What Cyber Essentials Plus Actually Means for MSPs

CE+ is a buyer expectation across UK regulated sectors. Guide to the 5 control areas, audit timeline, what to fix first, and how MSPs use it commercially.

Cyber Essentials Plus (CE+) is the UK's hands-on cyber certification, audited by an independent assessor against 5 technical control areas. For MSPs, it's now a buyer expectation in regulated sectors and increasingly outside them. This guide covers what CE+ actually tests, how it differs from CE basic, the 5 control areas in detail, the typical audit timeline, the 3 areas MSPs commonly stumble on, what the certificate is worth in commercial terms, the most common questions MSPs ask before going for it, and the mistakes to avoid.

What CE+ is and why it exists

Cyber Essentials is a UK government-backed scheme run by IASME, designed to protect organisations against the most common cyber attacks. It was launched in 2014 and has gone through several iterations since. The basic CE certification is a self-assessment questionnaire reviewed by a certifying body. Cyber Essentials Plus adds an external audit with hands-on testing.

The point of CE+ is verification. Anyone can fill in a self-assessment honestly or otherwise. With CE+, an independent auditor sees the controls in action: they sample your devices, check configurations live, run an external vulnerability scan against your perimeter, and review your evidence. The certificate then tells anyone reading it that those controls genuinely existed on the audit date.

"CE alone is increasingly read as a self-attestation. CE+ is read as proof."

Buyers, insurers, and regulators have caught up to the difference. CE alone is increasingly read as a self-attestation. CE+ is read as proof. For MSPs selling to regulated SMEs or public sector, CE+ has moved from a nice-to-have to a baseline requirement.

The 5 control areas in detail

1. Firewalls

Tests whether you have firewalls (hardware or software) protecting every device that connects to the internet. The auditor checks that:

Default-deny is the posture for inbound traffic, with documented exceptions.

Admin access to the firewall is restricted, MFA-protected, and uses non-default credentials.

Remote management interfaces aren't exposed to the public internet without strong protection.

Firewall rule changes go through a documented change control process.

Common gotchas

Home worker laptops without a configured local firewall.

IoT or printer devices with admin interfaces accessible from outside the network.

Legacy port-forwards from old projects that nobody documented.

2. Secure configuration

Tests whether devices are hardened against attack. The auditor checks that:

Default passwords have been changed on all devices and accounts.

Unnecessary services and software are removed or disabled.

Auto-run from removable media is disabled.

User accounts and software installations follow least privilege.

Common gotchas

A vendor account left enabled with default credentials after install.

Windows features that nobody uses still enabled.

Contractor or test laptops never properly hardened.

3. User access control

Tests how user accounts (especially privileged ones) are managed. The auditor checks that:

Each user has their own account, separate from any admin account they hold.

Admin accounts use MFA without exception.

There's a documented joiner/leaver process and you can show it ran for recent staff changes.

Privileged access is reviewed periodically (quarterly is the norm) and reduced where no longer needed.

Common gotchas

Shared admin accounts (one credential held by multiple staff).

Admin rights granted ad-hoc and never removed.

Ex-staff accounts still active months after they left.

Third-party support accounts with persistent admin rights.

4. Malware protection

Tests whether you defend devices against malicious software. The auditor checks that:

Anti-malware software is installed and updated on every in-scope device.

It's configured to scan files on access, scan downloads, and block access to known malicious websites.

Where appropriate, application allowlisting restricts what can run.

Mobile devices have appropriate protection (MDM, app store restrictions, etc.).

Common gotchas

A handful of devices with anti-malware out of date or disabled.

BYOD or contractor devices not enrolled in any management.

Mobile devices without policy enforcement.

5. Security update management

Tests whether you patch promptly. This is the area where MSPs most commonly stumble. The auditor checks that:

All software (OS, browsers, applications, firmware) is supported by the vendor (no end-of-life software in scope).

Patches for high or critical severity issues are applied within 14 days of vendor release.

You can produce evidence (a report) showing patches applied and the elapsed time.

Common gotchas

An EOL OS or application still in production.

