Cookie Consent by Free Privacy Policy Generator

Cyber Essentials vs Cyber Essentials Plus: Which Certification Do You Need?

Cyber Essentials vs Cyber Essentials Plus is not really a choice between basic and advanced cyber security. Both certifications assess the same five technical controls. The important difference is how thoroughly those controls are checked.

This distinction matters because organisations often make one of two mistakes. Some pay for Cyber Essentials Plus before their systems are ready for a technical audit. Others choose the cheaper self-assessment without considering whether a customer, tender or supply-chain partner expects independently verified protection.

Either decision can create unnecessary cost and disruption. A failed audit may delay a contract, while the wrong certification may provide less assurance than your clients need.

In this article, we explain how each certification works, what the assessments involve and how to decide which level is appropriate for your organisation.

What Is the Difference Between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a UK government scheme designed to protect organisations against common internet-based cyber attacks. It is built around five technical control areas:

-Firewalls

-Secure configuration

-Security update management

-User access control

-Malware protection

The National Cyber Security Centre describes Cyber Essentials as the minimum cyber security standard recommended by the Government for organisations of every size.

To achieve the basic certification, your organisation completes an online assessment questionnaire. A senior representative confirms that the answers are accurate, after which they are reviewed by a qualified assessor.

Cyber Essentials Plus begins with the same verified self-assessment and uses the same technical requirements. The difference is that an independent assessor also conducts a technical audit of your IT systems to confirm that the declared controls are actually in place.

That makes Plus a higher level of assurance, but not a completely different cyber security framework.

Area

Cyber Essentials

Cyber Essentials Plus

Assessment method

Verified self-assessment

Self-assessment and technical audit

Technical controls

Five core controls

The same five controls

Vulnerability scans

Not part of the standard assessment

Included

Device testing

No hands-on testing

Representative devices tested

Independent verification

Answers reviewed

Controls technically tested

Validity

12 months

12 months

Cost

Fixed by organisation size

Based on scope and complexity

The most useful way to think about the difference is this: Cyber Essentials verifies your declaration, while Cyber Essentials Plus verifies your environment.

How Does the Cyber Essentials Certification Process Work?

Before answering the question set, you need to define the scope of your assessment. This is often where organisations encounter their first difficulty.

Your scope should normally cover the IT infrastructure used to conduct your business. That can include laptops, desktop computers, servers, mobile phones, cloud services, home workers and personally owned devices used to access company information.

The current NCSC requirements advise organisations to establish the assessment boundary first, determine which infrastructure sits within it and then check every applicable requirement against that scope.

In our experience, weak asset visibility causes more problems than a lack of security software. You cannot confidently confirm that every device is patched if you do not have an accurate record of which devices access your systems.

The assessment questionnaire then examines how you meet each control.

Firewalls

Internet-connected devices must be protected by an appropriately configured firewall. Default passwords should be changed, unnecessary inbound connections blocked and administrative interfaces properly restricted.

Secure configuration

Devices, applications and cloud services should be configured to reduce unnecessary exposure. That means removing unused accounts, disabling services you do not need and changing insecure default settings.

Security update management

Supported software must receive relevant security updates within the required timeframe. High-risk or critical vulnerability fixes generally need to be applied within 14 days.

This requirement applies to more than Windows updates. Browsers, PDF readers, collaboration tools, mobile operating systems and third-party business applications can all fall within scope.

User access control

People should only receive access that they genuinely need. Administrator privileges must be tightly controlled, and standard user accounts should be used for everyday work.

Malware protection

In-scope devices must have an appropriate method of malware protection. Depending on the device and operating system, this may involve anti-malware software, application allow-listing or restrictions on installing unsigned applications.

For assessment accounts created after 27 April 2026, the updated Requirements for IT Infrastructure v3.3 and the Danzell question set apply.

Once awarded, a Cyber Essentials certification is valid for 12 months. You must complete a new assessment each year to remain certified.

What Happens During a Cyber Essentials Plus Technical Audit?

The Cyber Essentials Plus audit is designed to test whether the controls described in your questionnaire work in practice.

An assessor examines a representative set of user devices, alongside all internet gateways and servers that expose services to the internet.

Testing may include:

-External scans of your public IP addresses

-Vulnerability scans of sampled devices

-Checks for missing updates and unsupported software

-Tests of malware protection

-Verification of user and administrator account separation

-Multi-factor authentication checks for cloud services

The assessor does not necessarily test every laptop or phone. However, the sample must represent the different device types and operating systems used within the scope.

This detail can catch businesses by surprise. A company may have 100 well-managed Windows laptops but one older MacBook used by a director. If that MacBook is in scope and runs unsupported software, it can still create an audit problem.

Personally owned devices are another common blind spot. A private phone used to access company email or files may need to meet the relevant requirements. Preparation should therefore cover every route into business data, not only equipment purchased by the company.

It is also important to understand what the audit is not. Cyber Essentials Plus is not a penetration test. Vulnerability scans and configuration checks are performed according to the scheme’s test specification, but the assessor is not conducting an open-ended attempt to exploit your organisation.

A penetration test investigates how weaknesses could be combined or exploited. Cyber Essentials Plus checks whether a defined set of baseline controls has been implemented correctly.

How Much Do the Certifications Cost?

Cyber Essentials uses fixed assessment fees based on the number of employees in the organisation. Additional consultancy or remediation support may cost extra.

Cyber Essentials Plus is more expensive because it requires time from technical assessors. There is no single universal price. The cost depends on factors such as:

-The number and variety of devices

-Network complexity

-The number of locations

-Cloud infrastructure

-Internet-facing systems

-The extent of the certification scope

A small business with a heavily standardised Microsoft 365 environment may be relatively straightforward to audit. Another company of the same size could have multiple sites, Linux servers, unmanaged mobile devices and several cloud platforms. Employee numbers alone do not reveal the amount of audit work involved.

This is why low headline prices should be treated carefully. Before accepting a quotation, check what it includes. Ask whether remediation support, repeat testing, travel and the initial Cyber Essentials assessment are part of the fee.

Plus cannot be obtained as a standalone certificate. You must first pass Cyber Essentials, then complete the Plus audit within three months of that certification.

Do not complete the basic certification too early if you know you need Plus. Starting the three-month window before your systems are audit-ready can create avoidable pressure.

Which Certification Does Your Organisation Need?

The right answer depends on the level of assurance required, not simply the size of your business.

Cyber Essentials may be enough where you want to establish a recognised baseline, improve internal cyber security or meet a contract that only specifies the basic certification.

It is often a sensible starting point for smaller organisations with straightforward IT environments. The certification process can expose weaknesses in patching, account management and secure configuration without immediately committing the business to a technical audit.

Cyber Essentials Plus is usually the stronger choice when external stakeholders need evidence that your controls have been independently tested.

We would seriously consider Plus when:

-A tender or client contract specifically requires it

-You provide IT or managed services to other organisations

-Your team processes sensitive customer information

-You operate within a security-conscious supply chain

-A cyber incident would create significant operational disruption

-Senior management wants independent validation of internal claims

Handling sensitive data does not automatically make Plus mandatory, but it does strengthen the case for technical verification. A ten-person IT provider with administrative access to client systems may face greater practical risk than a much larger company with a simple, isolated environment.

Government contracts also need to be considered individually. Holding an up-to-date certificate can enable organisations to bid for certain contracts involving personal or financial information, but the required level will be set by the procurement documentation.

Do not assume every public-sector contract requires Plus. Equally, do not assume the basic certification will satisfy a buyer simply because it mentions the Cyber Essentials scheme. Read the tender wording carefully and ask for clarification where the stated requirement is ambiguous.

Is Cyber Essentials Plus Worth It?

Cyber Essentials Plus is worth considering when independent assurance has commercial or operational value.

The technical audit can reveal the gap between documented policy and real-world behaviour. A company may state that updates are deployed within 14 days, for example, while an audit discovers an unmanaged laptop that has not received updates for several months.

That does not mean the self-assessment lacks value. Cyber Essentials forces organisations to document their environment and take responsibility for basic controls. For many businesses, that process produces meaningful improvements.

The limitation is that a questionnaire can only assess what the organisation knows and reports. Plus adds an external check.

Government figures show that 59,090 Cyber Essentials certificates were awarded between April 2025 and March 2026, including 14,482 at Plus level. The same government dataset states that organisations with Cyber Essentials are 92% less likely to make a cyber insurance claim.

That figure should not be interpreted as a guarantee that certification prevents every incident. Cyber Essentials is intended to reduce exposure to common attacks. It does not replace staff awareness training, secure backups, incident response planning, security monitoring or broader risk management.

The certificate is most valuable when it reflects the way your organisation operates throughout the year. Treating it as an annual paperwork exercise may produce a pass, but it does little to improve long-term resilience.

How Should You Prepare for Cyber Essentials Plus?

Start preparation before completing the basic certification.

First, create an accurate inventory of every device, operating system and cloud platform within scope. Include equipment used by remote staff and any personally owned devices that connect to business data.

Next, check whether every operating system and application is still supported. Older software is a frequent source of trouble because updates are no longer available, making compliance impossible without upgrading, removing or appropriately isolating the product.

Run vulnerability scans before the assessor does. This gives you an opportunity to address missing updates, exposed services and configuration mistakes without using up valuable remediation time.

Check multi-factor authentication manually rather than relying entirely on an administration dashboard. Test both normal user accounts and administrator accounts across your cloud services.

Account separation also deserves attention. Employees should not use administrator-level accounts for routine activities such as reading email or browsing the internet.

Finally, allow space in the project schedule for awkward exceptions. The centrally managed devices are rarely the only concern. It is often the spare laptop, legacy server or executive’s tablet that creates last-minute work.

Frequently Asked Questions

Can you go directly to Cyber Essentials Plus?

No. You must first achieve the verified Cyber Essentials certification. The Plus technical audit must then be completed within three months.

Are the controls different in Cyber Essentials Plus?

No. Both certification levels use the same five technical control areas. Plus provides greater assurance by independently testing whether those controls have been implemented.

Is Cyber Essentials Plus mandatory?

It is not universally required by law. It may be required by a government contract, customer agreement, procurement framework or supply-chain policy.

How long are the certificates valid?

Both levels are valid for 12 months. Annual reassessment is necessary to maintain certification.

Does Cyber Essentials Plus guarantee that we are secure?

No certification can guarantee that an organisation will not experience a breach. Plus confirms that specific baseline controls were working at the time of the assessment.

Does Cyber Essentials Plus include a penetration test?

No. It includes prescribed vulnerability scanning and technical checks, but it is not a substitute for a full penetration test.

Conclusion

When comparing Cyber Essentials vs Cyber Essentials Plus, the deciding factor should be the level of assurance your organisation needs.

Cyber Essentials is a credible basic certification that helps you establish and demonstrate essential cyber security controls. Cyber Essentials Plus examines the same requirements but adds independent technical testing, making it more suitable when clients, procurement teams or senior stakeholders need stronger evidence.

We recommend starting with your commercial obligations and risk profile. Check what your contracts require, identify the systems and data within scope, then assess whether self-declaration provides enough confidence.

Whichever route you choose, preparation should improve your real security position rather than simply help you achieve certification. A certificate lasts for one year. Strong patching, access control and secure configuration need to work every day.