Cyber Essentials Basic = self-assessment questionnaire reviewed by IASME. Cyber Essentials Plus = independent IASME assessor physically tests your systems. Basic from £320+VAT; Plus from £1,499+VAT. CE+ is required for MOD, NHS high-risk frameworks, and enterprise supply chains.
CYBER ESSENTIALS vs
CYBER ESSENTIALS PLUS
The Complete Comparison
The definitive guide to Cyber Essentials vs Cyber Essentials Plus — assessment methods, what the IASME assessor tests, costs, timelines, supply chain requirements (MOD, DESNZ, NHS), and how to decide which level your business needs.
Cyber Essentials vs Plus —
every difference explained
| Aspect | CE Basic | CE Plus |
|---|---|---|
| Assessment method | Self-assessment questionnaire (SAQ) | Independent IASME assessor technical audit |
| Who tests your systems | You (reviewed by certifying body) | Qualified IASME assessor — hands-on testing |
| Vulnerability scanning | Not required | Required — all in-scope IPs scanned |
| Endpoint testing | Not required | Sample of devices physically tested |
| MFA verification | Self-declared in questionnaire | Live verification — assessor observes login |
| Email/browser malware test | Not required | EICAR test files sent — system response verified |
| Admin account separation | Self-declared | Assessor verifies on sampled devices live |
| Pass bar | Minor non-compliances may be accepted | All non-compliances must be remediated to pass |
| Level of assurance | Baseline certification | Independently verified — highest level |
| IASME assessment fee | From £320 + VAT (micro-org) | From £1,499 + VAT (micro-org) |
| Time to certify | 2–4 weeks typical | 4–10 weeks typical |
| Cyber liability insurance | £25,000 included (eligible orgs) | £25,000 included (eligible orgs) |
| Required for MOD/DESNZ supply chain | Basic level may be accepted | Often required for higher-classified contracts |
| Required for NHS suppliers | Accepted for many frameworks | Required for higher-risk NHS frameworks |
| Certificate validity | 12 months | 12 months |
How to decide: CE Basic or
Cyber Essentials Plus?
Use this framework to determine which level your business actually needs — based on your contracts, supply chain, and risk profile.
Choose Cyber Essentials Plus when...
Choose CE Basic when...
Written by IASME-accredited Cyber Essentials experts
Full Cyber Essentials Plus guide — costs, 7 assessment checks & how to pass
Including requirements, renewal process, and what the IASME assessor tests on the day.
Cyber Essentials vs Plus —
your questions answered
Q.What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials (Basic) is a self-assessment questionnaire — you answer questions about your security controls and a certifying body reviews your answers. Cyber Essentials Plus is independently verified: a qualified IASME assessor physically tests your systems, conducts vulnerability scans, and verifies your controls are actually working. CE+ provides a much higher level of assurance and is therefore required for more demanding contracts and supply chains.
Q.Do you need Cyber Essentials before getting Cyber Essentials Plus?
Yes. Cyber Essentials Plus always requires a valid Cyber Essentials (Basic) certificate. The CE+ assessment must begin within 3 months of your last CE Basic certification. If you don't have Basic, Coreitech completes this first as part of the CE+ process.
Q.Which is better — Cyber Essentials or Cyber Essentials Plus?
CE+ provides a higher level of assurance because it is independently verified. However, "better" depends on what you need it for. If your contracts specifically require CE+, choose CE+. If Basic is sufficient for your contracts and you're cost-conscious, Basic is a perfectly valid and widely recognised certification. Many organisations start with Basic and upgrade to CE+ at renewal.
Q.How much does Cyber Essentials Plus cost compared to Basic?
The IASME assessment fee for Cyber Essentials Basic starts from £320 + VAT (micro-organisations, 0–9 employees). Cyber Essentials Plus assessment fees start from £1,499 + VAT (micro-organisations) — reflecting the additional time required for independent technical testing. Larger organisations pay more for both. Coreitech charges separately for preparation and remediation support — contact us for a fixed-price quote based on your specific environment.
Q.What does a Cyber Essentials Plus assessment test that Basic doesn't?
CE+ involves: (1) External vulnerability scan of all public IP addresses; (2) Credentialed patch audit of sampled devices; (3) Malware protection testing using EICAR test files via email and browser; (4) Web browser executable download testing; (5) MFA enforcement live verification on cloud services; (6) Admin account separation — assessor observes live on sampled devices. None of these technical tests occur in the Basic self-assessment.
Q.How long does Cyber Essentials Plus take compared to Basic?
Cyber Essentials Basic typically takes 2–4 weeks from engagement to certificate (gap assessment, remediation, questionnaire completion, certifying body review). Cyber Essentials Plus typically takes 4–10 weeks — the additional time reflects independent technical assessment scheduling and any remediation required after the assessor's scan.
Q.Can Coreitech help with both Cyber Essentials and Cyber Essentials Plus?
Yes. Coreitech provides full end-to-end support for both Cyber Essentials Basic and CE+. For Basic: gap assessment, remediation, questionnaire guidance and submission. For Plus: all of the above, plus pre-assessment vulnerability scanning, technical configuration to pass each of the 7 assessor checks, and support on assessment day. Most clients pass first time with our preparation.
Not sure which level you need?
Talk to Coreitech. We'll check your contract requirements, assess your current controls, and recommend the right level — then get you certified efficiently and first time.
