Case Study: Eras streamlines Cyber Essentials Plus certification

Case Study: Eras streamlines Cyber Essentials Plus certification

Cyber security certifications can feel like alphabet soup, but Cyber Essentials Plus (CE+) is one worth understanding, whether required for a government contract or simply as proof your defences hold up under real scrutiny.

Cyber Essentials Plus is the higher of two tiers in the UK Government’s Cyber Essentials scheme, run by IASME on behalf of the National Cyber Security Centre (NCSC). It covers the same five technical control areas as the basic certification, but with one crucial difference: an independent assessor verifies those controls are working on your live systems, rather than taking your word for it.

Eras flies through the latest CE+ requirements

Norfolk-based Eras is an expert in psychometric products and consultancy, dedicated to helping organisations harness human potential. The organisation has multiple users working from home as well as a small central office.

Ben Miller, Head of Technology at Eras, explains their need for Cyber Essentials Plus. “Although not a legal requirement yet, many public sector and private clients prefer to see this standard reached.”

Eras already has Cyber Essentials Plus in place, but the requirements are becoming more and more stringent. “We’ve maintained CE/CE+ for several years, but previous suppliers placed much more of the burden on us. Strident made certification far less time-consuming, allowing us to focus on our day-to-day business.”

New requirements for Cyber Essentials Plus in 2026

Cyber Essentials Plus certificates run for twelve months, so it’s not a one-off tick-box exercise. The scheme’s technical requirements were revised for assessments from early 2026, and reflect how businesses actually work today: cloud-first, remote, and under near-constant threat.

  • Multi-factor authentication must cover all users, not just administrators — the single biggest shift in this update.
  • Patching windows have tightened, with critical and high-severity updates applied within 14 days. This now explicitly includes firmware on routers, firewalls, and managed switches, not just operating systems and applications.
  • Audits now expect clear visibility into cloud services and identity configurations, not just on-premise kit.
  • Several questions are now “automatic fail” if not fully implemented, so partial compliance no longer gets you over the line.

Strident makes recertification a breeze

“It was a very smooth process with Chris and the team at Strident, with minimal disruption to the business,” says Ben.

Strident’s support agent is installed on the computers at Eras, allowing system changes to be rapidly deployed. However, Ben highlights that the administration of Cyber Essentials Plus is where they felt the benefit. “Although we made some minor changes to our systems, Strident supported us in enhancing our governance, documentation, and evidencing existing controls.”

Ben highlights that while the goalposts are moving all the time, he feels more confident that the business is verifiably more secure.

If you would like to simplify your Cyber Essentials Plus certification, then please get in touch and we can help.

Get the latest news from Strident

6 Steps for Sorted IT

ISO & Data Protection