External Testing & Audit

Cyber Essentials Plus for Irish Businesses

Get independently verified. Cyber Essentials Plus adds external penetration testing and vulnerability assessment to the standard five controls, giving you and your stakeholders complete confidence in your security posture.

Compare Standard CE
External validation
Penetration testing

What is Cyber Essentials Plus?

Cyber Essentials Plus is the enhanced version of the standard Cyber Essentials scheme. It includes everything in standard Cyber Essentials — the five fundamental controls — plus independent external testing to verify those controls actually work in practice.

While standard Cyber Essentials is self-assessed, Cyber Essentials Plus involves a qualified external assessor who performs vulnerability scanning and limited penetration testing to confirm your security controls are effective against real-world attack scenarios.

The 5 Controls + Testing

  • 1.Secure configuration — Verified through external testing
  • 2.Access control — Tested for implementation gaps
  • 3.Malware protection — Validated across systems
  • 4.Patch management — Confirmed current
  • 5.Backup and recovery — Tested for effectiveness

Who Needs It?

  • Critical infrastructure operators
  • Large government contracts
  • Financial services sector
  • Insurance policy requirements
  • High-risk data handlers

Cyber Essentials vs Cyber Essentials Plus

AspectStandard CECE Plus
Assessment TypeSelf-assessment onlySelf + external testing
External TestingNoneVulnerability scan + pen test
Cost (Ireland)€800–€2,000€3,000–€8,000
Timeline4–8 weeks8–12 weeks
Validity3 years3 years
Assurance LevelMedium (self-reported)High (independently verified)

Note: Costs vary by assessor and organisation size. Contact us for a personalised quote.

Your Certification Timeline

1

Week 1-2

Initial Assessment & Scoping

We evaluate your current security posture and scope the external testing.

2

Week 3-4

Gap Analysis & Remediation Plan

Identify gaps and create a practical roadmap to close them.

3

Week 5-6

Implementation & External Testing

Implement controls and external assessor performs vulnerability scanning and penetration testing.

4

Week 7-8

Remediation of Test Findings

Address any vulnerabilities identified during external testing.

5

Week 9-10

Re-testing & Final Verification

External assessor confirms all controls are effective.

6

Week 11-12

Certification

Official IASME certificate issued.

Frequently Asked Questions

What's the difference between vulnerability scanning and penetration testing?

Vulnerability scanning is automated and identifies known weaknesses. Penetration testing is manual and attempts to exploit those vulnerabilities to assess real-world risk. Cyber Essentials Plus includes both.

Will the external testing disrupt my business?

No. External testing is non-destructive and scheduled during agreed windows. We coordinate with your team to minimise any impact.

What happens if vulnerabilities are found?

Vulnerabilities are documented in a detailed report. You then have time to remediate them, and the external assessor re-tests to confirm fixes. This is a normal part of the process.

Is Cyber Essentials Plus required for Irish businesses?

Not mandated, but increasingly required by government contracts, large enterprises, and cyber insurance providers. If you're bidding for significant contracts or in a regulated sector, it's worth considering.

Can I upgrade from standard Cyber Essentials to Plus?

Yes. If you're already certified, you can add the external testing component to upgrade to Cyber Essentials Plus.

How much does Cyber Essentials Plus cost?

Typical costs range from €3,000–€8,000 depending on your organisation size and complexity. Contact us for a personalised quote.

Learn More

Standard Cyber Essentials

Compare with the standard self-assessed Cyber Essentials scheme and decide which is right for your business.

Compare

CyFUN vs Cyber Essentials

Understand how Ireland's CyFUN framework compares to the UK Cyber Essentials scheme.

Compare frameworks

Ready for Cyber Essentials Plus?

Book a free 20-minute assessment call. We'll evaluate your security posture and create a personalised roadmap to Cyber Essentials Plus certification.

No commitment. No hidden fees. Just practical advice tailored to your business.

Cookie Preferences

We use cookies to enhance your experience, analyze site traffic, and serve targeted content. By clicking "Accept All," you consent to our use of cookies. You can manage your preferences in our cookie policy.