A few stragglers consistently outside the 14-day window.

No clean report on demand even when patching is happening.

Score your proof gap

Run the Proof Gap Scorecard. 12 questions, 5 minutes, instant report on where your MSP's proof is thin.

Take the free scorecard

How CE+ differs from CE basic

CE basic is a self-assessment questionnaire. You answer the questions, your certifying body reviews and accredits. It costs less, takes less time, but is read by buyers as your own claim about yourself.

CE+ uses the same control set but adds external testing on a sample of devices and an external vulnerability scan against your network perimeter. The auditor visits (or remote-audits) and sees the controls in action. They also confirm that the evidence you describe in your answers actually exists.

CE basic vs CE+ at a glance

Cost: CE basic typically £300-500. CE+ typically £1,500-3,500 depending on scope.

Time to certify: CE basic 2-4 weeks. CE+ 6-12 weeks including audit scheduling.

Effort: CE basic is mostly a paper exercise. CE+ requires you to clean up environments and produce evidence.

Buyer credibility: CE basic is the floor. CE+ is the standard for any supplier handling sensitive data or critical systems.

If you're choosing between them and you sell to regulated SMEs, public sector, or any buyer with a procurement function, CE+ is the right call. CE basic on its own won't meet the bar.

Why MSPs are getting pushed on CE+ now

Three commercial forces are converging:

Regulated SME clients. Legal, financial, and healthcare SMEs face audit and insurance pressure to verify their suppliers. The MSP is one of the highest-risk suppliers because they have privileged access. Auditors are now asking these SMEs to evidence that their MSP holds CE+ as a minimum.

Public sector contracts. Any supplier handling certain UK central government data must hold CE+. This requirement has trickled down through subcontracting chains, so even MSPs not directly bidding for public sector now hit it indirectly.

Cyber insurance underwriters. Underwriters are tightening the qualifying questions on cyber policy renewals. Many now ask the insured (the SME) to confirm their MSP holds CE+ or equivalent. SMEs that can't provide that evidence either pay higher premiums or get policies declined.

Net effect: an MSP without current CE+ is now losing deals it would have won 18 months ago, and it's taking the loss without always knowing why. The procurement team or insurance broker filtered them out before they got to the table.

(The Assurix Trustmark surfaces CE+ status, plus the additional controls beyond CE+ that increasingly matter (ISO 27001 components, NIS2-relevant controls, evidence library), on a public profile per MSP. Buyers, brokers, and procurement teams can verify your status without asking. CE+ is the floor, the Trustmark is the layer above that answers the questions CE+ alone doesn't.)

What to fix first if you're preparing for CE+

Three areas account for most CE+ audit failures or rework. Fix these before booking the audit.

Patch evidence

Most MSPs are patching on cadence. Few can produce a clean, on-demand report showing what was patched, when, and on which devices, broken out by severity. The auditor wants this report. If you can't produce it, the auditor concludes the patching is unverifiable, which is the same as not patching.

Build the report from your RMM or patching tool. Standardise the format. Run it monthly so you've got historic data to show the auditor on day 1.

Local admin sprawl

User access control failures usually look like one of these: legacy admin rights granted to standard users and never removed, shared service accounts with credentials known to multiple staff, third-party tools that installed with admin rights and stayed there, ex-staff accounts active because nobody owns offboarding.

Run an admin account audit. Pull the list, identify everyone with admin rights, justify each one, remove the rest. Set up a quarterly review going forward.

Endpoint coverage gaps

Almost every MSP has a small number of devices not enrolled in their standard tooling. BYOD devices, contractor laptops, a few neglected PCs in a back office. Each one is a CE+ audit failure if it's in scope.

Two options: enrol them properly into your management tooling, or scope them out cleanly with a documented business reason. The auditor doesn't mind either, but they will fail you for unmanaged devices in scope.

The audit timeline

Typical CE+ engagement runs 6-12 weeks end-to-end. Roughly:

Week 1-2: scoping conversation with your certifying body. Agree what's in scope.

Week 2-4: you complete the self-assessment questionnaire (this is the CE basic component, must pass before CE+).

