All systems operational · Ormskirk, North West England

Cyber Essentials Plus: The Complete Guide for North West Businesses

Cyber attacks are no longer a distant threat reserved for large corporations; they are an ever-present reality for businesses of every size, including those operating across the North West of England. In fact, the UK government’s Cyber Security Breaches Survey consistently highlights that a significant proportion of small and medium-sized businesses experience some form of cyber incident each year.

If you are looking to strengthen your organisation’s defences and demonstrate a credible commitment to security, achieving Cyber Essentials Plus certification is one of the most effective steps you can take. Unlike its foundational counterpart, this advanced certification involves independent, hands-on technical verification, giving customers, partners, and stakeholders genuine confidence in your security posture.

In this guide, we will break down exactly what Cyber Essentials Plus involves, how it differs from the standard certification, what the assessment process looks like in practice, and why it holds particular value for businesses operating in the North West. Whether you are beginning your certification journey or refining your existing knowledge, this analysis will give you the clarity you need to move forward with confidence.

What Is Cyber Essentials Plus?

Cyber Essentials is a UK government-backed certification scheme, overseen by the National Cyber Security Centre (NCSC) and administered by the IASME Consortium. Designed to protect organisations against the most prevalent internet-borne cyber threats, the scheme establishes five core technical controls that form the foundation of any credible cyber security posture. It provides businesses with a structured, recognised framework to demonstrate that essential security hygiene is in place, making it relevant for organisations of all sizes across every sector.

The scheme operates across two certification levels. The baseline Cyber Essentials (CE) certification involves a verified self-assessment questionnaire, reviewed and confirmed by an accredited Certification Body. Cyber Essentials Plus (CE+) builds directly on this foundation by adding a hands-on technical audit carried out by an independent, IASME-accredited assessor. Rather than replacing the self-assessment, CE+ validates those self-assessed controls through real-world testing, covering endpoint configurations, user account management, and network security. This independent verification is what sets CE+ apart and gives it considerably greater credibility with government bodies, procurement teams, and enterprise clients.

The scheme was originally launched in 2014 and has been updated several times to keep pace with the evolving threat landscape. The most recent version, v3.3 (codenamed ‘Danzell’), went live on 28 April 2026, introducing tightened requirements around cloud services, home working environments, and multi-factor authentication. CE+ certificates remain valid for 12 months and must be renewed annually, ensuring that an organisation’s security posture is independently verified on a regular, ongoing basis rather than treated as a one-time exercise.

Uptake continues to grow across the UK. According to GOV.UK statistical data, 59,090 Cyber Essentials certificates were awarded in 2025-26, with CE+ accounting for approximately 24% of that total, representing 14,482 certifications. While this reflects strong momentum, it also highlights that the majority of certified organisations currently hold only the baseline level, suggesting significant room for broader adoption of the higher-assurance standard.

Cyber Essentials vs Cyber Essentials Plus: What Is the Difference?

Understanding the distinction between the two certification levels is essential before deciding which is right for your business.

Cyber Essentials (now officially named ‘Danzell’ for the self-assessment process) requires an organisation to complete a structured questionnaire covering its existing IT security controls. A certifying body reviews the submitted responses to verify they meet the required standard, but no independent technical testing is carried out. In essence, the certification is based on what a business declares about its own systems. While this provides a meaningful baseline and demonstrates a commitment to cybersecurity, it relies on the accuracy of self-reported answers rather than verified, real-world evidence.

Cyber Essentials Plus builds directly on this foundation. Organisations must still complete the self-assessment questionnaire as a prerequisite, but CE+ adds a mandatory layer of independent technical verification. An accredited assessor physically tests the organisation’s systems against the same five core control areas: firewalls, secure configuration, user access control, malware protection, and patch management. According to IASME, this technical audit typically includes vulnerability scanning of internet-facing and internal systems, configuration checks across devices and user accounts, and simulated phishing tests sent to a sample of end users. Certification cannot be achieved simply by answering questions favourably; systems must demonstrably pass independent inspection.

This distinction matters significantly when it comes to assurance. As the Cloud Security Alliance highlights, CE+ validates that controls are genuinely functioning rather than simply self-declared, providing external stakeholders with far greater confidence in an organisation’s security posture.

For North West businesses tendering for NHS, local authority, or central government contracts, this difference is particularly relevant. Enterprise buyers and public sector procurement teams increasingly treat CE+ as a more credible signal of genuine security readiness. The investment in CE+ is not just a technical exercise; it is a competitive advantage in the tendering process.

