Cyber Essentials vs Cyber Essentials Plus: What's the Difference?
Back to Blog
Cyber Security8 min read

Cyber Essentials vs Cyber Essentials Plus: What's the Difference?

Coreitech Team
27 March 2026
#cyber essentials vs cyber essentials plus#difference cyber essentials plus#cyber essentials plus technical audit#which cyber essentials certification#cyber essentials plus cost UK#cyber essentials vs cyber essentials plus difference#cyber essentials plus explained#cyber essentials plus UK#CE vs CE plus UK#cyber essentials plus requirements#cyber essentials plus London#what is cyber essentials plus
Quick Answer

Cyber Essentials is a self-assessment. Cyber Essentials Plus is an independent technical audit. This guide explains the difference, who needs which, and how to decide.

Cyber Essentials vs Cyber Essentials Plus: What's the Difference?

Both certifications are called 'Cyber Essentials' — but they're fundamentally different in what they test, who performs the assessment, what they cost, and who actually needs them.

This guide explains exactly what separates the two, which industries or contract types require Plus, and how to decide which is right for your business.

For a more detailed breakdown, see our complete UK guide to Cyber Essentials vs CE+ or the Cyber Essentials Plus certification page.

— Need Expert IT Help?

Get a Free IT Consultation

Our London-based IT experts are ready to help your business. Free 30-minute consultation, no obligation.

Free 30-min consultation No obligation London-based team

The Core Difference in One Sentence

Cyber Essentials is a verified self-assessment. Cyber Essentials Plus is an independent technical audit.

With basic Cyber Essentials, you answer a detailed questionnaire about your IT setup and security controls. A qualified assessor reviews your answers. If they're satisfied the controls are in place, you're certified.

With Cyber Essentials Plus, an independent assessor physically tests your systems. They run vulnerability scans, attempt to exploit weaknesses, and verify with their own eyes that the controls you've described actually exist and work.


What Each Certification Actually Tests

Cyber Essentials

  • You complete the IASME online questionnaire (Willow platform)
  • Questions cover all five controls: firewalls, secure configuration, update management, access control, malware protection
  • You certify that your answers are accurate
  • Assessor reviews for completeness and consistency
  • Assessment method: Document review only
  • Who tests your systems: Nobody — you self-report

Cyber Essentials Plus

  • You must already hold a valid Cyber Essentials certificate (must be obtained first)
  • An IASME-approved assessor performs on-site or remote technical testing:
    • Vulnerability scanning of all in-scope devices
    • Malware simulation tests — does your malware protection actually catch threats?
    • Browser and email client tests — can malicious content execute?
    • Device configuration checks — verifying firewalls, patch levels, and access controls are as described
    • MFA verification — confirming multi-factor authentication is genuinely enabled on all required accounts
  • Assessment is performed by the assessor, not self-reported
  • Assessment method: Active technical testing
  • Who tests your systems: An independent qualified assessor

Cost Comparison

| | Cyber Essentials | Cyber Essentials Plus | |---|---|---| | Assessment type | Self-assessment questionnaire | Independent technical audit | | Cost (micro, 0–9 staff) | £320 + VAT | £1,499 + VAT | | Cost (small, 10–49 staff) | £440 + VAT | £1,999 + VAT | | Cost (medium, 50–249 staff) | £500 + VAT | £2,499 + VAT | | Technical testing | None | Vulnerability scans, malware tests | | Pre-requirement | None | Must hold basic CE certificate | | Time to complete | 2–4 weeks | 4–10 weeks | | Valid for | 12 months | 12 months |

Note: CE+ costs are IASME assessment fees only. Your IT provider may charge separately for preparation, gap assessment, and remediation support.


Who Requires Cyber Essentials (Basic)?

  • All central government contracts involving the handling of sensitive information or personal data
  • Many NHS contracts and healthcare supplier frameworks
  • MOD and defence supply chain contracts
  • Financial services suppliers being asked by FCA-regulated clients
  • Businesses wanting the NCSC Cyber Essentials badge and the £25,000 free cyber insurance (for organisations under £20m turnover)
  • Any business that wants to demonstrate baseline security to clients and partners

Who Requires Cyber Essentials Plus?

  • Central government contracts with higher security classification — many Cyber and Technology contracts now explicitly require Plus
  • NHS Digital suppliers — NHS Digital mandates Plus for suppliers accessing patient data systems
  • MOD contracts involving classified information
  • Large enterprise supply chains — St. James's Place, for example, mandated Plus across 2,800 firms in its network
  • Businesses targeting ISO 27001 — Plus is a useful stepping stone and evidence base
  • Organisations with high-risk IT environments — businesses that have experienced incidents, handle financial data at scale, or operate in regulated sectors
  • Businesses wanting maximum assurance — the independent testing verifies your controls actually work, not just that you've described them correctly

The Practical Decision Framework

Start with: what do your contracts require?

If a tender, contract, or client specifically asks for Cyber Essentials Plus — you need Plus, not basic.

If a tender asks for "Cyber Essentials" without specifying Plus — basic certification meets the requirement.

If no contract is driving the decision:

  • Under 25 staff, no government contracts, first certification → Basic Cyber Essentials
  • Government contracts, NHS/MOD supply chain, financial services → Ask your client which they require
  • High-risk environment, previous security incidents, handling significant personal/financial data → Cyber Essentials Plus
  • Aiming for ISO 27001 or Cyber Essentials Plus as a strategic credibility signal → Plus

Can You Go Straight to Plus Without Basic?

No. You must hold a valid basic Cyber Essentials certificate before you can undergo Cyber Essentials Plus assessment. The Plus assessment builds on the basic certification — it doesn't replace it.

Typically:

  1. Achieve basic Cyber Essentials certification
  2. Within 3 months, complete the Plus technical assessment
  3. Receive Cyber Essentials Plus certificate (replaces basic; valid for 12 months)

At renewal, you go through the same process: basic questionnaire, then Plus technical assessment.


What Happens If You Fail Plus?

Unlike basic Cyber Essentials (where you can resubmit the questionnaire after fixing issues), failing Plus means your assessor has found technical weaknesses that need remediation. You'll need to:

  1. Fix the identified issues (usually a few weeks of IT work)
  2. Schedule a re-assessment (additional cost)

This is why preparation matters. Working with an IT provider who understands the Plus requirements before the assessment significantly reduces the risk of failure and retest costs.


Further Reading


Coreitech helps London businesses achieve both Cyber Essentials and Cyber Essentials Plus certification — from gap assessment and remediation through to submission and post-certification monitoring. Book a free consultation or call 0203 834 9728.

— Cyber Security Services

Is your business protected against cyber threats?

Coreitech delivers enterprise-grade cyber security for UK SMEs — NextGen EDR, email security, dark web monitoring, SOC, and Cyber Essentials certification. Free security assessment.

4.9★ rated — 112+ reviews15-min critical SLAFrom £25/user/month
— Coreitech

Need IT support for your business?

Coreitech is a London-based managed IT support company helping UK SMEs with cyber security, Microsoft 365, cloud infrastructure, and expert helpdesk support. Based at London Bridge, SE1 — serving businesses across London and the UK.

Free IT audit with no obligation. Typically takes 30–45 minutes.