Week 4-8: prepare for the audit. Fix the gaps you found. Build the patch report. Tidy admin accounts. Close endpoint coverage gaps.

Week 8-10: audit. The auditor samples 3-5 devices per platform type, runs an external vulnerability scan, reviews evidence. Half-day to full-day on site or remote.

Week 10-12: audit report and certification. If passed, you receive the certificate. If failed in any control area, you get a remediation window (usually 30 days).

Recertification is annual.

How to use the certificate once you have it

DO:

Add it to every proposal, on page 1 of the proof section.

Display it in your QBR pack for every existing client.

Add it to your email signature and your website footer.

Reference the certificate number on supplier security questionnaires so reviewers can verify it on the IASME public register.

Diary the renewal date 90 days before expiry.

DON'T:

Let it expire. An expired CE+ is materially worse than no CE+ because it tells the buyer you let it lapse.

Hide it. Holding CE+ and not surfacing it on every proposal wastes most of the commercial value.

Treat it as a one-off compliance exercise. The prep work should genuinely upgrade your operational hygiene.

Scope it too widely. Including business areas that don't need certification just adds cost.

Common questions MSPs ask before going for CE+

Do we need to certify our clients too, or just ourselves?

Just yourselves, by default. CE+ certifies the organisation being audited (the MSP), not the MSPs' clients. Each client that wants their own CE+ goes through their own audit (which the MSP usually supports). The MSP's certificate doesn't transfer to clients.

Can we use our internal IT to do the audit instead of an external assessor?

No. The whole point of CE+ is independent verification. The auditor must be from a certifying body accredited by IASME. You can find the list on the NCSC and IASME websites. Pick one with experience auditing MSPs (some certifying bodies focus on different sectors).

What happens if we fail the audit?

Most certifying bodies offer a remediation window of 30 days to fix any failed control area and resubmit for re-test. There's usually an additional cost for the re-test. If you can't fix in 30 days, you don't get the certificate and have to start the process again from scratch.

Can we audit a subset of our environment, or does it have to be everything?

You can scope CE+ to a defined subset (a particular network, a particular business unit, a particular client environment). Scope it tightly to what your buyers actually care about. Wider scope adds cost and risk without commercial value.

Is CE+ recognised outside the UK?

It's a UK scheme so the recognition is strongest with UK buyers, UK insurers, and UK public sector. Some international buyers recognise it as an equivalent to their own national schemes. If you're selling significantly outside the UK, also consider ISO 27001 depending on the market.

How does CE+ relate to ISO 27001?

CE+ tests a specific set of technical controls. ISO 27001 tests a much broader management system covering policies, processes, risk management, and continuous improvement. CE+ is narrower and faster to achieve. ISO 27001 is wider, harder, and more credible to enterprise buyers. Many MSPs hold both.

Common mistakes

A few patterns that cost MSPs time, money, or both:

Booking the audit before doing the prep work. The audit fails, you pay for re-test, you've wasted 6 weeks.

Scoping too widely. CE+ scopes by network and device set. Including business areas that don't need the certification just adds cost and risk.

Treating CE+ as a checkbox. The MSPs that get the most commercial value out of CE+ use the prep work to genuinely upgrade their operational hygiene.

Not using the certificate in pitches. Holding CE+ and not surfacing it on every proposal and questionnaire response wastes most of the commercial value.

CE+ is the floor. Most buyers now want the layer above

CE+ is the baseline, but it's narrow by design. It tests 5 technical control areas at a single point in time. It doesn't show your continuous compliance posture, your operational metrics, your evidence library, your client outcomes. Buyers who care about CE+ increasingly want all of those visible too.

The Assurix Trustmark is the layer above CE+. It surfaces your CE+ certification alongside your Trustmark score against the CAF v4 (64 controls, audited annually with continuous monitoring between audits), on a public profile your prospects and clients can verify themselves. CE+ proves the floor. The Trustmark proves you live there.

Score your proof gap

Run the Proof Gap Scorecard. 12 questions, 5 minutes, instant report on where your MSP's proof is thin.

Take the free scorecard

Related reading