If you want to understand how managed security services underpin your readiness for CE+ certification, Blowfish Technology’s Cyber Security services provide the expert support needed to get there.

What Does the CE+ Technical Audit Actually Involve?

The CE+ audit is conducted by an IASME-approved certifying body and covers the same five technical control areas as the base Cyber Essentials assessment: firewalls, secure configuration, user access control, malware protection, and security update management. The critical difference is that nothing is taken on trust. Rather than reviewing a completed self-assessment questionnaire, the certifying body actively tests your environment to verify that the controls you claim to have in place are genuinely effective.

Vulnerability Scanning

The audit begins with both internal and external vulnerability scanning. Assessors deploy scanning tools across a representative sample of in-scope devices, cross-referencing findings against the National Vulnerability Database to identify unpatched software, unsupported operating systems, and missing critical security updates. Separately, all public-facing IP addresses are scanned for open ports, unusual services, and exploitable misconfigurations. A single critical vulnerability identified during this process will result in a fail unless it can be demonstrated as a false positive, which is why patch management must be consistently maintained in the lead-up to the audit.

Configuration and Access Control Checks

Assessors carry out detailed configuration checks across sampled devices, reviewing whether operating systems, applications, and user accounts are set up securely. This includes verifying that standard users are not operating with administrative privileges, that password policies meet the required standard, and that MFA is correctly enforced, particularly for cloud services. Under the updated v3.3 requirements, MFA is now mandatory across all cloud services, making this one of the most commonly flagged areas for businesses entering the process without adequate preparation.

Phishing and Malware Testing

A simulated phishing email is sent to a sample of users to assess whether technical controls, including email filtering, MFA, and sandboxing, would prevent a credential theft attempt from succeeding. Assessors also verify that endpoint malware protection would block a known malicious download. The full scope of the audit covers all devices capable of accessing organisational data, including laptops, desktops, mobile phones, tablets, and cloud services.

Importantly, organisations that fail one or more components are not immediately disqualified. There is a 30-day remediation window from the assessment start date to address identified issues and be re-tested. Having a managed IT partner who understands the CE+ requirements in detail makes this process significantly more manageable, reducing both the risk of failing and the time needed to remediate any findings.

What Is New in Cyber Essentials v3.3 in 2026?

Cyber Essentials v3.3, officially titled Requirements for IT Infrastructure and nicknamed Danzell, went live on 28 April 2026, replacing the previous version for all new and renewed certifications. The update was developed with a clear purpose: to prevent organisations treating certification as a box-ticking exercise and to ensure the standard remains a credible, meaningful indicator of genuine cyber security posture. As threats continue to evolve, IASME and the NCSC have consistently refined the scheme since its 2014 launch, and v3.3 represents what many practitioners are calling the most significant update in several years.

The headline change in Danzell is that Multi-Factor Authentication (MFA) is now mandatory for all cloud services, and critically, a failure to implement it triggers an automatic assessment failure. This is a direct response to the growing volume of brute-force attacks and credential stuffing campaigns targeting cloud platforms. The rule applies to every user, including contractors, part-time staff, and shared accounts, with no exception for cost. Accepted methods include authenticator apps, hardware tokens, passkeys, and biometrics, with email and SMS considered less secure fallback options.

V3.3 also significantly expands controls for home-working and hybrid environments, reflecting the permanent shift away from traditional office-based working. Organisations must now account for devices and access patterns that were previously treated as out of scope, including BYOD devices that access organisational data through a browser.

For the full technical detail, the IASME Consortium’s official v3.3 requirements document is the authoritative reference. Additional guidance on what changed and how to prepare is available via Cyber Essentials v3.3 Danzell: What Changed and How to Prepare and the IASME April 2026 update announcement.

Mandatory MFA for All Cloud Services: What This Means for Your Business

From 28 April 2026, under Cyber Essentials v3.3 (Danzell), Multi-Factor Authentication is no longer optional for cloud services. It is mandatory for every user account across every in-scope cloud platform, including Microsoft 365, Google Workspace, CRM systems, finance applications, and any SaaS tool accessed with a business email address. Critically, this requirement extends beyond administrators to include contractors, part-time staff, and even shared mailboxes. As confirmed by updated Cyber Essentials MFA guidance, failure to satisfy this requirement now triggers an automatic fail on the assessment, regardless of how well the organisation performs elsewhere.

