Cyber Essentials Plus (UK NCSC) — Gap Analysis
UK NCSC Cyber Essentials Plus — Independently VerifiedAbout Cyber Essentials Plus (UK NCSC)
Cyber Essentials Plus is the UK government-backed independently-verified cybersecurity baseline. It builds on the self-assessed Cyber Essentials certification by adding a hands-on technical audit, including external vulnerability scans, internal scans and authenticated tests of in-scope devices. CE+ is mandatory for many UK central government contracts that involve handling sensitive information and is a strong differentiator in UK public and private sector procurement.
Issuing Body
UK National Cyber Security Centre (NCSC), administered by IASME
Edition
2024
Coverage
5 technical controls — Firewalls, Secure Configuration, Security Update Management, User Access Control, Malware Protection — plus on-site hands-on technical verification.
Typical Users
UK organisations, especially those bidding for central UK government contracts (where CE+ is mandatory for handling sensitive information) and the wider supply chain.
How to use this tool
1. Work through each clause. For each requirement, choose Compliant, Partial, Non-compliant, or leave as Not assessed.
2. Add notes against any requirement to record evidence, gaps, or corrective actions.
3. Click Save progress — data is stored locally in your browser, never uploaded.
4. Export the report as TXT, CSV, JSON or print to PDF for your audit file.
Note: This tool is a guided self-assessment. It does not replace a third-party audit and the authoritative version of the standard must be obtained from the issuing body.
ISO Xpert — Get in touch
UK-based consultancy specialising in management-system gap analysis, training and certification preparation across ISO, API, Halal, GFSI, ESG, cybersecurity and industry-specific standards.
Phone / WhatsApp
Office
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK