Cyber Essentials vs Cyber Essentials Plus: What's the Difference?
Both certifications are called 'Cyber Essentials' — but they're fundamentally different in what they test, who performs the assessment, what they cost, and who actually needs them.
This guide explains exactly what separates the two, which industries or contract types require Plus, and how to decide which is right for your business.
For a more detailed breakdown, see our complete UK guide to Cyber Essentials vs CE+ or the Cyber Essentials Plus certification page.
Get a Free IT Consultation
Our London-based IT experts are ready to help your business. Free 30-minute consultation, no obligation.
The Core Difference in One Sentence
Cyber Essentials is a verified self-assessment. Cyber Essentials Plus is an independent technical audit.
With basic Cyber Essentials, you answer a detailed questionnaire about your IT setup and security controls. A qualified assessor reviews your answers. If they're satisfied the controls are in place, you're certified.
With Cyber Essentials Plus, an independent assessor physically tests your systems. They run vulnerability scans, attempt to exploit weaknesses, and verify with their own eyes that the controls you've described actually exist and work.
What Each Certification Actually Tests
Cyber Essentials
- You complete the IASME online questionnaire (Willow platform)
- Questions cover all five controls: firewalls, secure configuration, update management, access control, malware protection
- You certify that your answers are accurate
- Assessor reviews for completeness and consistency
- Assessment method: Document review only
- Who tests your systems: Nobody — you self-report
Cyber Essentials Plus
- You must already hold a valid Cyber Essentials certificate (must be obtained first)
- An IASME-approved assessor performs on-site or remote technical testing:
- Vulnerability scanning of all in-scope devices
- Malware simulation tests — does your malware protection actually catch threats?
- Browser and email client tests — can malicious content execute?
- Device configuration checks — verifying firewalls, patch levels, and access controls are as described
- MFA verification — confirming multi-factor authentication is genuinely enabled on all required accounts
- Assessment is performed by the assessor, not self-reported
- Assessment method: Active technical testing
- Who tests your systems: An independent qualified assessor
Cost Comparison
| | Cyber Essentials | Cyber Essentials Plus | |---|---|---| | Assessment type | Self-assessment questionnaire | Independent technical audit | | Cost (micro, 0–9 staff) | £320 + VAT | £1,499 + VAT | | Cost (small, 10–49 staff) | £440 + VAT | £1,999 + VAT | | Cost (medium, 50–249 staff) | £500 + VAT | £2,499 + VAT | | Technical testing | None | Vulnerability scans, malware tests | | Pre-requirement | None | Must hold basic CE certificate | | Time to complete | 2–4 weeks | 4–10 weeks | | Valid for | 12 months | 12 months |
Note: CE+ costs are IASME assessment fees only. Your IT provider may charge separately for preparation, gap assessment, and remediation support.
Who Requires Cyber Essentials (Basic)?
- All central government contracts involving the handling of sensitive information or personal data
- Many NHS contracts and healthcare supplier frameworks
- MOD and defence supply chain contracts
- Financial services suppliers being asked by FCA-regulated clients
- Businesses wanting the NCSC Cyber Essentials badge and the £25,000 free cyber insurance (for organisations under £20m turnover)
- Any business that wants to demonstrate baseline security to clients and partners
Who Requires Cyber Essentials Plus?
- Central government contracts with higher security classification — many Cyber and Technology contracts now explicitly require Plus
- NHS Digital suppliers — NHS Digital mandates Plus for suppliers accessing patient data systems
- MOD contracts involving classified information
- Large enterprise supply chains — St. James's Place, for example, mandated Plus across 2,800 firms in its network
- Businesses targeting ISO 27001 — Plus is a useful stepping stone and evidence base
- Organisations with high-risk IT environments — businesses that have experienced incidents, handle financial data at scale, or operate in regulated sectors
- Businesses wanting maximum assurance — the independent testing verifies your controls actually work, not just that you've described them correctly
The Practical Decision Framework
Start with: what do your contracts require?
If a tender, contract, or client specifically asks for Cyber Essentials Plus — you need Plus, not basic.
If a tender asks for "Cyber Essentials" without specifying Plus — basic certification meets the requirement.
If no contract is driving the decision:
- Under 25 staff, no government contracts, first certification → Basic Cyber Essentials
- Government contracts, NHS/MOD supply chain, financial services → Ask your client which they require
- High-risk environment, previous security incidents, handling significant personal/financial data → Cyber Essentials Plus
- Aiming for ISO 27001 or Cyber Essentials Plus as a strategic credibility signal → Plus
Can You Go Straight to Plus Without Basic?
No. You must hold a valid basic Cyber Essentials certificate before you can undergo Cyber Essentials Plus assessment. The Plus assessment builds on the basic certification — it doesn't replace it.
Typically:
- Achieve basic Cyber Essentials certification
- Within 3 months, complete the Plus technical assessment
- Receive Cyber Essentials Plus certificate (replaces basic; valid for 12 months)
At renewal, you go through the same process: basic questionnaire, then Plus technical assessment.
What Happens If You Fail Plus?
Unlike basic Cyber Essentials (where you can resubmit the questionnaire after fixing issues), failing Plus means your assessor has found technical weaknesses that need remediation. You'll need to:
- Fix the identified issues (usually a few weeks of IT work)
- Schedule a re-assessment (additional cost)
This is why preparation matters. Working with an IT provider who understands the Plus requirements before the assessment significantly reduces the risk of failure and retest costs.
Further Reading
- Cyber Essentials Plus — full guide: costs, requirements, assessment checks & how to pass first time
- Complete UK guide: Cyber Essentials vs Cyber Essentials Plus — which does your business need?
- Cyber Essentials certification London
- Cyber Essentials Basic
Coreitech helps London businesses achieve both Cyber Essentials and Cyber Essentials Plus certification — from gap assessment and remediation through to submission and post-certification monitoring. Book a free consultation or call 0203 834 9728.
