Skip to main content
Image coming soon

Cyber Essentials Plus Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
Cyber Essentials Plus · Evidence & Implementation Kit
Walk into your Cyber Essentials Plus audit knowing exactly what the assessor will test, and pass it.
Every Plus audit test procedure and every control theme, handed to you as adopt-ready preparation, with exactly what the assessor verifies hands-on and the reason organizations fail.
Audit-ready in a weekend, not a month.

Here is the honest situation. Cyber Essentials Plus is Cyber Essentials verified by an independent, hands-on audit: an assessor samples your devices and tests them directly with external and authenticated internal vulnerability scans, malware tests and account checks. Most failures are avoidable and come from not knowing what the assessor does. Reading the test specification and preparing every device type, scan and test file is the real job. This Kit hands you that preparation.

This Kit removes the guesswork. It is the Plus audit test procedures plus the underlying control requirements, written as controls you personalize and prepare in a weekend, grounded in the NCSC and IASME test specification.

What you get, the moment you buy

13
Plus audit test procedures. Exactly what the assessor runs: scope and segregation checks, device and cloud-account sampling, external and authenticated internal scans, the malware email and web tests, and the account and MFA checks. Prepare each to pass.
14
Control theme requirements. The five themes' requirements the tests verify, as adopt-ready controls, so the underlying configuration is right before the audit.
1
Plus Control Matrix, pre-built. Every control in a working spreadsheet, ready to record readiness and evidence location.
1
Gap & Readiness Assessment. Score each control and the workbook tells you your readiness as a single percentage, and exactly what to fix next.

Grounded in the NCSC and IASME Cyber Essentials Plus Test Specification and Requirements v3.3, with sampling, the test file set and the pass rule called out. Editable Word and Excel files.

It is verified, not self-declared
Cyber Essentials is a questionnaire; Plus is tested by an assessor on sampled devices. Knowing the exact test cases in advance is the difference between a clean pass and a re-test. This Kit gives you those test cases and how to prepare for each.

What one control looks like

This is the authenticated internal vulnerability scan (Test case 2), the test that catches the most failures. All 27 are built to this depth.

CEP-AUDIT-5 Authenticated internal vulnerability scan (Test case 2) PLUS AUDIT METHOD
Adopt this control

To prepare for a pass, [Organization] must allow an authenticated vulnerability scan of sampled end user devices, servers, and IaaS instances using the approved tool. The scan must find no vulnerability that is vendor-rated critical or high risk, carries a CVSS v3 base score of 7 or above, or has no vendor severity detail, where the vendor fix has been available for more than 14 days.

What the assessor verifies
  • Authenticated vulnerability scan report for the sampled devices showing no qualifying unpatched issue older than 14 days
  • Scan credentials confirmed as authenticated so the scan sees actual installed patch levels
  • Assessor pass determination recorded for every sampled device
Common finding they raise: The scan runs unauthenticated by mistake and reports clean, hiding missing patches that an authenticated scan would have caught.

Why this is not another template pack

  • The test is the point. Generic checklists list the five themes. This tells you exactly what the assessor does on the day and why organizations fail each test. That is what passes Plus.
  • Current to v3.3. The scans, patch windows, MFA and account checks match the requirements and test specification in force now.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. Passing Plus proves the same controls that underpin ISO 27001 and the Essential Eight, so the work carries into your wider security program.

Who buys this

UK organizations that need the higher-assurance certificate for contracts, managed service providers preparing clients for the audit, and the IT and security leads who face the assessor. Whether it is your first Plus or an annual renewal, you save weeks and walk in prepared for every test.

By the end of the weekend you will have
✓  Preparation for every Plus audit test
✓  The five themes' requirements met
✓  What the assessor verifies, test by test
✓  Your device sample brought to one standard
✓  A readiness percentage and a fix list
✓  The common failure points closed before the audit

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

How is this different from the Cyber Essentials kit? This one adds the hands-on Plus audit test procedures, what the assessor actually does, on top of the requirements, so you prepare for the technical audit.

Does this certify me? Certification is issued by an NCSC-approved certification body through IASME. The Kit prepares you: the test procedures, the requirements, and what the assessor verifies.

Is it current? Yes, grounded in the current Cyber Essentials Plus Test Specification and Requirements v3.3. Updates included.

What if it is not for me? A 30-day money-back guarantee.

Do not meet the assessor without knowing the test.
A failed audit is a re-test and a delay. The Kit is instant, and it is guaranteed.
Add it to your cart and be audit-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com