UK’s trusted IT infrastructure partner since 2003
sales@servnetuk.com
0800 987 4111
Servnet
ConfiguratorGet in Touch
Compliance · UK Cyber

Cyber Essentials Plus 2026 UK buyer's guide

Servnet Editorial · Cyber Security Practice9 min read

Cyber Essentials Plus (CE+) is the UK government-backed cyber certification scheme that has become a de-facto baseline for supplier-onboarding, insurance discounts, and panel-firm appointments. The 2026 standard (Annex A version, last updated April 2025) introduces clearer rules on cloud + BYOD. This is the practical UK buyer's guide.

Cyber Essentials Plus — 5 control families
CE+ 2026 — control map1FirewallsCORE2Secure configurationCORE3User access controlCORE4Malware protectionCORE5Security update managementCORE+Hands-on assessor verificationPLUS

What CE+ actually requires

Cyber Essentials covers 5 control families: firewalls + boundary devices, secure configuration, user access control, malware protection, security update management.

Cyber Essentials Plus adds external + internal vulnerability testing by an NCSC-approved assessor body — verifying the controls are actually implemented (not just claimed).

Certification valid for 12 months. Annual recertification required.

When CE+ is mandatory

Most UK central government contracts require CE+ (some require ISO 27001 or NCSC CAF additionally).

NHS supply chain via DSP Toolkit increasingly cross-references CE+.

MOD supply chain — required for certain bid tiers.

Solicitors' Indemnity Insurance — increasingly bundled or discounted for CE+ holders.

Panel firm appointments in legal + financial services often request CE+ during procurement.

The 2026 standard changes

Cloud services in scope — IaaS workloads owned by the organisation are explicitly in scope. SaaS apps mostly excluded but admin access to SaaS is in scope.

BYOD clarification — BYO devices accessing organisational data are in scope. Most organisations now require enrolled / MDM-managed devices to meet the standard.

MFA on all internet-facing services — including cloud-based admin interfaces.

Software currency — all software (not just OS) must be in-support. End-of-support software must be removed or fenced off.

Common gaps UK firms have

BYOD without MDM — typical gap for SMB. Microsoft Intune or Jamf Pro resolves.

Default admin accounts on network appliances — firewalls, switches, printers, IoT.

Unsupported software (Windows 7, Server 2012, old MySQL versions) still in production.

Backup that isn't immutable — backup hit by ransomware = no recovery. Immutable backup is now expected.

No documented incident response process.

CE+ programme — 8-week typical path
W0W2W4W6W8Gap analysis2wRemediation4wInternal pre-audit1wCE+ assessment1wTotal: 8 weeks end-to-end

The Servnet 8-week path to CE+

Weeks 1-2: gap analysis against current state.

Weeks 3-6: remediation — MFA rollout, MDM deployment, vulnerability patching, default-credential change, backup immutability.

Week 7: mock external + internal vulnerability scan.

Week 8: book CE+ assessor — certificate issued typically 2-4 weeks after assessment.

What Servnet does

Servnet runs CE+ readiness as a defined practice. We don't issue the certificate (that's the NCSC-approved assessor body) but we run the gap analysis, deploy missing controls, and support your assessor relationship.

Typical UK engagement: 8-10 weeks end-to-end, fixed-fee, ~£8-25k depending on environment complexity (excluding remediation hardware / software).

Key takeaways
  • CE+ is a de-facto UK baseline for supplier-onboarding, panel appointments, insurance discounts.
  • 2026 standard explicitly includes cloud IaaS + BYOD in scope.
  • Common gaps: MFA, BYOD MDM, unsupported software, non-immutable backup.
  • 8-week path from gap analysis to assessment is achievable for most UK SMB / mid-market.
  • Servnet runs readiness; NCSC-approved assessor issues the certificate.
Frequently asked

FAQs — Cyber Essentials Plus 2026 UK buyer's guide

Scope

Is our cloud in scope?

IaaS workloads (Azure VMs, AWS EC2 you manage) — yes, fully in scope. SaaS apps (Microsoft 365, Salesforce, Xero) — mostly excluded but admin access to SaaS IS in scope. The 2026 Annex A clarified this.

Does BYOD need to be in scope?

If BYO devices access organisational data, yes. Most UK firms now require MDM enrolment (Microsoft Intune or Jamf Pro) for BYO devices to satisfy the standard.

Cost + timeline

What does CE+ cost?

Assessor fees: typically £1.5-5k for the assessment itself, depending on scope size. Servnet readiness work: typically £8-25k depending on remediation. Hardware / software for remediation: variable.

How long does it take?

8-10 weeks from kick-off to certificate for typical SMB / mid-market with reasonable starting posture. Worse starting posture: 12-16 weeks. Servnet runs the timeline honestly.

Related

Got a question this article didn't answer?

One conversation with an engineer who's done this before. No sales script.

Talk to Servnet →