Not all MFA methods carry equal weight under the updated standard. While email and SMS-based verification are technically permitted, they are classified as lower-assurance approaches and are not the preferred choice for organisations seeking a robust, audit-ready posture. The recommended methods are authenticator apps such as Microsoft Authenticator or Google Authenticator, hardware security keys using FIDO2 tokens, and passkeys or biometric credentials tied to device authentication. Organisations relying solely on SMS codes should consider upgrading their MFA method ahead of their CE+ assessment, as assessors will evaluate the quality and consistency of authentication controls, not simply their presence.

For a typical North West SME operating on Microsoft 365, practical compliance means enforcing MFA across all user accounts through either Conditional Access policies or Security Defaults, well before the CE+ audit takes place. Security Defaults offer a straightforward baseline for smaller businesses, while Conditional Access provides more granular control suited to organisations with varied user roles or device types. Neither approach works if rollout is incomplete; every account must be covered without exception.

Missing MFA coverage remains one of the most frequently identified gaps during pre-certification readiness assessments, particularly for organisations that enforced MFA for administrators but overlooked standard user accounts. As noted in Cyber Essentials v3.3 practitioner commentary, a quiet gap has opened up for many SMEs between their current security posture and what the updated standard demands.

Working with an experienced IT support partner ahead of your CE+ audit can make a significant difference. A structured MFA audit will identify unprotected accounts, misconfigured policies, and legacy applications that may not support modern authentication methods. Blowfish Technology works with businesses across the North West to assess, configure, and enforce MFA policies as part of a broader Cyber Essentials Plus readiness programme, reducing the risk of a failed audit and ensuring your organisation meets the v3.3 standard with confidence.

Expanded Controls for Cloud and Remote Working

Cyber Essentials v3.3 makes a significant structural change that many businesses will feel immediately: cloud-hosted services and devices used in home or hybrid working environments are now explicitly within scope. Earlier versions of the scheme left room for ambiguity, allowing some organisations to certify against a narrower slice of their IT estate while leaving cloud platforms and remote endpoints unexamined. That gap is now firmly closed. As Outpost24’s compliance guide to v3.3 notes, the update reflects the realities of modern IT environments where cloud-first and hybrid models are the norm rather than the exception.

The practical implications are substantial. Organisations must now demonstrate that every device used for work, whether in the office, at home, or in a hybrid arrangement, is managed and configured to the same security standard. This means documented patch management evidenced within 14 days, active malware protection, and consistent access controls across all endpoints. BYOD devices are also in scope unless a formal exclusion can be justified, which adds complexity for businesses that have allowed informal personal device use since 2020.

Cloud service configurations require equal attention. Storage platforms, collaboration tools, and SaaS applications must all be reviewed to confirm they meet v3.3’s requirements around user access control and secure configuration. For North West businesses that moved quickly to cloud-first models during and after the pandemic, device management practices may have grown organically rather than strategically, leaving gaps that a CE+ technical audit will surface.

Formalising these controls before an audit is far more effective than attempting remediation during one. Blowfish Technology’s Cloud Services provide managed cloud infrastructure designed to support exactly this kind of structured, compliant environment, giving businesses confidence that their cloud configuration meets the scheme’s expanded v3.3 requirements from the outset.

Who Needs Cyber Essentials Plus? A Decision Framework for North West SMEs

Not every North West business needs Cyber Essentials Plus, but the number that genuinely benefit from it is larger than the current 24% uptake rate suggests. Of the 59,090 Cyber Essentials certificates issued in 2025–26, only 14,482 were CE+, meaning roughly three-quarters of certified organisations are still operating at the lower assurance level. For some, that is entirely appropriate. For many others, it represents an unacknowledged gap.

The decision to pursue CE+ over standard CE typically comes down to four factors. First, supply-chain and procurement exposure: since April 2025, all central government contracts handling sensitive or personal data require valid Cyber Essentials certification, and CE+ provides independently verified assurance that a self-assessed certificate simply cannot match. Second, cyber insurance positioning: insurers are increasingly differentiating between CE and CE+ holders when setting premiums and coverage terms. Third, competitive advantage in tendering: CE+ is becoming a differentiator in bids where procurement teams scrutinise supplier security credentials. Fourth, internal risk appetite: organisations handling sensitive personal data or operating cloud-heavy infrastructure carry elevated exposure that base CE may not adequately address.

