Abdul Munaim Dar
← Back to projects

Cyber Essentials Plus Certification

Implemented the five technical control themes and led remediation ahead of the external Cyber Essentials Plus audit — a separate certification effort from ISO 27001, with its own preparation.

Cyber Essentials Plus Certification certification badge

Overview

Cyber Essentials Plus is a UK government-backed scheme, run by IASME on behalf of the NCSC, that verifies five baseline technical controls with a hands-on external audit rather than a self-assessment. Unlike ISO 27001’s broad management-system scope, CE+ is narrow and technical by design — a separate, standalone certification effort from Allsorter’s ISO 27001 work, with its own preparation and its own audit day.

Architecture

The scheme fixes five control themes: boundary firewalls and internet gateways, secure configuration, user access control (least-privilege admin rights and MFA on cloud services), malware protection, and patch management — high and critical patches applied within 14 days of release. An IASME-accredited assessor then independently verifies all five against a representative sample of user devices, every internet gateway, and every internet-facing server: authenticated vulnerability scans, a simulated malware test, and a check of patch and build status on sampled endpoints.

My scope was implementing these controls and running remediation ahead of the audit — closing the gaps an authenticated scan or a sampled device would actually surface, not just the ones visible from a policy document.

Key decisions & tradeoffs

The 14-day patch SLA enforced as a standing process, not a pre-audit scramble. CE+ treats this as a hard requirement, checked against real patch state on sampled devices. Building it as an ongoing process meant audit day tested something already true, rather than something rushed into place for the assessor.

MFA on every cloud admin path, no exceptions. CE+ specifically checks least-privilege and MFA on cloud services, so standing admin access without MFA was the first thing closed out.

Running the same class of scan internally before the assessor did. Authenticated vulnerability scans ahead of the accredited assessor’s own scan meant audit day surfaced nothing that hadn’t already been found and fixed.

Results

  • Allsorter holds Cyber Essentials Plus certification, verifiable via the compliance page.
  • Certification runs on a 12-month renewal cycle, so the control work had to be maintained on an ongoing basis, not just brought into shape once.
  • The same five controls now sit alongside the ISO 27001 technical controls as the baseline Allsorter’s infrastructure runs against day to day.