CE Plus is Cyber Essentials with independent technical testing on top. It carries more weight with government, defence, and enterprise buyers — and 786 Cyber prepares you completely for the documentation layer before your assessor arrives.
CE vs CE Plus
Cyber Essentials Plus covers exactly the same five control areas as Cyber Essentials — the difference is how compliance is verified. CE Plus requires an accredited assessor to technically test your controls, not just review your documentation.
| Area | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Control categories | Same 5 categories | Same 5 categories |
| Verification method | Self-assessment questionnaire, verified by accredited assessor | Independent technical testing by accredited assessor |
| Documentation required | Policies, controls, evidence | Same documentation — must be complete before audit begins |
| Technical testing | Not required | Vulnerability scans, configuration checks, MFA verification |
| Recognised by | Most enterprise & public sector buyers | MOD, high-assurance government, defence supply chains |
| Cost | Lower — self-assessment | Higher — includes assessor fees for technical audit |
| Renewal | Annual | Annual |
| 786 Cyber covers | Full documentation layer | Full documentation layer — you arrange the accredited assessor |
"CE Plus documentation must be complete and evidenced before the technical audit begins. 786 Cyber handles this layer entirely — so when your assessor arrives, you're ready."
Why CE Plus matters
CE Plus preparation checklist
786 Cyber generates and tracks all of these — your documentation is complete before the assessor arrives.
How 786 Cyber helps
All policies required for CE Plus — Acceptable Use, Password, Remote Working, BYOD — generated and ready to publish before the audit.
Every control implementation logged with timestamps. When the assessor asks for evidence that controls were in place, it's already compiled.
Visual progress across all 5 CE control categories — see exactly what's complete and what still needs attention before the audit date.
Catalogue all in-scope devices with OS version, patch status, and owner — the foundation of your CE Plus scope definition.
CE Plus is annual. 786 Cyber tracks your certification date and alerts you with enough time to prepare documentation before renewal.
CE Plus controls tagged to ISO 27001, GDPR, and NIST CSF — every control satisfies multiple framework requirements simultaneously.
CE Plus builds on Cyber Essentials — all CE documentation must be complete before the CE Plus audit. If you haven't achieved CE yet, that's the right starting point.
786 Cyber builds your complete documentation foundation — so when your assessor arrives, everything is ready.