As a practical guide, businesses with fewer than 10 employees handling limited external data may find standard CE a reasonable starting point. However, organisations with 20 or more staff, significant cloud infrastructure, or any supply-chain relationship with public sector clients will typically find CE+ the more defensible position. Research into UK SME cyber risk consistently shows that smaller organisations are now primary targets precisely because attackers pursue the path of least resistance. CE+ closes the gaps that self-assessment can miss.

Government and Supply-Chain Requirements

Since April 2025, following the Cabinet Office’s publication of Procurement Policy Note 014 (PPN 014), all central government contracts involving sensitive or personal data require suppliers to hold a valid Cyber Essentials certification as a minimum. This is no longer an advisory recommendation; it is a contractual obligation. Many government departments and prime contractors are now specifying CE+ specifically for higher-risk supply relationships, particularly those involving access to personal data, critical infrastructure, or IT and digital services. NHS bodies represent a clear example, with NHS Supply Chain now requiring CE+ from suppliers handling NHS data. You can verify the current contractual obligations and scheme requirements directly via the GOV.UK Cyber Essentials scheme overview.

For North West businesses supplying public sector organisations, NHS trusts such as NHS Greater Manchester ICB, local authorities including Greater Manchester Combined Authority, or large enterprise customers operating under government contracts, CE+ should be treated as a procurement prerequisite rather than an optional extra. An expired or absent certificate at the point of tender submission will result in disqualification, regardless of how strong your wider bid may be.

Critically, the supply-chain pressure does not stop at direct government suppliers. Prime contractors are increasingly passing CE and CE+ requirements down to their own subcontractors and technology partners contractually. A North West SME in manufacturing, professional services, or technology may face a binding certification requirement simply by supplying a prime contractor, without ever holding a government contract directly. For ambitious regional businesses, acting ahead of that demand rather than reacting to it is the smarter commercial position.

Cyber Insurance Benefits

For North West SME finance and risk decision-makers, the insurance case for Cyber Essentials Plus is arguably one of the most immediately tangible arguments for certification. According to GOV.UK statistical data, organisations holding a Cyber Essentials certification are 92% less likely to make a claim on their cyber insurance policy compared to non-certified counterparts. That is not a marginal improvement; it represents a fundamental shift in risk profile that insurers are actively pricing into their underwriting decisions.

Many cyber insurance providers now offer premium discounts or improved terms to CE and CE+ certified businesses, recognising that certification demonstrates a proactive, verifiable commitment to risk management rather than simply a stated intention. Research indicates that CE Plus certification is associated with an average premium reduction of approximately 35%, a figure that carries real weight for a 50-person North West business paying several thousand pounds annually in premiums. For businesses of this size, the potential savings could partially or fully offset the cost of the CE+ audit itself, which typically ranges from £1,500 to £5,000 depending on organisational complexity.

CE+ carries considerably greater weight with insurers than the standard self-assessment level. Because the technical audit provides independent verification of controls across all five security domains, underwriters receive meaningful evidence of security posture rather than a completed questionnaire. This distinction matters to risk assessors, and it increasingly influences both the availability and cost of cover.

It is also worth noting that businesses achieving the base-level Cyber Essentials certification receive up to £25,000 of complimentary cyber liability insurance as part of the scheme, providing an immediate return for smaller organisations.

The broader financial picture reinforces the case further. The average cost of a cyber breach for an SME consistently and significantly exceeds the combined annual cost of CE+ certification and managed security support. Viewed through that lens, certification is not simply a compliance exercise; it is a financially sound risk management decision.

Competitive and Contractual Advantages

For North West businesses operating in competitive markets, Cyber Essentials Plus carries a commercial weight that the base certification level simply cannot match. When tendering for contracts, CE+ demonstrates that your security controls have been independently verified through hands-on technical testing, rather than declared through a self-assessment questionnaire. Procurement teams and enterprise buyers increasingly understand this distinction, and in sectors where supplier risk is scrutinised closely, that difference can determine whether your proposal progresses or stalls.

In regulated sectors such as legal, finance, healthcare technology, and professional services, CE+ also supports your broader compliance posture. GDPR’s accountability principle requires organisations to actively demonstrate that appropriate technical measures are in place, not simply assert that they are. An annually renewed CE+ certificate provides an auditable, independently verified artefact that supports precisely that demonstration, strengthening your position with clients, regulators, and data protection officers alike.

