Insights

Cyber Essentials vs Cyber Essentials Plus: which do you need?

Same five controls, different level of proof. Here is the real difference between Cyber Essentials and Cyber Essentials Plus — and how to choose.

It is the most common question we get about certification: what is the difference between Cyber Essentials and Cyber Essentials Plus, and which one do you actually need?

The answer is simpler than most people expect. Both cover the same five controls. The difference is the level of proof.

Cyber Essentials: a verified self-assessment

Standard Cyber Essentials is a self-assessment. You answer a questionnaire describing how your organisation meets each of the five controls, and that submission is reviewed against the current scheme. Pass, and you are certified for the year.

It is quick, affordable, and a perfectly credible baseline. Its one limitation is inherent: it relies on your own account of your controls. Nobody has independently tested that things are as described.

Cyber Essentials Plus: the same, independently tested

Cyber Essentials Plus keeps the self-assessment and adds a hands-on technical audit. An assessor examines a sample of your devices and systems and verifies that the controls actually work in practice — that patching is current, that malware protection behaves as it should, that configurations hold up.

Nothing about the standard changes. What changes is that the claims are checked rather than taken on trust. That is exactly why Plus carries more weight.

Which should you choose?

A few simple rules of thumb:

  • Start with standard Cyber Essentials if you want a solid, recognised baseline and nothing in your contracts specifically demands Plus.
  • Choose Plus when a customer, tender or insurer requires it — public-sector and larger private contracts increasingly do — or when you want the stronger assurance that comes from an independent test.
  • Do both, in order. Many organisations certify to Cyber Essentials first, then step up to Plus when a specific opportunity requires it. The work you do for one feeds directly into the other.

Plus is not a different standard. It is the same standard, checked. That is precisely why it reassures the people asking for it.

The honest trade-offs

Plus costs more and takes a little longer, because a person is doing real testing rather than reviewing a form. In return, you get findings you can trust and a credential that answers procurement's questions before they are asked. For many businesses that is money well spent; for others, standard certification is exactly right for now. There is no single correct answer — only the right one for your situation.

If you are not sure which your customers actually need, tell us the requirement and we will point you at the right one — not the bigger one. New to all this? Start with our plain-English guide to Cyber Essentials, or get a fixed-price quote and we will scope the right level with you.

Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights