Cyber Essentials Plus

Cyber Security

Cyber Essentials Plus Certification

Demonstrate a higher level of cyber security assurance with Cyber Essentials Plus. Building on the Cyber Essentials standard, Plus includes an independent technical assessment that verifies your security controls are working effectively in practice.

SA1 Solutions guides your organisation through the entire Cyber Essentials Plus journey, from initial readiness assessments and remediation through to the external audit. We ensure your systems meet the required standards before testing begins, helping minimise disruption and maximise your chances of passing first time. Cyber Essentials Plus is increasingly required by government bodies, enterprise clients, and organisations handling sensitive information, providing greater confidence to customers, partners, and stakeholders.

How the audit works

The Cyber Essentials Plus Audit Process

Cyber Essentials Plus adds a hands-on technical audit on top of the self-assessment. Here is how it runs in three stages, with our team managing the scanning, remediation and assessor coordination from start to finish.

1
Phase oneBefore the audit

Asset Register

You send a list of in-scope devices with hostnames, OS versions and editions, and locations, or we pull it from Intune, your antivirus portal or Qualys.

Your part

Consent and IPs

You sign the audit consent form and add your external IP addresses, authorising the vulnerability scanning that Cyber Essentials Plus requires.

Your part

Qualys Deployment

We deploy the Qualys Cloud Agent to the in-scope devices. It scans quietly in the background and feeds daily reports, with no disruption to your team.

Handled by SA1

Proactive Remediation

Using the daily Qualys reports, we patch, fix misconfigurations and close vulnerabilities so devices meet the standard before audit day arrives.

Handled by SA1
Phase two

Audit day: the assessor verifies your controls remotely

Three days before, the assessor finalises the device sample and updates the Qualys report to match. On the day, we coordinate directly with the auditor and connect remotely to each sampled device, sharing the screen to demonstrate that every required control is correctly in place and operating.

Sample locked 3 days prior Remote and screen-shared Around 5 to 10 min per device
3
Phase threeAfter the audit

Evidence and Certificate

The assessor lists any outstanding items, we address them and submit the requested evidence on your behalf, and the auditor reviews it. Your organisation is then awarded Cyber Essentials Plus, independently verified assurance you can show customers, suppliers and stakeholders.

Handled by SA1
Awarded
Cyber Essentials Plus

Mind the deadline

Your Cyber Essentials Plus evidence must be submitted within 90 days of achieving Cyber Essentials, or 30 days of your CE+ audit, whichever is sooner. We keep you comfortably ahead of it so the certificate is never at risk.

Why go Plus

Benefits of Cyber Essentials Plus with SA1 Solutions

Independent, hands-on proof that your security controls actually work, plus the commercial doors that certification opens, all managed by our team.

>_cyber-essentials-plus // assurance overview VERIFIED
Result: Verified Method: Independent audit Managed by: SA1 Solutions
Verified

Independently Verified Security Controls

Cyber Essentials Plus goes beyond self-assessment. An independent assessor tests your systems and controls directly, providing hard evidence that your protections work in practice.

Trusted

Increased Customer and Supplier Confidence

Show your commitment to security with a recognised, independently audited certification that builds trust with customers, suppliers and stakeholders.

Reduced

Reduced Cyber Security Risk

Our proactive remediation identifies and resolves weaknesses before the audit, improving your posture and reducing exposure to cyber threats.

Unlocked

Greater Access to Contracts and Opportunities

Many public sector organisations, government bodies and larger enterprises now require Cyber Essentials Plus as part of supplier onboarding and procurement.

Managed

Fully Managed Remediation and Audit Support

We manage the preparation, vulnerability remediation, auditor coordination and certification on your behalf, minimising disruption to your business.

Ongoing

Ongoing Security Improvements

The detailed vulnerability reporting and remediation completed during certification strengthens your environment and improves long-term cyber resilience.

By the numbers

The measurable impact of Cyber Essentials

Reduced risk
92%

Organisations with Cyber Essentials are reported to be 92% less likely to make a cyber insurance claim than those without certification.

Protection
80%

The five Cyber Essentials controls can prevent around 80% of common cyber attacks when correctly implemented.

Coverage
5controls

Firewalls, secure configuration, user access control, malware protection and security update management.

Insurance
£25,000

Cyber liability insurance included for eligible organisations (under £20m turnover) on whole-organisation certification.

Contact us today

Demonstrate independently verified cyber security, meet supplier requirements, and build greater trust with customers. Speak to our experts today to start your Cyber Essentials Plus certification journey.