Displaying CE+ certification visibly on proposals, company websites, and client communications sends a trust signal that procurement teams across the UK are increasingly familiar with. With over 215,000 certificates awarded since the scheme’s launch, the badge carries genuine recognition in enterprise buying environments.

CE+ also provides a structured foundation for organisations planning to pursue ISO 27001. The five technical controls that CE+ documents and verifies form the practical baseline that ISO 27001 builds governance processes around, reducing the gap analysis burden significantly when your organisation is ready to take that next step.

How Much Does Cyber Essentials Plus Cost in 2026?

Budgeting accurately for Cyber Essentials Plus requires understanding that the headline audit fee is only part of the total investment. In 2026, the base-level Cyber Essentials self-assessment (Danzell) costs between £300 and £500 for micro businesses, while the full CE+ technical audit ranges from £1,500 to £5,000 or more, depending on the size and complexity of your organisation. Because CE self-assessment must be completed and passed before a CE+ audit can proceed, these costs stack on top of one another rather than being mutually exclusive.

The single biggest driver of cost variation is scope. A 10-person business operating a cloud-first setup with a small, homogenous device estate will have significantly fewer in-scope systems than a 100-person manufacturer running on-premise servers across multiple sites with a mixed device environment. More devices, more locations, and more infrastructure complexity means more assessor time, more scanning, and more configuration checks; all of which push the final CE+ fee toward the upper end of the pricing range.

Remediation costs are consistently the most underestimated element of any CE+ budget. Businesses that identify gaps during a pre-audit gap analysis, such as missing enforced MFA (now mandatory under v3.3), unpatched devices, or excessive user privileges, must resolve those issues before the certifying body conducts its technical audit. Discovering these gaps at audit stage rather than in preparation leads to delays, potential re-testing fees, and unplanned IT spend.

This is where working with a managed IT partner delivers measurable financial value. A partner like Blowfish Technology can conduct a thorough pre-assessment, identify and remediate configuration weaknesses before the formal audit, and significantly reduce the risk of costly surprises. For North West businesses without dedicated in-house security resource, this support is particularly practical.

When evaluating the true cost of CE+, always account for three layers: the certification fee, remediation work, and the ongoing managed support required to maintain compliance and prepare for annual renewal. For official certified volume data and scheme background, the GOV.UK statistical data sets provide a reliable reference point.

The Annual Renewal Cycle: What Happens After Certification?

Achieving Cyber Essentials Plus certification is a significant milestone, but it is important to understand that it marks the beginning of an ongoing compliance programme rather than the end of one. Every CE+ certificate is valid for exactly 12 months from the date of issue, with no grace period. Once it expires, your organisation is no longer certified, and the practical and commercial consequences of that gap can be serious.

Renewal is not a simplified review of your previous submission. It follows the same structure as the initial certification: a completed self-assessment questionnaire assessed against the current scheme requirements, followed by a full independent technical audit. Critically, renewal is assessed against the version of the standard in force at the time of submission. Any new cloud services, devices, or software introduced during the year fall within scope and must be compliant before the audit begins. With the scheme now operating under v3.3, organisations renewing in 2026 or beyond will encounter updated requirements, particularly around mandatory MFA for cloud services.

The consequences of allowing a certificate to lapse extend well beyond an administrative inconvenience. Businesses supplying central government or regulated enterprise clients risk contract suspension, failed procurement checks, and a weakened cyber insurance position. Planning the renewal process to begin at least eight weeks before the expiry date provides sufficient time to identify and address any compliance gaps before they become audit failures.

This is where a managed IT partner delivers genuine value throughout the year. With Blowfish Technology’s Managed IT Support, patch management, device configuration reviews, and access control hygiene are maintained continuously, meaning that infrastructure remains audit-ready as a matter of course. Renewal becomes a structured confirmation of existing good practice rather than a reactive remediation exercise carried out under time pressure.

How Blowfish Technology Supports CE+ Certification in the North West

Blowfish Technology works with businesses across Greater Manchester, Lancashire, and the wider North West region to prepare for, achieve, and maintain Cyber Essentials Plus certification as part of a fully managed IT and cyber security service. Rather than simply directing clients toward a certifying body, Blowfish takes an end-to-end approach: conducting a gap analysis before the audit, providing hands-on remediation of identified issues, offering guided support throughout the technical assessment, and delivering ongoing managed security once certification is achieved.

