Jisc

Cyber Essentials Plus

Independently verify that your cyber security controls and protections are working.

Cyber Essentials Plus certificate

Build trust, meet compliance requirements and strengthen your cyber resilience with Cyber Essentials Plus, the independently verified certification that proves your essential cyber security controls are working effectively.

As a government-backed scheme supported by the National Cyber Security Centre (NCSC), Cyber Essentials helps organisations protect themselves against the most common cyber threats. Cyber Essentials Plus goes further, independently testing and verifying that the five IASME critical security controls are correctly implemented across your environment.

Deliver measurable security outcomes

Cyber Essentials Plus helps your organisation to:

  • Reduce exposure to common cyber attacks
  • Demonstrate security assurance to customers, partners and stakeholders
  • Meet compliance, funding and procurement requirements
  • Build confidence in your cyber security controls
  • Strengthen cyber resilience across your organisation

By identifying weaknesses before they become security incidents, Cyber Essentials Plus provides reassurance that the protections you rely on are working as intended.

Why upgrade to Cyber Essentials Plus?

Cyber Essentials Plus goes beyond self-assessment, providing independent testing and validation of critical cyber security controls. It gives customers, partners and stakeholders greater confidence in your organisation's cyber resilience.

Cyber Essentials:

  • Self-assessment
  • Demonstrates intent
  • Security baseline
  • Foundation certification

Cyber Essentials Plus:

  • Independent testing
  • Demonstrates effectiveness
  • Validated security controls
  • Enhanced assurance

Expertise built around your sector

Our deep understanding of the education, research, public and not-for-profit sectors makes us uniquely placed to support your cyber security goals.

As the UK's connectivity provider for education and research, we understand the challenges organisations face and the practical steps needed to improve resilience. We also act as a close advisor to IASME on education-specific concerns, helping organisations navigate certification with confidence.

Supported every step of the way

We provide a structured, customer-focused route to certification. We engage early to help define scope, assess readiness and identify potential gaps, giving you greater visibility and a clearer path to success.

This approach means less time spent resolving issues late in the process, reduced risk of delays, and a smoother certification experience.

As an accredited certification body, we work closely with your team to ensure everyone understands what is required and how to prepare effectively.

More than a certification

Cyber Essentials Plus is not simply about passing an assessment. It is an opportunity to strengthen security practices, improve organisational resilience and establish a stronger foundation for the future.

By working in partnership with us, you'll gain practical guidance, actionable insights and expert support that help protect your people, systems and data long after certification is achieved.

As one of only 25 organisations in the UK to hold NCSC Cyber Incident Response Level 2 (CIRL2) accreditation, and the only provider dedicated exclusively to serving the education sector, we are uniquely positioned to help you build lasting cyber resilience.

Get started

Ready to strengthen your cyber resilience and achieve Cyber Essentials Plus certification with confidence? Book a scoping call with our experts to discuss your requirements, explore your readiness, and build a clear path to certification success.

Book a scoping call

ISO certification

This service is included within the scope of our ISO9001 and ISO27001 certificates.

Read more about International Organisation for Standardisation (ISO) standards and view Jisc certificates.

iso-9001-2015-ukas-logo

iso_iec_27001ukas