Rather than relying on a self-assessment questionnaire alone, an external assessor physically audits your systems, testing your network's real-world resilience against remote threats, not just checking that the right policies are written down and declared. Sound Networks guides you through the entire process, from initial self-assessment through to the final remote audit. We work to ensure vulnerabilities are resolved before the external audit takes place, giving you the best possible chance of passing first time.
Standard Cyber Essentials confirms the right security controls are documented and in place. Cyber Essentials Plus goes further, independently verifying those controls are really working under real conditions. It's the right choice if:
Getting Plus certified isn't a single test, it's a structured process designed to catch and fix issues before they can cause a failed audit:
Carried out when we start working with you, to establish your current security baseline.
One week before your audit, to check progress and catch any regressions.
Within 24 hours of the audit itself, for a final real-time check.
Of your PCs, network security, and client device configuration, carried out by a qualified external assessor.
Before the reassessment process begins, to keep your certification and protection current year over year.
A qualified external assessor evaluates your IT systems and configurations directly, confirming they meet the Cyber Essentials Plus technical standard, not just that your policies exist on paper.
We run scans designed to expose potential weaknesses in your defences before an attacker, or the auditor finds them, giving us the chance to patch issues in advance.
Our consultants carry out a complete review of your IT systems and policies against the Cyber Essentials Plus standard, then provide a clear report on any areas that need attention before the audit. Contact us for more information. We handle the technical groundwork so you can stay focused on running your business.
Standard Cyber Essentials is based on a self-assessment questionnaire, verified by an external assessor. Cyber Essentials Plus adds a hands-on technical audit and vulnerability scans, so your controls are independently tested rather than just documented.
It typically takes 4 to 6 weeks from start to finish, covering the initial scan, remediation of any issues, pre-audit scanning, and the final remote audit.
You'll receive a clear breakdown of what needs fixing. Because we run scans at several points before the audit itself, most issues are identified and resolved well before the formal assessment takes place.
It depends on your contracts and clients. Some government tenders and security-conscious clients specifically require Plus-level assurance rather than standard certification. If you're unsure which applies to you, we can help you check.
Like standard Cyber Essentials, Plus certification is renewed annually, including a fresh round of scans and audit.
No, you will first need to qualify and gain standard Cyber Essentials certification before advancing to the Plus standard.

