This approach is particularly valuable for SMEs without a dedicated in-house IT security team. The knowledge and resource gap between a business’s current security posture and full CE+ compliance can be significant, and without specialist support, it is difficult to close independently within a realistic timeframe.

Blowfish’s broader managed IT support and cyber security services directly underpin the technical controls assessed under CE+ v3.3. Managed EDR addresses malware protection and endpoint visibility requirements, while cloud infrastructure management and managed Wi-Fi support secure configuration and network boundary controls. Two-factor authentication services align directly with the mandatory MFA requirements introduced under v3.3.

Because these services are already embedded within a managed relationship, businesses are not building compliance from scratch. The foundations are in place, and Blowfish guides clients through the final steps to certification and beyond, including annual renewal planning and ongoing security monitoring.

Pre-Assessment Gap Analysis and Remediation

Before any formal CE+ audit begins, Blowfish Technology conducts a structured gap analysis that maps each client’s existing IT environment against the five CE+ control areas: firewalls, secure configuration, user access control, malware protection, and patch management. This mapping is performed against the specific requirements of v3.3, ensuring that every control is assessed against the current standard rather than an outdated version. Under v3.3, cloud services that store or process organisational data are explicitly in scope and cannot be excluded, which significantly expands the surface area that the gap analysis must cover.

Several recurring issues emerge consistently at this stage. Unenforced MFA across cloud services is now an automatic fail condition under v3.3, meaning any in-scope service where MFA has not been enabled will immediately end the assessment. Devices running unsupported or unpatched software, overprivileged user accounts that violate least-privilege principles, and inconsistent malware protection across mixed device estates are all common discoveries. Shadow IT, particularly departmentally-adopted SaaS tools not centrally managed by IT teams, is another frequent gap that organisations often underestimate.

Critically, all remediation work is completed before the formal audit, not during it. This approach significantly reduces the risk of a failed assessment and the additional cost and scheduling delays that re-testing brings.

For North West businesses using Microsoft 365 or Google Workspace, MFA configuration via Conditional Access policy deployment is consistently the most time-sensitive remediation task. It requires careful planning, thorough testing, and structured user communication to avoid operational disruption, making early identification essential.

The gap analysis also surfaces broader security improvements beyond strict CE+ requirements, such as email security configuration and identity governance, strengthening overall cyber resilience in the process.

Guided Audit Support

During the formal CE+ technical audit, Blowfish Technology acts as a dedicated liaison between your organisation and the certifying body. This means the audit scope is clearly defined from the outset, with all in-scope systems properly prepared and accessible for testing before the assessment window opens. Scope management is one of the most common points of failure in CE+ audits. Over-scoping increases complexity and cost unnecessarily, while under-scoping can leave vulnerabilities unexamined and result in certification failure. Blowfish’s technical team handles this process methodically, so there are no surprises on the day.

Where unexpected findings do emerge during the live audit, Blowfish staff are on hand to interpret assessor results in real time and advise on the fastest available route to remediation. Because the CE+ audit is a live technical assessment, the ability to respond quickly to emerging issues can be the difference between a successful outcome and a failed assessment.

For business owners and operations managers without a technical background, this level of support removes significant uncertainty from what can otherwise feel like an opaque process. Having an experienced managed IT partner present ensures that assessor findings are communicated in plain language and actioned promptly, rather than left to interpretation.

Following the audit, Blowfish provides a clear, plain-English summary covering the outcome, any remediation steps completed, and full certificate details. This gives your business a reliable record for procurement tender submissions, cyber insurance applications, and ongoing compliance documentation.

Post-Certification Managed Security

Passing the CE+ audit is a significant achievement, but it represents the beginning of a continuous security commitment rather than the conclusion of one. Maintaining the security posture required to pass annual renewal under CE+ v3.3 demands ongoing management across all five control areas: firewalls, secure configuration, user access controls, malware protection, and patch management. Allowing any of these to drift between certification dates creates real exposure, both to live threats and to the disruptive remediation effort that accumulates when compliance gaps are only identified in the run-up to reassessment. With 32% of CE+ assessments requiring remediation on the first attempt, the organisations best positioned for smooth annual renewal are those treating their certification controls as a live operational discipline, not a periodic exercise.

Blowfish Technology’s managed security services are designed to close exactly this gap. Through Endpoint Detection and Response (EDR) and active threat hunting, Blowfish provides continuous monitoring of endpoints and cloud environments, delivering real-time threat visibility to CE+-certified businesses. This matters because certification confirms a security posture at a fixed point in time, while threats evolve daily. EDR and threat hunting ensure that suspicious activity across devices and cloud platforms is identified and investigated before it can undermine the controls that certification depends on.

