third-party assessment preparation to annual renewal.
Five Core Controls — Technical Implementation
Cyber Essentials Plus requires hands-on implementation of 5 control areas. Tyndora guides implementation and prepares evidence for third-party technical assessment.
- Boundary Firewalls: Network perimeter protection and filtering
- Secure Configuration: OS hardening, disabled unnecessary services, strong defaults
- Access Control: Authentication, authorization, least-privilege principles
- Malware Prevention: Anti-virus/malware tools, email filtering, web protection
- Patch Management: Regular patching of OS, applications, firmware
CYBER ESSENTIALS PLUS READINESS
Certification Level
Plus (Third-Party Verified)
Core Controls Implemented
3 / 5 in place, 2 in progress
Current Status
Baseline Cyber Essentials first — Plus to follow
Next milestone
Third-party technical assessment — targeting ~6 months
Third-Party Assessment & Certification Process
Unlike baseline Cyber Essentials (self-assessment), CEP requires an independent assessor to verify your controls through technical testing and document review.
Assessment Preparation
- ✓ Gather control documentation
- ✓ Prepare technical evidence
- ✓ Schedule third-party assessor
- ✓ Provide assessment access
Assessment Execution
- ✓ Technical control verification
- ✓ Configuration reviews
- ✓ Testing and sampling
- ✓ Document assessment (2-3 days on-site)
Certification & Renewal
- ✓ Assessment report delivery
- ✓ Certificate issuance (12 months)
- ✓ Annual renewal assessment
- ✓ Continuous control maintenance
Assessment Timeline
Q1: Preparation
Document controls, gather evidence, schedule assessor
Q2: Assessment
Third-party on-site technical assessment (2-3 days)
Q3: Remediation
Address findings, update documentation, close gaps
Q4: Award
Receive CEP certificate valid for 12 months
Get Cyber Essentials Plus Certified
Book a discovery and we'll show you how to implement the 5 core controls and prepare for third-party assessment.
Book a discovery