Quick Answer

Cyber Essentials Basic = self-assessment questionnaire reviewed by IASME. Cyber Essentials Plus = independent IASME assessor physically tests your systems. Basic from £320+VAT; Plus from £1,499+VAT. CE+ is required for MOD, NHS high-risk frameworks, and enterprise supply chains.

— Cyber Essentials vs Cyber Essentials Plus · UK

CYBER ESSENTIALS vs
CYBER ESSENTIALS PLUS
The Complete Comparison

The definitive guide to Cyber Essentials vs Cyber Essentials Plus — assessment methods, what the IASME assessor tests, costs, timelines, supply chain requirements (MOD, DESNZ, NHS), and how to decide which level your business needs.

CE Basic: self-assessment, from £320+VAT, 2–4 weeks
CE+: independent technical testing, from £1,499+VAT, 4–10 weeks
CE+ required for MOD supply chain & NHS high-risk frameworks
Both include £25,000 cyber liability insurance (eligible orgs)
Coreitech delivers both — end-to-end support
— Full Comparison

Cyber Essentials vs Plus —
every difference explained

AspectCE BasicCE Plus
Assessment methodSelf-assessment questionnaire (SAQ)Independent IASME assessor technical audit
Who tests your systemsYou (reviewed by certifying body)Qualified IASME assessor — hands-on testing
Vulnerability scanningNot requiredRequired — all in-scope IPs scanned
Endpoint testingNot requiredSample of devices physically tested
MFA verificationSelf-declared in questionnaireLive verification — assessor observes login
Email/browser malware testNot requiredEICAR test files sent — system response verified
Admin account separationSelf-declaredAssessor verifies on sampled devices live
Pass barMinor non-compliances may be acceptedAll non-compliances must be remediated to pass
Level of assuranceBaseline certificationIndependently verified — highest level
IASME assessment feeFrom £320 + VAT (micro-org)From £1,499 + VAT (micro-org)
Time to certify2–4 weeks typical4–10 weeks typical
Cyber liability insurance£25,000 included (eligible orgs)£25,000 included (eligible orgs)
Required for MOD/DESNZ supply chainBasic level may be acceptedOften required for higher-classified contracts
Required for NHS suppliersAccepted for many frameworksRequired for higher-risk NHS frameworks
Certificate validity12 months12 months
— Decision Framework

How to decide: CE Basic or
Cyber Essentials Plus?

Use this framework to determine which level your business actually needs — based on your contracts, supply chain, and risk profile.

Do your contracts specify CE+?
Choose CE+
Continue
Do you supply MOD, DESNZ, or NHS?
Likely CE+ required
Continue
Are you an enterprise supplier?
CE+ strongly recommended
CE Basic usually sufficient

Choose Cyber Essentials Plus when...

You supply the UK Ministry of Defence
MOD and DESNZ contracts increasingly specify CE+ or require it for higher security classifications. Basic CE alone may not be sufficient.
You bid for NHS or public sector contracts above certain thresholds
NHS England and many NHS trusts require Cyber Essentials Plus for higher-risk supplier frameworks.
Your enterprise clients require it
Large financial services firms, insurers, and FTSE companies increasingly specify CE+ as a supply chain requirement.
You want maximum credibility and assurance
CE+ is independently verified — it carries significantly more weight with sophisticated buyers than self-assessed Basic.
You handle highly sensitive personal data
Organisations processing special category data, financial data, or large volumes of personal data benefit from the higher assurance level CE+ provides.

Choose CE Basic when...

Your contracts only require CE Basic
Many government contracts and frameworks accept Cyber Essentials Basic. Check your specific requirements before committing to Plus.
You are getting certified for the first time
CE Basic is an excellent starting point — you can upgrade to CE+ in a subsequent renewal once your controls are embedded.
Budget is constrained
At £320+VAT vs £1,499+VAT (micro-org), Basic is significantly cheaper. For businesses where CE+ is not a contractual requirement, Basic delivers excellent value.
You want to move quickly
CE Basic can typically be achieved in 2–4 weeks. CE+ takes 4–10 weeks due to the independent testing requirement.
— About This Guide

Written by IASME-accredited Cyber Essentials experts

IASME Licensed Certifying Body
Coreitech holds IASME certification to deliver both CE Basic and CE+ assessments
100+ Certifications Delivered
Experience across finance, healthcare, retail, public sector, and manufacturing
First-time Pass Rate 94%
Industry-leading success through proactive gap assessment and remediation
— Need CE+?

Full Cyber Essentials Plus guide — costs, 7 assessment checks & how to pass

Including requirements, renewal process, and what the IASME assessor tests on the day.

Cyber Essentials Plus Guide
— FAQ

Cyber Essentials vs Plus —
your questions answered

Q.What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials (Basic) is a self-assessment questionnaire — you answer questions about your security controls and a certifying body reviews your answers. Cyber Essentials Plus is independently verified: a qualified IASME assessor physically tests your systems, conducts vulnerability scans, and verifies your controls are actually working. CE+ provides a much higher level of assurance and is therefore required for more demanding contracts and supply chains.

Q.Do you need Cyber Essentials before getting Cyber Essentials Plus?

Yes. Cyber Essentials Plus always requires a valid Cyber Essentials (Basic) certificate. The CE+ assessment must begin within 3 months of your last CE Basic certification. If you don't have Basic, Coreitech completes this first as part of the CE+ process.

Q.Which is better — Cyber Essentials or Cyber Essentials Plus?

CE+ provides a higher level of assurance because it is independently verified. However, "better" depends on what you need it for. If your contracts specifically require CE+, choose CE+. If Basic is sufficient for your contracts and you're cost-conscious, Basic is a perfectly valid and widely recognised certification. Many organisations start with Basic and upgrade to CE+ at renewal.

Q.How much does Cyber Essentials Plus cost compared to Basic?

The IASME assessment fee for Cyber Essentials Basic starts from £320 + VAT (micro-organisations, 0–9 employees). Cyber Essentials Plus assessment fees start from £1,499 + VAT (micro-organisations) — reflecting the additional time required for independent technical testing. Larger organisations pay more for both. Coreitech charges separately for preparation and remediation support — contact us for a fixed-price quote based on your specific environment.

Q.What does a Cyber Essentials Plus assessment test that Basic doesn't?

CE+ involves: (1) External vulnerability scan of all public IP addresses; (2) Credentialed patch audit of sampled devices; (3) Malware protection testing using EICAR test files via email and browser; (4) Web browser executable download testing; (5) MFA enforcement live verification on cloud services; (6) Admin account separation — assessor observes live on sampled devices. None of these technical tests occur in the Basic self-assessment.

Q.How long does Cyber Essentials Plus take compared to Basic?

Cyber Essentials Basic typically takes 2–4 weeks from engagement to certificate (gap assessment, remediation, questionnaire completion, certifying body review). Cyber Essentials Plus typically takes 4–10 weeks — the additional time reflects independent technical assessment scheduling and any remediation required after the assessor's scan.

Q.Can Coreitech help with both Cyber Essentials and Cyber Essentials Plus?

Yes. Coreitech provides full end-to-end support for both Cyber Essentials Basic and CE+. For Basic: gap assessment, remediation, questionnaire guidance and submission. For Plus: all of the above, plus pre-assessment vulnerability scanning, technical configuration to pass each of the 7 assessor checks, and support on assessment day. Most clients pass first time with our preparation.

— Get Certified

Not sure which level you need?

Talk to Coreitech. We'll check your contract requirements, assess your current controls, and recommend the right level — then get you certified efficiently and first time.