Structured patch management, device configuration reviews, and user access audits form the operational backbone of Blowfish’s managed IT service. Under CE+ v3.3, critical security patches must be applied within 14 days, a firm window that demands an automated, consistently managed process to meet reliably at scale. By building these activities into regular service delivery, Blowfish keeps client environments in a state of continuous readiness, so that annual CE+ renewal becomes a straightforward confirmation of an already well-maintained posture.

As a North West-based managed service provider with over 50 years of combined team experience, Blowfish brings both the technical depth to manage complex, hybrid IT environments and the regional understanding to support businesses across Greater Manchester, Lancashire, and the surrounding area effectively.

If you would like to understand where your organisation currently stands against the CE+ v3.3 requirements, the Blowfish team is available for an initial readiness conversation. Get in touch via the Blowfish contact page to get started.

Frequently Asked Questions About Cyber Essentials Plus

Do I need Cyber Essentials before I can get Cyber Essentials Plus?

Yes. CE+ is a two-stage process. Organisations must first hold a current Cyber Essentials certificate, completing the Danzell self-assessment questionnaire as the foundational step. The independent technical audit must then be carried out within three months of that base certificate being awarded. There is no route to CE+ that bypasses the self-assessment stage.

How long does the CE+ audit take?

The technical audit itself typically takes one to two days for a small to medium-sized business, covering vulnerability scanning, configuration checks, and sampled device testing. However, the total time from initial readiness assessment through to receiving your certificate is usually four to eight weeks. Organisations requiring remediation between testing phases should plan for the longer end of that window. Complexity of your IT estate and the number of issues identified will influence the overall timeline.

Can I get Cyber Essentials Plus if my team works remotely or uses personal devices?

Yes, but this requires careful preparation. Under Cyber Essentials v3.3, any device used to access organisational data is within scope for the audit, including personal and home-working devices. Those devices must satisfy all five control requirements. Critically, MFA is now mandatory for all cloud services under v3.3, and this is a live-tested control at CE+ level rather than a self-declared one. Remote and hybrid environments are explicitly addressed within the updated standard.

Is Cyber Essentials Plus the same as ISO 27001?

No. CE+ is a focused, prescriptive technical certification testing five specific control areas, verified through hands-on assessment. ISO 27001 is a comprehensive information security management standard covering governance, risk management, and a significantly broader control set. CE+ prescribes exactly what to implement; ISO 27001 requires organisations to design and operate their own security management system. CE+ is widely regarded as a practical and proportionate first step toward ISO 27001 for growing businesses.

What happens if my organisation fails part of the CE+ audit?

The certifying body will identify each specific control area that did not meet the required standard. Organisations are given the opportunity to remediate those issues and undergo re-testing. Approximately one in four organisations requires some remediation at CE+ level, making pre-audit preparation genuinely important. Re-testing may incur additional cost and will extend your certification timeline, which is why a thorough gap analysis before the formal audit, such as the pre-assessment support offered by Blowfish Technology, can protect both your budget and your schedule.

Ready to Achieve Cyber Essentials Plus in the North West?

For North West SMEs, the case for Cyber Essentials Plus in 2026 has never been stronger. Government procurement requirements, growing supply-chain pressure, a 92% reduction in cyber insurance claim likelihood, and the enhanced credibility of independent technical verification all point in the same direction. CE+ is no longer a nice-to-have; for many businesses, it is becoming a commercial prerequisite.

With Cyber Essentials v3.3 now live, mandatory MFA across all cloud services is a hard requirement, not a recommendation. If your business uses Microsoft 365 or Google Workspace and has not yet enforced MFA for every user account, including contractors and shared mailboxes, you risk an automatic assessment failure at your next certification or renewal. Acting now avoids last-minute disruption.

Blowfish Technology is the North West’s trusted partner for end-to-end CE+ support. From initial gap analysis and remediation through to guided audit support and annual renewal, our North West-based team brings over 50 years of combined experience to every engagement.

CE+ is genuinely achievable for businesses of all sizes with the right preparation. Contact Blowfish Technology today to discuss your readiness and take the first step towards certification with confidence.

M
Matt Palfreyman

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 2012. Based in Ormskirk, with 50+ years of combined experience.