Cyber Essentials Plus, passed on the first attempt.
Cyber Essentials Plus is the audited variant of Cyber Essentials. Osiris helps your organisation prepare for, evidence, and pass the technical audit cleanly, with remediation, rehearsal, and senior support on audit day.
- AuditedIndependent verification
- Senior-ledAudit-day support
- AnnualRecertification supported

Pass without re-tests.
Eight capabilities that get you through the technical audit without the back-and-forth. Rehearsed, evidenced, and senior-supported on the day.
Technical audit preparation
Where CE is self-assessed, CE Plus is technically audited. We rehearse the audit on a sample of devices before it counts, so nothing catches you out on the day.
Endpoint hardening
Patching cadence, anti-malware, secure configuration, and admin separation across the sample devices the auditor will test.
MFA and access control
Multi-factor enforced on internet-facing services and admin accounts, with access control reviewed and documented to the standard's evidence requirements.
Vulnerability scanning
External and internal scanning to the standard's testing methodology, with findings remediated and re-tested before the audit.
Evidence package
A documented evidence pack the auditor can review without follow-up. We build it with you, sign it off internally, and hand it over clean.
Audit day support
A senior consultant on hand throughout the audit, co-ordinating, answering questions, and getting you signed off without re-tests.
Remediation sprint
If rehearsal exposes a weak control, we prioritise the fix, document the change, and retest before the independent audit window opens.
Renewal planning
Plus is annual. We track what needs to stay in place after the audit, so renewal is controlled maintenance rather than another scramble.

Cyber Essentials Plus is the one your insurer really trusts.
The self-assessed Cyber Essentials gets you onto the buyer's list. The audited Plus is the one that holds up in a tender, a renewal conversation, or a board-level supplier-risk review. The remediation work is identical; the difference is independent verification, and a properly run audit makes that verification straightforward rather than expensive.
Scope. Rehearse. Audit. Maintain.
- 01
Scope
We define the sample with you: the devices, services, identities, and locations the auditor will test against.
- 02
Rehearse
An internal rehearsal of the technical tests, so we can fix what fails before it counts.
- 03
Audit
The independent technical audit, with senior support on the day. Clean, evidenced, and defensible.
- 04
Maintain
Annual renewal. We track what has changed in the standard each cycle and prepare you well in advance.
Going for Plus this year?
Talk to a senior consultant about scope, remediation, and what a clean audit would look like for your organisation.



