Back to Standards
Security & Access ControlUnited Kingdom

Cyber Essentials Plus

Cyber Essentials Plus

Enhanced version of Cyber Essentials with hands-on technical verification.

Issuing Body: National Cyber Security Centre UKCode: CYBER-ESSENTIALS-PLUSOfficial WebsiteDocumentation

Purpose

Provides higher assurance through independent technical testing of security controls.

Requirements Overview

All Cyber Essentials requirements plus: Hands-on technical verification; Vulnerability scanning; Configuration testing; Internal and external testing

Overview

The Cyber Essentials Plus standard emerged in 2014 as a critical response to the UK National Cyber Security Centre's evolving cyber security strategy. Developed by the Cabinet Office, this certification represents a significant advancement in technical security verification for organizations handling sensitive digital infrastructure. Unlike its predecessor self-assessment models, Cyber Essentials Plus mandates independent technical testing by approved assessors. This approach provides a more rigorous evaluation of an organization's security controls, moving beyond documentation to actual implementation and effectiveness. For data centers, the standard represents a comprehensive security validation process that examines real-world vulnerability and defense mechanisms. The certification focuses on practical technical controls that directly address modern cyber threats. Key areas of assessment include firewall configuration, patch management, user access controls, and malware protection. By requiring hands-on verification, Cyber Essentials Plus ensures that data centers can demonstrate robust security practices to government agencies, critical infrastructure partners, and enterprise customers. Particularly significant for UK-based data centers, the standard has become a critical benchmark for organizations seeking government contracts, supporting essential services, or operating in regulated industries. Its annual reassessment requirement ensures that organizations maintain a dynamic and current approach to cybersecurity, adapting to emerging threats and technological changes.

Key Requirements

Independent External Vulnerability Scanning and Penetration Testing

Cyber Essentials Plus mandates that NCSC-approved external assessors conduct automated vulnerability scanning of all internet-facing systems, network devices, and applications, followed by manual penetration testing to identify exploitable weaknesses.

Data centers must provide assessors with internet-accessible test accounts, network topology documentation, and unobstructed scanning access to DMZ and perimeter systems without restricting scan intensity or scope.

The assessment must include testing of authentication mechanisms, application logic flaws, and network segmentation effectiveness, with organizations unable to exclude systems from testing scope—all internet-facing infrastructure must be scanned and tested, creating compliance challenges for data centers with legacy systems or third-party managed infrastructure.

Internal Configuration Testing and Compliance Verification

Assessors must conduct hands-on technical testing of internal systems, security device configurations, and administrative controls by accessing the environment as authorized users or IT administrators.

This includes verification that firewalls are correctly configured to industry baselines, that patch management systems are functioning and actually applying updates to systems within defined SLAs, that user access controls enforce principle of least privilege, and that audit logging is enabled and capturing security events.

Data centers must permit assessors to verify Active Directory configurations, test security group memberships, validate certificate management, and confirm that administrative credentials are properly segregated and monitored.

Malware Protection and Endpoint Detection Validation

The standard requires independent verification that anti-malware and endpoint detection systems are installed, configured, enabled, and actually detecting test samples across servers, workstations, and critical infrastructure management systems.

Assessors must confirm that definitions are updated (typically within 24-48 hours of release), that on-access and on-demand scanning are active, and that behavioral detection or threat intelligence feeds are operational.

Data centers must demonstrate that malware protection extends to all management interfaces, backup systems, and disaster recovery infrastructure—systems frequently overlooked in standard deployments.

Secure User Authentication and Access Control Testing

Cyber Essentials Plus assessors conduct live testing of authentication mechanisms by attempting to exploit weak password policies, test for password reuse, verify multi-factor authentication implementation on privileged accounts and remote access, and confirm that accounts with administrative access are restricted to authorized personnel.

Testing includes verification of session timeout mechanisms, confirmation that default credentials have been changed on network devices and infrastructure management systems, and validation that former employees' accounts are disabled within acceptable timeframes.

Data centers must demonstrate segregation between administrative credentials used for different systems and evidence that service accounts operate with minimal necessary privileges.

Patch Management and System Update Verification

Assessors verify through system examination and manual testing that patch management processes are implemented, that critical patches are applied within defined SLAs (typically 14 days for critical vulnerabilities), and that systems actually reflect applied patches through version verification and testing.

The assessment includes validation that patching is tracked, documented, and tested before production deployment; that emergency patching procedures exist for zero-day vulnerabilities; and that systems cannot be bypassed to avoid patching.

Data centers must address the specific challenge of patching cluster environments, virtualization platforms, and firmware on network infrastructure while maintaining service availability—a complex coordination requirement verified through technical testing rather than document review.

Network Security Configuration and Segmentation Testing

Independent assessors conduct hands-on testing of firewall rules, network access control lists, and segmentation controls by attempting network traversal between security zones, testing for unexpected open ports, and verifying that network segmentation actually prevents unauthorized lateral movement.

Testing includes validation that default-deny rule bases are implemented, that administrative network access is restricted to authorized management segments, and that data center traffic segregation (customer networks, management networks, backup networks) is technically enforced.

Assessors must verify that network monitoring and intrusion detection capabilities are enabled on critical segments and that logging captures attempted policy violations.

Access to Physical and Virtual Infrastructure Assessment

Assessors evaluate and test physical security controls on data center facilities including badge access system configurations, segregation of data center access, verification that visitor access is logged and restricted, and confirmation that security personnel maintain accurate access records.

In virtual infrastructure, assessors verify hypervisor configurations, test for virtual machine escape vulnerabilities, and confirm that privileged access to virtual management interfaces is restricted and audited.

The assessment extends to physical device management including hard drives, backup media, and network equipment to verify that decommissioned infrastructure is securely wiped or destroyed according to documented procedures.

Security Event Logging and Incident Response Capability Validation

Cyber Essentials Plus requires independent verification that security-relevant events are logged across systems, that log retention meets minimum requirements (typically 90 days for security events), and that logs are protected from tampering and deletion.

Assessors test log integrity controls, verify that audit trails capture authentication attempts and privilege elevation, and confirm that incident response procedures exist and can be executed.

Data centers must demonstrate that centralized logging or SIEM systems capture critical infrastructure logs, that logs are reviewed for suspicious patterns, and that security events trigger escalation procedures with documented response times.

Who Uses & Why

Cyber Essentials Plus certification becomes mandatory for data centers in several specific scenarios. Organizations bidding on Crown Commercial Service contracts, supporting NHS Digital services, or providing infrastructure for UK government and defense sectors must obtain certification. Essential service providers in telecommunications, electricity distribution, and water utilities are also required to comply. For many data centers, certification offers strategic advantages beyond strict requirements. Financial services providers, cloud platforms targeting regulated industries, and managed service providers can differentiate themselves by demonstrating advanced security credentials. Mid-market data centers (5,000-50,000 square feet) find particular value in the certification, as it provides a comprehensive security verification they might not otherwise afford. Geographic considerations are crucial. The standard primarily targets UK-based operations or organizations with significant UK revenue. Smaller organizations (fewer than 10 employees) may find the base Cyber Essentials tier sufficient, but those pursuing government or critical infrastructure contracts should pursue the Plus certification. Cost and complexity should be carefully evaluated. While certification requires significant preparation and potential infrastructure modifications, it can reduce individual customer audit requirements and enhance competitive positioning in security-conscious markets.

Certification Levels

Level
Cyber Essentials
Cyber Essentials Plus