FNS
guide · 17 September 2026

Cyber Essentials vs Cyber Essentials Plus: What's the Difference?

Cyber Essentials is a self-assessed questionnaire; Cyber Essentials Plus adds independent technical verification. Here's what each involves, what they cost in effort, and which one your business actually needs.

Cyber Essentials is a self-assessed certification based on a questionnaire; Cyber Essentials Plus covers the same five technical controls but adds an independent, hands-on technical audit of your systems. Plus is more rigorous, takes more effort and typically costs more, but carries more weight.

Both are UK government-backed schemes, administered on behalf of the National Cyber Security Centre (NCSC) through certification bodies such as IASME. Both are built around the same five technical controls. The difference is entirely in how compliance is verified — and that difference matters a lot more than it might first appear.

What Cyber Essentials involves

Cyber Essentials (sometimes just called "CE") is a self-assessment. A senior individual within the business (typically a director or senior manager) completes a detailed questionnaire covering the five technical control areas — firewalls, secure configuration, security update management, user access control, and malware protection. The answers are then reviewed and verified by a qualifying certification body before the certificate is issued.

Because it's self-assessed, Cyber Essentials is quicker and less expensive to achieve. It's a solid entry point for demonstrating that basic cyber hygiene is in place, and it's often required by clients or supply chains as a minimum bar.

What Cyber Essentials Plus adds

Cyber Essentials Plus builds on the same questionnaire but adds an independent technical audit carried out by a qualifying assessor. Rather than taking your word for it, the assessor actually tests your systems — this typically includes:

Because Plus involves an assessor's time on site or working with your systems remotely, it takes longer to arrange and costs more than standard Cyber Essentials. Exact current pricing and process details are set out by IASME and the NCSC and do change from time to time, so it's worth checking iasme.co.uk and ncsc.gov.uk directly rather than relying on a fixed figure.

Side-by-side comparison

| | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment method | Self-assessed questionnaire | Independent technical audit |
| Verified by | Reviewed by certification body | Tested hands-on by a qualified assessor |
| Typical time to achieve | Days to a few weeks | Longer — audit needs scheduling |
| Relative cost | Lower | Higher |
| Rigour | Confirms controls are declared and understood | Confirms controls actually work in practice |
| Renewal | Annual | Annual (and current CE certification is usually a prerequisite) |
| Common use case | Baseline requirement, supplier assurance | Higher-value contracts, public sector work, stronger assurance |

Why the difference matters in practice

In our experience, standard Cyber Essentials is genuinely useful for getting the fundamentals right and demonstrating a baseline of care — and for many SMEs it's the sensible starting point. But because it's self-assessed, it relies on the person filling in the questionnaire understanding their own IT environment accurately. It's entirely possible to pass Cyber Essentials while still having gaps that a technical audit would catch — an unpatched device that was mistakenly believed to be up to date, for example, or a firewall rule that isn't quite what was described.

Cyber Essentials Plus closes that gap. It's increasingly asked for by larger organisations, public sector procurement, and insurers, precisely because it provides independent proof rather than a self-reported answer.

A worked example

Picture a 12-person engineering firm that wants to bid for a contract with a larger manufacturer. The manufacturer's procurement team asks for evidence of Cyber Essentials Plus as a condition of working with subcontractors. The firm already holds standard Cyber Essentials, having completed the questionnaire the previous year. To get to Plus, they need to book an assessor, make sure every laptop actually has current updates installed (not just believed to be), and be ready for the assessor to run vulnerability scans against their live network. The process takes a few weeks longer than the standard renewal did, but it's what unlocks the contract.

Which should you go for?

Common mistakes

Related questions

If you're weighing up which certification is right for your business, or need help getting your environment ready for either one, our Cyber Security team can talk you through it — get in touch to start the conversation.